SmartSuite
SmartSuite pushes Forms 2.0, granular governance, and AI while courting GRC and ITSM teams
A side-by-side editorial comparison of Kanboard and TimeCamp — release velocity, themes, recent moves, and the top alternatives to consider.
Kanboard is on a year-long security-hardening run, sweeping the codebase one attack class at a time.
Kanboard's last six releases read as a single sustained security audit: parameterized queries replacing raw SQL, SSRF protection for webhooks, LDAP injection escapes, timing-safe token comparisons, CSRF for project role changes, comment-visibility enforcement for unauthenticated users, and removal of unsafe deserialization paths (file cache driver, legacy serialized events). Feature work continues in parallel — RTL support, Arabic translation, sub-task counts, bulk tag operations — but is clearly secondary to the hardening arc.
TimeCamp's feed is competitor-comparison SEO, not product releases — billing beats stopwatch.
TimeCamp's recent 'changelog' is entirely bottom-of-funnel marketing: TimeCamp-vs-Toggl, Clockify, Harvest, Hubstaff, Time Doctor, Jibble, and Everhour comparisons, plus billable-hours explainers for agencies and CPA firms. The consistent message is positioning — TimeCamp as a billing and profitability platform rather than a simple tracker or a surveillance tool. No actual product changes appear in these entries.
Kanboard's last six releases read as a single sustained security audit: parameterized queries replacing raw SQL, SSRF protection for webhooks, LDAP injection escapes, timing-safe token comparisons, CSRF for project role changes, comment-visibility enforcement for unauthenticated users, and removal of unsafe deserialization paths (file cache driver, legacy serialized events). Feature work continues in parallel — RTL support, Arabic translation, sub-task counts, bulk tag operations — but is clearly secondary to the hardening arc.
The team is methodically working through input surfaces (LDAP, headers, webhooks, file uploads, redirect targets) and output surfaces (comments, exports, API responses) to close authorization and injection gaps. This is mature-project hygiene, not pivot work — Kanboard is positioning itself as an audit-ready self-hostable kanban for organizations with security review checklists. PHP 8.1 is now the floor; the codebase is being modernized alongside the hardening.
Expect the security cadence to continue with one to two more releases focused on remaining trust boundaries, then a feature-weighted release picking up RTL/locale follow-ons and possibly the long-promised SQLite/Postgres parity work hinted at by recent Docker Compose additions.
TimeCamp's recent 'changelog' is entirely bottom-of-funnel marketing: TimeCamp-vs-Toggl, Clockify, Harvest, Hubstaff, Time Doctor, Jibble, and Everhour comparisons, plus billable-hours explainers for agencies and CPA firms. The consistent message is positioning — TimeCamp as a billing and profitability platform rather than a simple tracker or a surveillance tool. No actual product changes appear in these entries.
On this evidence, TimeCamp is investing in comparison SEO aimed at agencies, consultancies, and accounting firms, framing rivals as either too simple (Toggl, Clockify) or monitoring-first (Hubstaff, Time Doctor). That is a marketing motion, not a product one: the feed shows where TimeCamp wants to win buyers, not what it shipped. The crawl source here looks like a blog, not a release log.
Expect more 'TimeCamp vs [competitor]' pieces and vertical billable-hours guides on the same cadence. These entries give no grounded signal about the actual product roadmap.
Other PM products tracked by Sparkpulse, ranked by recent ship velocity. Each card links to a full editorial trajectory and lets you pivot into a head-to-head comparison with either Kanboard or TimeCamp.
SmartSuite pushes Forms 2.0, granular governance, and AI while courting GRC and ITSM teams
Aha! pushes from planning into building — roadmaps now compile to working apps
Atlassian threads agentic CI/CD and richer package management through Bitbucket
ProdPad's feed is a sustained argument against dated roadmaps and for Now-Next-Later.
RescueTime's feed is its productivity blog, with no product signal
Everhour's tracked feed is its HR/PM glossary blog, not the product changelog.
See all Kanboard alternatives → · See all TimeCamp alternatives →
Latest ship moves from both products, interleaved chronologically. ⚡ = editorial spark.
They serve adjacent needs but don't currently overlap on shipped themes. TimeCamp is currently shipping more aggressively (velocity 5.0 vs 0.0), with 0 editorial sparks in the last 30 days against 0. See the at-a-glance table above for a side-by-side breakdown of velocity, recent sparks, and editorial themes.
Sparkpulse doesn't pick a winner — we score release velocity, not feature parity. TimeCamp is currently shipping more aggressively (velocity 5.0 vs 0.0), with 0 editorial sparks in the last 30 days against 0. For your specific use case, the alternatives sections above list other PM products to evaluate alongside.
Top Kanboard alternatives in PM are ranked by recent ship velocity. Browse the "Kanboard alternatives" section above for the current picks, or visit /alternatives/kanboard for the full list with editorial commentary on each.
Top TimeCamp alternatives in PM are ranked by recent ship velocity. Browse the "TimeCamp alternatives" section above for the current picks, or visit /alternatives/timecamp for the full list with editorial commentary on each.