Ethico
The whistleblower hotline vendor is assembling a compliance suite, one module at a time.
A side-by-side editorial comparison of Kavita and Passbolt — release velocity, themes, recent moves, and the top alternatives to consider.
A self-hosted reading server that spent two releases becoming infrastructure, then paid for it with a CVE.
Kavita ships two to four substantial releases a year with hotfixes trailing each one, and the last two years moved it well past a comic reader: OIDC login, an annotation system, a rebuilt epub reader, a reading-list overhaul, a stats system, and a scanner reported 50x faster. The most recent release is a critical security hotfix carrying CVE-2026-47202 that affects every prior version. Kavita+ remains the paid tier where metadata features land first.
Passbolt collapsed the Community-to-Pro upgrade into a settings toggle, then spent the next release on sharing transparency.
Three releases on a roughly monthly cadence, each named after a song. 5.12 took the Safari extension out of beta so it stands level with Chrome, Firefox and Edge, and added a PIN code resource type. 5.13 built on the 5.12 codebase unification to let administrators switch between Community and Pro editions from organisation settings, with no separate environment or manual migration. 5.14 added explicit confirmation dialogs before creating items in shared folders or editing shared resources, made group members visible in access lists, and fixed an MFA policy enforcement issue.
Kavita ships two to four substantial releases a year with hotfixes trailing each one, and the last two years moved it well past a comic reader: OIDC login, an annotation system, a rebuilt epub reader, a reading-list overhaul, a stats system, and a scanner reported 50x faster. The most recent release is a critical security hotfix carrying CVE-2026-47202 that affects every prior version. Kavita+ remains the paid tier where metadata features land first.
The arc is a hobby-scale project taking on the obligations of infrastructure — standard auth, an external API contract for third-party clients, sync with other readers, and formal vulnerability disclosure. Each of those decisions expands the attack surface, and the 0.9.x line shows the bill arriving: security hardening now leads the release notes rather than following them. The team has also visibly grown from one maintainer to a named pair, which is what made the parallel reader and foundation rewrites possible.
The next release is likely the delayed scanner-improvement work that 0.8.7 displaced, with continued API hardening rather than new reader surfaces. Expect the CVE details to be published once adoption of 0.9.0.2 is high enough.
Three releases on a roughly monthly cadence, each named after a song. 5.12 took the Safari extension out of beta so it stands level with Chrome, Firefox and Edge, and added a PIN code resource type. 5.13 built on the 5.12 codebase unification to let administrators switch between Community and Pro editions from organisation settings, with no separate environment or manual migration. 5.14 added explicit confirmation dialogs before creating items in shared folders or editing shared resources, made group members visible in access lists, and fixed an MFA policy enforcement issue.
Two threads are running at once. Commercially, the friction between the open-source edition and the paid one has been engineered away — evaluation is now a toggle rather than a deployment project. Product-wise, the focus has moved from storing secrets to showing users who can actually reach them, which is where self-hosted password managers usually lose enterprise deals. Both threads point at the same buyer: an admin at an organisation already running Community and considering Pro.
The sharing-visibility work looks unfinished — expect access review or permission audit surfaces to follow — and the in-app edition switch is a natural place for licence and trial handling to appear next.
Other Collab products tracked by Sparkpulse, ranked by recent ship velocity. Each card links to a full editorial trajectory and lets you pivot into a head-to-head comparison with either Kavita or Passbolt.
The whistleblower hotline vendor is assembling a compliance suite, one module at a time.
Contract automation grows up: admin permission maps, 2FA, and forms that do their own arithmetic.
The knowledge graph quietly turned itself into a meetings product.
A minimal RSS reader that made passkeys the only way in, then went back to polishing the reading experience.
A Go bookmark manager rebuilding itself around an API — and only ever shipping release candidates.
FreshRSS keeps turning a reader into a queryable archive — and hardening the parts that touch the web.
See all Kavita alternatives → · See all Passbolt alternatives →
Latest ship moves from both products, interleaved chronologically. ⚡ = editorial spark.
Both compete on the same themes — self-hosted — within Collab. Passbolt is currently shipping more aggressively (velocity 2.5 vs 0.0), with 0 editorial sparks in the last 30 days against 0. See the at-a-glance table above for a side-by-side breakdown of velocity, recent sparks, and editorial themes.
Sparkpulse doesn't pick a winner — we score release velocity, not feature parity. Passbolt is currently shipping more aggressively (velocity 2.5 vs 0.0), with 0 editorial sparks in the last 30 days against 0. For your specific use case, the alternatives sections above list other Collab products to evaluate alongside.
Top Kavita alternatives in Collab are ranked by recent ship velocity. Browse the "Kavita alternatives" section above for the current picks, or visit /alternatives/kavita for the full list with editorial commentary on each.
Top Passbolt alternatives in Collab are ranked by recent ship velocity. Browse the "Passbolt alternatives" section above for the current picks, or visit /alternatives/passbolt for the full list with editorial commentary on each.