Wiki.js
Wiki.js 3.0 beta closes enterprise auth and SEO gaps at sprint pace
A side-by-side editorial comparison of HedgeDoc and KACE — release velocity, themes, recent moves, and the top alternatives to consider.
| Feature | HedgeDoc | KACE |
|---|---|---|
| Sector | Collab | Collab |
| Velocity score | 2.5 | 5.0 |
| Sparks · 30d | 0 | 0 |
| Top themes | markdown, collaborative-editing, security-fixes, self-hosted | endpoint-management, patch-management, it-operations, mdm |
| Last editorial update | 17d ago | 1d ago |
| Website | Visit → | — |
A collaborative markdown editor on a security-driven maintenance cadence.
HedgeDoc's 1.x line ships every one to two months and is dominated by security response. Recent releases carry seven advisories between them — HTML injection via an email localpart, YAML frontmatter denial of service, CSRF in the Gist export, a rate-limit bypass through CF-Connecting-IP, a permission-value validation gap, missing upload security headers, and script execution in uploaded SVGs. Around those sit configuration knobs for the external-link warning, webp uploads, and rate limits.
KACE stays in maintenance mode: Patch Tuesday catalogs and targeted bug fixes dominate
KACE's recent changelog is almost entirely reactive — monthly Patch Tuesday security catalog updates and point fixes for specific bugs (script re-execution failures, Apple device configuration issues, MFA on new tenants). The one substantive release in the window is KACE SMA 15.1, which added Windows ARM64 agent support and Windows 11 24H2 Feature Update handling. Outside that single capability release, the platform is in steady operational maintenance mode.
HedgeDoc's 1.x line ships every one to two months and is dominated by security response. Recent releases carry seven advisories between them — HTML injection via an email localpart, YAML frontmatter denial of service, CSRF in the Gist export, a rate-limit bypass through CF-Connecting-IP, a permission-value validation gap, missing upload security headers, and script execution in uploaded SVGs. Around those sit configuration knobs for the external-link warning, webp uploads, and rate limits.
Two threads run in parallel. The perimeter work reduces attack surface and maintenance burden at once: old API endpoints and unused config are deleted, Node 18 support is dropped now that its security window has closed, and features added in one release tend to gain an off switch in the next. The second thread is realtime correctness — concurrent-editing data loss, connections dropped mid-handshake, operations discarded during revision gap recovery — which is the only work aimed at the core editing experience rather than its edges.
Expect the 1.x line to continue as security and correctness maintenance, with more legacy endpoints and configuration removed rather than new editing features added.
KACE's recent changelog is almost entirely reactive — monthly Patch Tuesday security catalog updates and point fixes for specific bugs (script re-execution failures, Apple device configuration issues, MFA on new tenants). The one substantive release in the window is KACE SMA 15.1, which added Windows ARM64 agent support and Windows 11 24H2 Feature Update handling. Outside that single capability release, the platform is in steady operational maintenance mode.
KACE is a mature endpoint management platform in a consolidation phase. ARM64 support follows Microsoft's device portfolio rather than opening new capability territory. The consistent Patch Tuesday catalog cadence is table-stakes for the IT admin buyer, but there is no visible investment in new management paradigms — AI-assisted patching, policy drift detection, or modern MDM extensions are absent from the changelog. KACE Cloud fixes are reactive to reported bugs, not proactive capability additions.
KACE's next likely output is the October 2026 Patch Tuesday catalog update or another KACE Cloud bug fix. There are no visible signals of a meaningful capability expansion in this window.
Other Collab products tracked by Sparkpulse, ranked by recent ship velocity. Each card links to a full editorial trajectory and lets you pivot into a head-to-head comparison with either HedgeDoc or KACE.
Wiki.js 3.0 beta closes enterprise auth and SEO gaps at sprint pace
GitHub Copilot adds adaptive model orchestration and self-resolving code review in a single week.
Asana embeds AI into Slack threads and closes the rich-text gap with Notion
Hive is building shared AI automation infrastructure into the core of its PM platform.
SiYuan is actively developing AI agent capabilities that control the note-taking environment itself, from database field configuration to workspace settings.
Teable ships Scheduled Routines and Composio connections, gaining both a scheduler and an integration bus in one release
See all HedgeDoc alternatives → · See all KACE alternatives →
Latest ship moves from both products, interleaved chronologically. ⚡ = editorial spark.
They serve adjacent needs but don't currently overlap on shipped themes. KACE is currently shipping more aggressively (velocity 5.0 vs 2.5), with 0 editorial sparks in the last 30 days against 0. See the at-a-glance table above for a side-by-side breakdown of velocity, recent sparks, and editorial themes.
Sparkpulse doesn't pick a winner — we score release velocity, not feature parity. KACE is currently shipping more aggressively (velocity 5.0 vs 2.5), with 0 editorial sparks in the last 30 days against 0. For your specific use case, the alternatives sections above list other Collab products to evaluate alongside.
Top HedgeDoc alternatives in Collab are ranked by recent ship velocity. Browse the "HedgeDoc alternatives" section above for the current picks, or visit /alternatives/hedgedoc for the full list with editorial commentary on each.
Top KACE alternatives in Collab are ranked by recent ship velocity. Browse the "KACE alternatives" section above for the current picks, or visit /alternatives/kace for the full list with editorial commentary on each.