← Back to home
Comparison · PM

Vikunja vs Aha!

Side-by-side trajectory, velocity, and editorial themes.

V0.0

Vikunja crossed the v1.0 finish line and pivoted hard into security hardening.

◆ Current state

Vikunja shipped two v1.0 release candidates through late 2025 and early 2026, then jumped to a v2 series whose first widely-tagged point release, v2.2.1, is dominated by security work. The latest release patches multiple SSRF and IDOR vulnerabilities, enforces disabled/locked-account semantics across every auth surface (OIDC, API tokens, CalDAV, LDAP), and adds a shared SSRF-safe HTTP client that webhooks and migrations now route through. User-facing feature work has slowed; the visible energy is in plumbing and audit cleanup.

◆ Where it's heading

The arc moves from feature-completion (S3 storage, drag-and-drop project moves, hover previews in late 2025) toward platform credibility — closing security gaps a self-hosted task tool needs to clear before serious team adoption. The rapid version-number jump from v1.0.0-rc4 to v2.2.1 in two months suggests v1.0 shipped and the team tagged a v2 line aimed at addressing accumulated authz debt. Expect the next several releases to keep the security-first posture rather than return to a feature push.

◆ Prediction

The next release will likely continue closing remaining authz edges (more IDOR audits, additional credential-stripping in API responses) and bundle a translations and dependency sweep. A user-facing feature push probably waits until the security work plateaus.

A6.3

Aha! Builder is reshaping the product — prototypes, databases, and an MCP server land in the same week.

◆ Current state

Aha! is shipping at a daily cadence and pushing in two directions simultaneously. First, the Builder surface is being fleshed out into a full prototype-and-validate environment: built-in databases with preview/production split, in-app feedback widgets, prototypes saved as records linked to product work, AI-assisted feature mockups. Second, AI is being layered across the existing PM workflow — an MCP server that exposes Aha! data to Claude, ChatGPT, and Copilot; AI-built customer-insights reports; AI-assisted roadmap presentations. A new HubSpot integration on the Ideas side rounds out the recent moves.

◆ Where it's heading

Aha! is positioning to defend its roadmap-software seat against AI-native challengers (the Productboard comparison post is a tell) by becoming the layer where product managers prototype, validate with users, and connect the result back to the roadmap. The Builder line is the strategic bet — taking PMs out of Figma/Retool tooling and keeping them in Aha!. The MCP server matters in parallel: it positions Aha! as a data source for any agent runtime, not just as a destination workflow tool.

◆ Prediction

Expect Aha! Builder to be packaged as a standalone SKU (or upgraded tier) within the next quarter, given how complete the prototype-database-feedback loop now is. The MCP server is likely the first of several agent-integration surfaces; a second wave will probably target Linear/Jira-style sync agents that bridge Aha! into engineering execution tools.

See more alternatives to Vikunja
See more alternatives to Aha!