Eleventy
The v4 canary line is being renamed Build Awesome while 3.x is kept on pure maintenance.
A side-by-side editorial comparison of Pimcore and Sulu — release velocity, themes, recent moves, and the top alternatives to consider.
Nearly every release in this window carries security hardening — Pimcore is working through an injection sweep.
Pimcore maintains two calendar-versioned lines in parallel, 2026.2.x and 2026.1.x, with fixes landing on the newer line and selectively backported. The content is dominated by input-validation work: explicit field allowlists on Custom Report updates, an ORDER BY column allowlist for redirect listings, rejection of unwhitelisted filter properties, escaped field names in DataObject JOIN conditions, hardened unserialize paths, and CSV exports bound to the requesting user. Feature work is thin by comparison — a CDN integration and a TemplateProviderInterface extension point in 2026.2.1.
Sulu ships 2.6 and 3.0 in lockstep, and the 3.0 line still reads like a maintenance branch.
Sulu is a Symfony-based CMS for developer-built sites, and its release process is a synchronised pair: every 3.0.x patch ships within a minute of the matching 2.6.x patch, carrying largely the same pull requests. Six releases in five months — 3.0.8/2.6.25, 3.0.7/2.6.24, 3.0.6/2.6.23 — are almost entirely fixes, editor upgrades and framework compatibility work. A security advisory was patched across both branches in March.
Pimcore maintains two calendar-versioned lines in parallel, 2026.2.x and 2026.1.x, with fixes landing on the newer line and selectively backported. The content is dominated by input-validation work: explicit field allowlists on Custom Report updates, an ORDER BY column allowlist for redirect listings, rejection of unwhitelisted filter properties, escaped field names in DataObject JOIN conditions, hardened unserialize paths, and CSV exports bound to the requesting user. Feature work is thin by comparison — a CDN integration and a TemplateProviderInterface extension point in 2026.2.1.
The pattern is a systematic pass over places where user input reaches SQL or deserialization, spread across releases rather than bundled into one advisory — Custom Reports alone are touched in three separate releases. Alongside it runs a slower cleanup of the v11 era: admin functions removed, admin translations deprecated, v11-specific workflows refactored to v12. A task in the most recent release adds backward-compatibility break detection to the project's own code review tooling, which reads as an attempt to keep that cleanup from breaking integrators unannounced.
Expect the hardening sweep to keep producing small paired releases on both lines, with Custom Reports and listing filters the likely remaining targets, and further admin-layer removals as the v12 cleanup continues.
Sulu is a Symfony-based CMS for developer-built sites, and its release process is a synchronised pair: every 3.0.x patch ships within a minute of the matching 2.6.x patch, carrying largely the same pull requests. Six releases in five months — 3.0.8/2.6.25, 3.0.7/2.6.24, 3.0.6/2.6.23 — are almost entirely fixes, editor upgrades and framework compatibility work. A security advisory was patched across both branches in March.
Three threads run through the pairs. Editor upkeep is constant, with CKEditor moving to 47 LTS and then 48 and the fallout — table widgets, webpack font builds — fixed release by release. Framework compatibility is the second: Request->get calls replaced for Symfony 8, PHPUnit 13 and PHPStan kept green on lowest dependencies. The third and most interesting is data-model cleanup on the 3.0 side, where tags migrated from names to IDs behind a newly added DoctrineMigrationsBundle, with smart-content filters reworked to match. What is not visible is any capability that exists on 3.0 and not on 2.6 — a major version that is not yet behaving like one.
Expect the paired-release rhythm to continue with more Symfony 8 preparation and CKEditor 48 fallout. The open question is when 3.0 starts receiving work that is not upmerged from 2.6; until then the major version number is not buying users anything.
Other Mkt Auto products tracked by Sparkpulse, ranked by recent ship velocity. Each card links to a full editorial trajectory and lets you pivot into a head-to-head comparison with either Pimcore or Sulu.
The v4 canary line is being renamed Build Awesome while 3.x is kept on pure maintenance.
Steady feature-then-patch cadence, with security reports rising because AI tools are finding them
Measurement gets granular while the API quietly opens ClickFunnels up to outside agents
n8n's daily patch train hides the real work: hardening its MCP server into a proper auth resource.
OneSignal is arguing a new category into existence before showing the product behind it.
Kit rebuilt its landing page editor, then handed the controls to an AI agent.
See all Pimcore alternatives → · See all Sulu alternatives →
Latest ship moves from both products, interleaved chronologically. ⚡ = editorial spark.
They serve adjacent needs but don't currently overlap on shipped themes. Pimcore and Sulu are shipping at a similar cadence (velocity 5.0 vs 5.0, both within Sparkpulse's "active" band). See the at-a-glance table above for a side-by-side breakdown of velocity, recent sparks, and editorial themes.
Sparkpulse doesn't pick a winner — we score release velocity, not feature parity. Pimcore and Sulu are shipping at a similar cadence (velocity 5.0 vs 5.0, both within Sparkpulse's "active" band). For your specific use case, the alternatives sections above list other Mkt Auto products to evaluate alongside.
Top Pimcore alternatives in Mkt Auto are ranked by recent ship velocity. Browse the "Pimcore alternatives" section above for the current picks, or visit /alternatives/pimcore for the full list with editorial commentary on each.
Top Sulu alternatives in Mkt Auto are ranked by recent ship velocity. Browse the "Sulu alternatives" section above for the current picks, or visit /alternatives/sulu for the full list with editorial commentary on each.