Sulu
Sulu ships 2.6 and 3.0 in lockstep, and the 3.0 line still reads like a maintenance branch.
A side-by-side editorial comparison of Pimcore and Eleventy — release velocity, themes, recent moves, and the top alternatives to consider.
Nearly every release in this window carries security hardening — Pimcore is working through an injection sweep.
Pimcore maintains two calendar-versioned lines in parallel, 2026.2.x and 2026.1.x, with fixes landing on the newer line and selectively backported. The content is dominated by input-validation work: explicit field allowlists on Custom Report updates, an ORDER BY column allowlist for redirect listings, rejection of unwhitelisted filter properties, escaped field names in DataObject JOIN conditions, hardened unserialize paths, and CSV exports bound to the requesting user. Feature work is thin by comparison — a CDN integration and a TemplateProviderInterface extension point in 2026.2.1.
The v4 canary line is being renamed Build Awesome while 3.x is kept on pure maintenance.
Two lines run in parallel. The 3.x branch gets dependency-only releases — 3.1.5 and 3.1.6 explicitly ship no core code changes, after 3.1.3 and 3.1.4 failed to publish and were left as immutable dead tags. The v4 alpha train, meanwhile, is where the work is: Node minimum raised to 22.15, page.inputPathDir and page.dir removed, batched incremental builds added, and a large refactor of the Nunjucks fork onto a fully-async prerelease. The releases themselves now carry the Build Awesome name and offer an @awesome.me/buildawesome install alongside @11ty/eleventy@canary.
Pimcore maintains two calendar-versioned lines in parallel, 2026.2.x and 2026.1.x, with fixes landing on the newer line and selectively backported. The content is dominated by input-validation work: explicit field allowlists on Custom Report updates, an ORDER BY column allowlist for redirect listings, rejection of unwhitelisted filter properties, escaped field names in DataObject JOIN conditions, hardened unserialize paths, and CSV exports bound to the requesting user. Feature work is thin by comparison — a CDN integration and a TemplateProviderInterface extension point in 2026.2.1.
The pattern is a systematic pass over places where user input reaches SQL or deserialization, spread across releases rather than bundled into one advisory — Custom Reports alone are touched in three separate releases. Alongside it runs a slower cleanup of the v11 era: admin functions removed, admin translations deprecated, v11-specific workflows refactored to v12. A task in the most recent release adds backward-compatibility break detection to the project's own code review tooling, which reads as an attempt to keep that cleanup from breaking integrators unannounced.
Expect the hardening sweep to keep producing small paired releases on both lines, with Custom Reports and listing filters the likely remaining targets, and further admin-layer removals as the v12 cleanup continues.
Two lines run in parallel. The 3.x branch gets dependency-only releases — 3.1.5 and 3.1.6 explicitly ship no core code changes, after 3.1.3 and 3.1.4 failed to publish and were left as immutable dead tags. The v4 alpha train, meanwhile, is where the work is: Node minimum raised to 22.15, page.inputPathDir and page.dir removed, batched incremental builds added, and a large refactor of the Nunjucks fork onto a fully-async prerelease. The releases themselves now carry the Build Awesome name and offer an @awesome.me/buildawesome install alongside @11ty/eleventy@canary.
v4 is accumulating breaking changes faster than it is stabilizing — three of the entries in this window announce removals or minimum-version bumps, and alpha.10 exists only to hotfix a regression alpha.9 introduced. The Nunjucks refactor is the biggest bet: making the fork fully async removes the need for async-specific template tags, but the release notes flag it as risky for existing Nunjucks users. The naming change is proceeding on the same timeline, so users tracking canary are absorbing an identity shift and an API shift at once.
Expect more v4 alphas carrying breaking removals before any beta, with the Nunjucks async refactor generating follow-up regressions; 3.x looks likely to keep receiving dependency-only patches with no core changes.
Other Mkt Auto products tracked by Sparkpulse, ranked by recent ship velocity. Each card links to a full editorial trajectory and lets you pivot into a head-to-head comparison with either Pimcore or Eleventy.
Sulu ships 2.6 and 3.0 in lockstep, and the 3.0 line still reads like a maintenance branch.
Steady feature-then-patch cadence, with security reports rising because AI tools are finding them
Measurement gets granular while the API quietly opens ClickFunnels up to outside agents
n8n's daily patch train hides the real work: hardening its MCP server into a proper auth resource.
OneSignal is arguing a new category into existence before showing the product behind it.
Kit rebuilt its landing page editor, then handed the controls to an AI agent.
See all Pimcore alternatives → · See all Eleventy alternatives →
Latest ship moves from both products, interleaved chronologically. ⚡ = editorial spark.
They serve adjacent needs but don't currently overlap on shipped themes. Pimcore and Eleventy are shipping at a similar cadence (velocity 5.0 vs 5.0, both within Sparkpulse's "active" band). See the at-a-glance table above for a side-by-side breakdown of velocity, recent sparks, and editorial themes.
Sparkpulse doesn't pick a winner — we score release velocity, not feature parity. Pimcore and Eleventy are shipping at a similar cadence (velocity 5.0 vs 5.0, both within Sparkpulse's "active" band). For your specific use case, the alternatives sections above list other Mkt Auto products to evaluate alongside.
Top Pimcore alternatives in Mkt Auto are ranked by recent ship velocity. Browse the "Pimcore alternatives" section above for the current picks, or visit /alternatives/pimcore for the full list with editorial commentary on each.
Top Eleventy alternatives in Mkt Auto are ranked by recent ship velocity. Browse the "Eleventy alternatives" section above for the current picks, or visit /alternatives/eleventy for the full list with editorial commentary on each.