CryptPad
CryptPad ships by season, and spends most of it keeping OnlyOffice documents intact.
A side-by-side editorial comparison of HedgeDoc and Paperless-ngx — release velocity, themes, recent moves, and the top alternatives to consider.
HedgeDoc 1.x releases are now mostly advisories — security in, features rarely.
The 1.x line ships on a roughly six-to-eight-week rhythm, and almost every release leads with security fixes: HTML injection through an email localpart, YAML frontmatter denial-of-service, CSRF in the Gist export, a rate-limit bypass via the CF-Connecting-IP header, SVG upload script execution. Around that, the recent additions are operator controls — an external-link warning page with a whitelist, configurable login and signup rate limits, an option to restrict uploads to registered users or disable them entirely.
Paperless-ngx shipped its 3.0 rewrite, then spent a week putting out the fires.
3.0.0 landed on July 22 after a long beta, carrying both the largest feature set in the project's history and nine breaking changes. The four releases since are pure repair: a broken migration in 3.0.1 that required an immediate 3.0.2, then two patch rounds covering OCR skipping, permission-filtered document dedup, Gotenberg conversion, email date parsing and search index edge cases. The pace tells you 3.0 shipped into real deployments fast.
The 1.x line ships on a roughly six-to-eight-week rhythm, and almost every release leads with security fixes: HTML injection through an email localpart, YAML frontmatter denial-of-service, CSRF in the Gist export, a rate-limit bypass via the CF-Connecting-IP header, SVG upload script execution. Around that, the recent additions are operator controls — an external-link warning page with a whitelist, configurable login and signup rate limits, an option to restrict uploads to registered users or disable them entirely.
This reads as a mature collaborative editor in hardening mode. New settings appear where an administrator needed a lever, not where a user asked for a feature, and the one substantial correctness fix in the window — data loss when five or more people edited a document at once — was a repair to the existing operational-transform client rather than new ground. Node 24 support and the removal of dead config options point the same direction: keeping a working product current.
Expect the next 1.x release to follow the same shape — one or more advisories plus a small configuration option — since every release in this window has done so.
3.0.0 landed on July 22 after a long beta, carrying both the largest feature set in the project's history and nine breaking changes. The four releases since are pure repair: a broken migration in 3.0.1 that required an immediate 3.0.2, then two patch rounds covering OCR skipping, permission-filtered document dedup, Gotenberg conversion, email date parsing and search index edge cases. The pace tells you 3.0 shipped into real deployments fast.
The project has moved from a document scanner-and-tagger to a document platform with AI in the core: Paperless AI, remote OCR via Azure, a document parser plugin framework, tantivy replacing Whoosh for search, file versions and sharelink bundles. The breaking changes are the other half of that story — dropping API v1, Python 3.10, document encryption and the old consumer clears the decks for that platform. Recent patches keep touching LLM plumbing, including passing output language into chat and adding docstrings so the classifier reads better as an LLM tool.
Expect the 3.0.x patch cadence to continue for another few rounds before feature work resumes; the migration and OCR regressions are the ones still surfacing.
Other Collab products tracked by Sparkpulse, ranked by recent ship velocity. Each card links to a full editorial trajectory and lets you pivot into a head-to-head comparison with either HedgeDoc or Paperless-ngx.
CryptPad ships by season, and spends most of it keeping OnlyOffice documents intact.
GitHub is hardening the registry it owns while Copilot absorbs every new model.
Zoho Sign is wiring signatures into agents and into every country's stamp law.
Avoma's real work is happening in MCP; its feed is buried under competitor comparison pages.
Bloomfire's feed is a knowledge-management content mill, batch-publishing SEO on the day it ships.
AFFiNE ships daily canaries; the interesting work is server-side doc reconciliation.
See all HedgeDoc alternatives → · See all Paperless-ngx alternatives →
Latest ship moves from both products, interleaved chronologically. ⚡ = editorial spark.
Both compete on the same themes — self-hosted — within Collab. Paperless-ngx is currently shipping more aggressively (velocity 6.3 vs 2.5), with 1 editorial sparks in the last 30 days against 0. See the at-a-glance table above for a side-by-side breakdown of velocity, recent sparks, and editorial themes.
Sparkpulse doesn't pick a winner — we score release velocity, not feature parity. Paperless-ngx is currently shipping more aggressively (velocity 6.3 vs 2.5), with 1 editorial sparks in the last 30 days against 0. For your specific use case, the alternatives sections above list other Collab products to evaluate alongside.
Top HedgeDoc alternatives in Collab are ranked by recent ship velocity. Browse the "HedgeDoc alternatives" section above for the current picks, or visit /alternatives/hedgedoc for the full list with editorial commentary on each.
Top Paperless-ngx alternatives in Collab are ranked by recent ship velocity. Browse the "Paperless-ngx alternatives" section above for the current picks, or visit /alternatives/paperless-ngx for the full list with editorial commentary on each.