Vikunja vs Aha!
Side-by-side trajectory, velocity, and editorial themes.
Vikunja crossed the v1.0 finish line and pivoted hard into security hardening.
Vikunja shipped two v1.0 release candidates through late 2025 and early 2026, then jumped to a v2 series whose first widely-tagged point release, v2.2.1, is dominated by security work. The latest release patches multiple SSRF and IDOR vulnerabilities, enforces disabled/locked-account semantics across every auth surface (OIDC, API tokens, CalDAV, LDAP), and adds a shared SSRF-safe HTTP client that webhooks and migrations now route through. User-facing feature work has slowed; the visible energy is in plumbing and audit cleanup.
The arc moves from feature-completion (S3 storage, drag-and-drop project moves, hover previews in late 2025) toward platform credibility — closing security gaps a self-hosted task tool needs to clear before serious team adoption. The rapid version-number jump from v1.0.0-rc4 to v2.2.1 in two months suggests v1.0 shipped and the team tagged a v2 line aimed at addressing accumulated authz debt. Expect the next several releases to keep the security-first posture rather than return to a feature push.
The next release will likely continue closing remaining authz edges (more IDOR audits, additional credential-stripping in API responses) and bundle a translations and dependency sweep. A user-facing feature push probably waits until the security work plateaus.
Aha! Builder is reshaping the product — prototypes, databases, and an MCP server land in the same week.
Aha! is shipping at a daily cadence and pushing in two directions simultaneously. First, the Builder surface is being fleshed out into a full prototype-and-validate environment: built-in databases with preview/production split, in-app feedback widgets, prototypes saved as records linked to product work, AI-assisted feature mockups. Second, AI is being layered across the existing PM workflow — an MCP server that exposes Aha! data to Claude, ChatGPT, and Copilot; AI-built customer-insights reports; AI-assisted roadmap presentations. A new HubSpot integration on the Ideas side rounds out the recent moves.
Aha! is positioning to defend its roadmap-software seat against AI-native challengers (the Productboard comparison post is a tell) by becoming the layer where product managers prototype, validate with users, and connect the result back to the roadmap. The Builder line is the strategic bet — taking PMs out of Figma/Retool tooling and keeping them in Aha!. The MCP server matters in parallel: it positions Aha! as a data source for any agent runtime, not just as a destination workflow tool.
Expect Aha! Builder to be packaged as a standalone SKU (or upgraded tier) within the next quarter, given how complete the prototype-database-feedback loop now is. The MCP server is likely the first of several agent-integration surfaces; a second wave will probably target Linear/Jira-style sync agents that bridge Aha! into engineering execution tools.
See more alternatives to Vikunja →
See more alternatives to Aha! →