← Back to home
Comparison · Comms

Roundcube vs Maddy

A side-by-side editorial comparison of Roundcube and Maddy — release velocity, themes, recent moves, and the top alternatives to consider.

Shared themes:self-hosted

Roundcube vs Maddy: at a glance

FeatureRoundcubeMaddy
SectorCommsComms
Velocity score5.00.0
Sparks · 30d00
Top themeswebmail, php, security, oidcmail-server, self-hosted, golang, zero-downtime-reload
Last editorial update1d ago1h ago
WebsiteVisit →Visit →

What is Roundcube?

After four years, Roundcube 1.7 lands — and the release stream is otherwise all CVEs

Roundcube maintains two lines in lockstep: 1.6 as LTS and 1.7 as stable, with security fixes released to both on the same day. The vulnerability stream is heavy and varied — stored XSS via an unescaped attachment MIME type (CVE-2026-54432), a pre-auth SQL injection in the virtuser_query plugin, CSS injection through SVG animate, SSRF bypasses via local address URLs, an infinite loop in the TNEF decoder. Version 1.7.0, released in May after almost four years of development, is the only feature release in the window.

Read the full Roundcube trajectory →

What is Maddy?

A one-binary mail server learning to behave like production infrastructure.

maddy is an all-in-one SMTP and IMAP server written in Go, aimed at people who want a working mail host without assembling Postfix, Dovecot and a policy daemon themselves. The 0.9 line moved quickly — 0.9.0 through 0.9.5 between late March and late May — with the sequence following a recognisable shape: a feature release, an immediate patch for a broken integration, a security release, then cleanup. Configuration is directive-based, and much of the changelog concerns the behaviour of individual modules like auth.ldap, check.rspamd and check.dnsbl.

Read the full Maddy trajectory →

Roundcube vs Maddy: editorial side-by-side

R5.0

After four years, Roundcube 1.7 lands — and the release stream is otherwise all CVEs

◆ Current state

Roundcube maintains two lines in lockstep: 1.6 as LTS and 1.7 as stable, with security fixes released to both on the same day. The vulnerability stream is heavy and varied — stored XSS via an unescaped attachment MIME type (CVE-2026-54432), a pre-auth SQL injection in the virtuser_query plugin, CSS injection through SVG animate, SSRF bypasses via local address URLs, an infinite loop in the TNEF decoder. Version 1.7.0, released in May after almost four years of development, is the only feature release in the window.

◆ Where it's heading

The arc is a long-lived webmail codebase paying down structural risk. 1.7.0's headline changes are defensive rather than user-facing: a mandatory public_html/ entry point so installations aren't exposed by default, improved OAuth2/OIDC support including discovery and logout, removed code bloat and automated code style and quality checks. Everything since has been paired security releases across both lines, several of them reporting classes of bug — sanitizer bypasses, injection through plugin queries — that the 1.7 hardening work is aimed at. Expect the security cadence to stay high while the 1.6 LTS remains supported.

◆ Prediction

Expect continued same-day paired security releases on 1.6 and 1.7, with 1.7.x accruing incremental OIDC and sanitizer hardening before any 1.8 work becomes visible.

M
Maddy
COMMS
0.0

A one-binary mail server learning to behave like production infrastructure.

◆ Current state

maddy is an all-in-one SMTP and IMAP server written in Go, aimed at people who want a working mail host without assembling Postfix, Dovecot and a policy daemon themselves. The 0.9 line moved quickly — 0.9.0 through 0.9.5 between late March and late May — with the sequence following a recognisable shape: a feature release, an immediate patch for a broken integration, a security release, then cleanup. Configuration is directive-based, and much of the changelog concerns the behaviour of individual modules like auth.ldap, check.rspamd and check.dnsbl.

◆ Where it's heading

The project is systematically removing the compromises that made early versions convenient. Obsolete SASL LOGIN was disabled by default, the STARTTLS plaintext fallback was dropped, the maddyctl symlink behaviour and the implicit run command were deleted after four years of deprecation warnings, and libdns providers that have not kept up with 1.x are being cut. Running the other way is operational maturity: no-downtime config reload, queue-length metrics, OpenMetrics fixes, systemd readiness reporting, and SLSA build attestations on release artifacts. This is a project moving from hobbyist-friendly to operator-friendly, and accepting breakage to get there.

◆ Prediction

0.10.0 is already scoped by the deprecations announced in 0.9.1 — expect the flagged libdns providers to be removed and gandi to require Bearer tokens. Given the 0.9.x pattern, a feature release followed quickly by an integration fix is the likely shape.

Alternatives to Roundcube and Maddy

Other Comms products tracked by Sparkpulse, ranked by recent ship velocity. Each card links to a full editorial trajectory and lets you pivot into a head-to-head comparison with either Roundcube or Maddy.

See all Roundcube alternatives → · See all Maddy alternatives →

Recent activity from Roundcube and Maddy

Latest ship moves from both products, interleaved chronologically. ⚡ = editorial spark.

  1. 27d agoRoundcubeRoundcube LTS patches attachment XSS, SSRF and a TNEF loop
  2. 27d agoRoundcubeRoundcube 1.7 gets the same attachment XSS and SSRF fixes
  3. 1mo agoRoundcubeRoundcube LTS fixes a pre-auth SQL injection in virtuser_query
  4. 1mo agoRoundcubeRoundcube 1.7.1 carries the pre-auth SQL injection fixes
  5. 2mo agoMaddymaddy 0.9.5 fixes nested pipeline logging and systemd reload reporting
  6. 2mo agoRoundcubeRoundcube Webmail 1.7.0
  7. 3mo agoMaddymaddy 0.9.4 removes the maddyctl symlink and implicit run command
  8. 3mo agoMaddymaddy 0.9.3 patches an LDAP injection flaw in auth.ldap
  9. 4mo agoRoundcubeRoundcube 1.6.15 fixes an SVG animate bypass and search regressions
  10. 4mo agoMaddymaddy 0.9.2 fixes an rspamd panic on unspecified tls_client
  11. 4mo agoMaddymaddy 0.9.1 flags libdns providers for removal in 0.10.0
  12. 4mo agoMaddymaddy 0.9.0 adds no-downtime configuration reloading

Frequently asked questions

What is the difference between Roundcube and Maddy?

Both compete on the same themes — self-hosted — within Comms. Roundcube is currently shipping more aggressively (velocity 5.0 vs 0.0), with 0 editorial sparks in the last 30 days against 0. See the at-a-glance table above for a side-by-side breakdown of velocity, recent sparks, and editorial themes.

Is Roundcube better than Maddy?

Sparkpulse doesn't pick a winner — we score release velocity, not feature parity. Roundcube is currently shipping more aggressively (velocity 5.0 vs 0.0), with 0 editorial sparks in the last 30 days against 0. For your specific use case, the alternatives sections above list other Comms products to evaluate alongside.

What are the best alternatives to Roundcube?

Top Roundcube alternatives in Comms are ranked by recent ship velocity. Browse the "Roundcube alternatives" section above for the current picks, or visit /alternatives/roundcube for the full list with editorial commentary on each.

What are the best alternatives to Maddy?

Top Maddy alternatives in Comms are ranked by recent ship velocity. Browse the "Maddy alternatives" section above for the current picks, or visit /alternatives/maddy for the full list with editorial commentary on each.