← Back to home
Comparison · Collab

HedgeDoc vs BookStack

A side-by-side editorial comparison of HedgeDoc and BookStack — release velocity, themes, recent moves, and the top alternatives to consider.

Shared themes:self-hosted

HedgeDoc vs BookStack: at a glance

FeatureHedgeDocBookStack
SectorCollabCollab
Velocity score2.55.0
Sparks · 30d00
Top themescollaborative-editing, markdown, self-hosted, security-hardeningself-hosted, security-releases, permissions, documentation
Last editorial update12h ago6h ago
WebsiteVisit →Visit →

What is HedgeDoc?

HedgeDoc 1.x releases are now mostly advisories — security in, features rarely.

The 1.x line ships on a roughly six-to-eight-week rhythm, and almost every release leads with security fixes: HTML injection through an email localpart, YAML frontmatter denial-of-service, CSRF in the Gist export, a rate-limit bypass via the CF-Connecting-IP header, SVG upload script execution. Around that, the recent additions are operator controls — an external-link warning page with a whitelist, configurable login and signup rate limits, an option to restrict uploads to registered users or disable them entirely.

Read the full HedgeDoc trajectory →

What is BookStack?

BookStack's release stream is mostly security patches with feature drops in between.

Four of BookStack's last six releases are security releases. The newest closes five separate issues at once: external authentication could match the wrong user where IDs differ only by casing or accents, the login form leaked user existence through timing, exported content could load interactive content over file links, API errors exposed debug detail by default, and the default PDF renderer could probe files on the host. The one feature release, v26.05, added a page contents view in the editor, tag browsing API endpoints, a dedicated revision-viewing permission, in-UI MFA reset and new image and CSP controls.

Read the full BookStack trajectory →

HedgeDoc vs BookStack: editorial side-by-side

H
HedgeDoc
COLLAB
2.5

HedgeDoc 1.x releases are now mostly advisories — security in, features rarely.

◆ Current state

The 1.x line ships on a roughly six-to-eight-week rhythm, and almost every release leads with security fixes: HTML injection through an email localpart, YAML frontmatter denial-of-service, CSRF in the Gist export, a rate-limit bypass via the CF-Connecting-IP header, SVG upload script execution. Around that, the recent additions are operator controls — an external-link warning page with a whitelist, configurable login and signup rate limits, an option to restrict uploads to registered users or disable them entirely.

◆ Where it's heading

This reads as a mature collaborative editor in hardening mode. New settings appear where an administrator needed a lever, not where a user asked for a feature, and the one substantial correctness fix in the window — data loss when five or more people edited a document at once — was a repair to the existing operational-transform client rather than new ground. Node 24 support and the removal of dead config options point the same direction: keeping a working product current.

◆ Prediction

Expect the next 1.x release to follow the same shape — one or more advisories plus a small configuration option — since every release in this window has done so.

B
BookStack
COLLAB
5.0

BookStack's release stream is mostly security patches with feature drops in between.

◆ Current state

Four of BookStack's last six releases are security releases. The newest closes five separate issues at once: external authentication could match the wrong user where IDs differ only by casing or accents, the login form leaked user existence through timing, exported content could load interactive content over file links, API errors exposed debug detail by default, and the default PDF renderer could probe files on the host. The one feature release, v26.05, added a page contents view in the editor, tag browsing API endpoints, a dedicated revision-viewing permission, in-UI MFA reset and new image and CSP controls.

◆ Where it's heading

Cadence is set by responsible disclosures — a named researcher credited in nearly every patch — and the feature work leans the same way, toward finer permissions and content security controls. For a self-hosted wiki that users routinely expose publicly, hardening is the roadmap, with quarterly feature releases sitting between patch runs.

◆ Prediction

Expect another patch on the 26.05 line next. The permission and CSP work visible in v26.05 is the thread the following minor most plausibly continues, though the entries give no signal on timing.

Alternatives to HedgeDoc and BookStack

Other Collab products tracked by Sparkpulse, ranked by recent ship velocity. Each card links to a full editorial trajectory and lets you pivot into a head-to-head comparison with either HedgeDoc or BookStack.

See all HedgeDoc alternatives → · See all BookStack alternatives →

Recent activity from HedgeDoc and BookStack

Latest ship moves from both products, interleaved chronologically. ⚡ = editorial spark.

  1. 15h agoBookStackSecurity release fixes five issues including auth matching
  2. 5d agoHedgeDocHedgeDoc 1.11.1
  3. 27d agoBookStackURL filtering, redirects and permission checks hardened
  4. 1mo agoHedgeDocHedgeDoc 1.11.0
  5. 1mo agoBookStackAttachment metadata leak and file:// export risk closed
  6. 2mo agoBookStackv26.05 adds page contents view, tag API and revision permissions
  7. 2mo agoBookStackRate limiting added to MFA verification routes
  8. 3mo agoBookStackAttachment permission and webhook URL validation fixes
  9. 3mo agoHedgeDocHedgeDoc 1.10.8
  10. 5mo agoHedgeDocHedgeDoc 1.10.7
  11. 5mo agoHedgeDocHedgeDoc 1.10.6
  12. 7mo agoHedgeDocHedgeDoc 1.10.4

Frequently asked questions

What is the difference between HedgeDoc and BookStack?

Both compete on the same themes — self-hosted — within Collab. BookStack is currently shipping more aggressively (velocity 5.0 vs 2.5), with 0 editorial sparks in the last 30 days against 0. See the at-a-glance table above for a side-by-side breakdown of velocity, recent sparks, and editorial themes.

Is HedgeDoc better than BookStack?

Sparkpulse doesn't pick a winner — we score release velocity, not feature parity. BookStack is currently shipping more aggressively (velocity 5.0 vs 2.5), with 0 editorial sparks in the last 30 days against 0. For your specific use case, the alternatives sections above list other Collab products to evaluate alongside.

What are the best alternatives to HedgeDoc?

Top HedgeDoc alternatives in Collab are ranked by recent ship velocity. Browse the "HedgeDoc alternatives" section above for the current picks, or visit /alternatives/hedgedoc for the full list with editorial commentary on each.

What are the best alternatives to BookStack?

Top BookStack alternatives in Collab are ranked by recent ship velocity. Browse the "BookStack alternatives" section above for the current picks, or visit /alternatives/bookstack for the full list with editorial commentary on each.