Wakapi
A critical auth bypass lands in the middle of Wakapi's slow identity rebuild.
A side-by-side editorial comparison of Process Street and Vikunja — release velocity, themes, recent moves, and the top alternatives to consider.
Process Street's public feed is an SEO content engine, not a changelog.
Nothing in this feed reports a product change. It runs a steady daily-ish cadence of evergreen business content — risk management primers, business writing advice, an MBTI personality explainer, a compliance audit walkthrough — interleaved with lead-generation assets built around free Process Playbook checklists and product how-tos like an employee onboarding automation guide. The one item with substance behind it is a customer story on a healthcare practice cutting insurance appeals prep from 15 minutes to under 2, which reads as a compliance-ops proof point rather than a release.
Vikunja crossed the v1.0 finish line and pivoted hard into security hardening.
Vikunja shipped two v1.0 release candidates through late 2025 and early 2026, then jumped to a v2 series whose first widely-tagged point release, v2.2.1, is dominated by security work. The latest release patches multiple SSRF and IDOR vulnerabilities, enforces disabled/locked-account semantics across every auth surface (OIDC, API tokens, CalDAV, LDAP), and adds a shared SSRF-safe HTTP client that webhooks and migrations now route through. User-facing feature work has slowed; the visible energy is in plumbing and audit cleanup.
Nothing in this feed reports a product change. It runs a steady daily-ish cadence of evergreen business content — risk management primers, business writing advice, an MBTI personality explainer, a compliance audit walkthrough — interleaved with lead-generation assets built around free Process Playbook checklists and product how-tos like an employee onboarding automation guide. The one item with substance behind it is a customer story on a healthcare practice cutting insurance appeals prep from 15 minutes to under 2, which reads as a compliance-ops proof point rather than a release.
The company positions itself as a compliance operations platform in its own feed signature, and the content is being steered to match: PHI handling, appeals packets, audit readiness, risk assessment and controls now sit alongside the older generic productivity material. Some of that older material is being recirculated rather than retired — a 2021 milestone retrospective carries a current date in this window, so the feed is partly an archive re-dump. Product direction cannot be read here at all.
Expect more compliance and regulated-industry content to displace the generic productivity posts, but this feed will keep carrying no release information, so any actual product movement will have to be observed elsewhere.
Vikunja shipped two v1.0 release candidates through late 2025 and early 2026, then jumped to a v2 series whose first widely-tagged point release, v2.2.1, is dominated by security work. The latest release patches multiple SSRF and IDOR vulnerabilities, enforces disabled/locked-account semantics across every auth surface (OIDC, API tokens, CalDAV, LDAP), and adds a shared SSRF-safe HTTP client that webhooks and migrations now route through. User-facing feature work has slowed; the visible energy is in plumbing and audit cleanup.
The arc moves from feature-completion (S3 storage, drag-and-drop project moves, hover previews in late 2025) toward platform credibility — closing security gaps a self-hosted task tool needs to clear before serious team adoption. The rapid version-number jump from v1.0.0-rc4 to v2.2.1 in two months suggests v1.0 shipped and the team tagged a v2 line aimed at addressing accumulated authz debt. Expect the next several releases to keep the security-first posture rather than return to a feature push.
The next release will likely continue closing remaining authz edges (more IDOR audits, additional credential-stripping in API responses) and bundle a translations and dependency sweep. A user-facing feature push probably waits until the security work plateaus.
Other PM products tracked by Sparkpulse, ranked by recent ship velocity. Each card links to a full editorial trajectory and lets you pivot into a head-to-head comparison with either Process Street or Vikunja.
A critical auth bypass lands in the middle of Wakapi's slow identity rebuild.
NocoBase runs two release lines at once while the v3 client rewrite absorbs the AI work
Hive ships in batches, and this one is all planning accuracy and admin control.
Plane ships a fortnightly digest, and the AI layer is where the real work is going.
Ever Teams shipped ten tags in twelve hours and one of them touched the product
Asana's agent left the app — it now answers work questions inside Slack threads.
See all Process Street alternatives → · See all Vikunja alternatives →
Latest ship moves from both products, interleaved chronologically. ⚡ = editorial spark.
They serve adjacent needs but don't currently overlap on shipped themes. Process Street is currently shipping more aggressively (velocity 5.0 vs 0.0), with 0 editorial sparks in the last 30 days against 0. See the at-a-glance table above for a side-by-side breakdown of velocity, recent sparks, and editorial themes.
Sparkpulse doesn't pick a winner — we score release velocity, not feature parity. Process Street is currently shipping more aggressively (velocity 5.0 vs 0.0), with 0 editorial sparks in the last 30 days against 0. For your specific use case, the alternatives sections above list other PM products to evaluate alongside.
Top Process Street alternatives in PM are ranked by recent ship velocity. Browse the "Process Street alternatives" section above for the current picks, or visit /alternatives/process-st for the full list with editorial commentary on each.
Top Vikunja alternatives in PM are ranked by recent ship velocity. Browse the "Vikunja alternatives" section above for the current picks, or visit /alternatives/vikunja for the full list with editorial commentary on each.