← Back to home
Comparison · PM

OpenProject vs Wakapi

A side-by-side editorial comparison of OpenProject and Wakapi — release velocity, themes, recent moves, and the top alternatives to consider.

OpenProject vs Wakapi: at a glance

FeatureOpenProjectWakapi
SectorPMPM
Velocity score6.32.5
Sparks · 30d10
Top themesproject-management, mcp, ai-integration, open-sourcetime-tracking, self-hosted, oidc, auth-bypass
Last editorial update12d ago28d ago
WebsiteVisit →Visit →

What is OpenProject?

OpenProject's MCP Server gains write access — AI agents can now create tasks, add comments, and manage relations.

OpenProject 17.8.0 marks the most significant AI integration milestone in the product's history: the MCP Server can now create and update work packages, add comments, and manage relations — moving from a read-only query layer to a write-capable AI agent interface. The same release adds multiple target versions per work package, sprints and milestones to the project timeline, and relation display in the free Community edition. OpenProject 17.7.0 laid the organizational management foundation: departments, work-related user attributes, and individual work schedules for capacity planning.

Read the full OpenProject trajectory →

What is Wakapi?

A critical auth bypass lands in the middle of Wakapi's slow identity rebuild.

Wakapi's recent releases cluster around identity and deployment rather than time tracking itself: OpenID Connect login, then an OIDC-only mode, multiple API keys per user, and a switch from Alpine to a distroless nonroot container image. The 2.17.x line has carried two security fixes now — a responsibly disclosed issue in 2.17.3, and a critical authentication bypass in 2.17.6 caused by a shared cache key namespace. Release notes are mostly bare issue numbers, so several entries state that something changed without saying what.

Read the full Wakapi trajectory →

OpenProject vs Wakapi: editorial side-by-side

O6.3

OpenProject's MCP Server gains write access — AI agents can now create tasks, add comments, and manage relations.

◆ Current state

OpenProject 17.8.0 marks the most significant AI integration milestone in the product's history: the MCP Server can now create and update work packages, add comments, and manage relations — moving from a read-only query layer to a write-capable AI agent interface. The same release adds multiple target versions per work package, sprints and milestones to the project timeline, and relation display in the free Community edition. OpenProject 17.7.0 laid the organizational management foundation: departments, work-related user attributes, and individual work schedules for capacity planning.

◆ Where it's heading

The two-track development pattern is clear: broader project management capabilities for enterprises (resource management, capacity planning, PM² methodology support) and a rapidly maturing AI interface through the MCP Server. The progression from read-only MCP to write-capable MCP is a qualitative shift — AI assistants become active project participants rather than passive query tools. The XWiki integration in 17.6.0 shows the platform also extending into enterprise knowledge management.

◆ Prediction

The logical next step is workflow automation via the MCP Server — AI agents that can trigger status transitions, query resource availability from the 17.7.0 capacity data, or auto-assign work packages based on department membership. The data model is in place; the automation layer is the missing piece.

W2.5

A critical auth bypass lands in the middle of Wakapi's slow identity rebuild.

◆ Current state

Wakapi's recent releases cluster around identity and deployment rather than time tracking itself: OpenID Connect login, then an OIDC-only mode, multiple API keys per user, and a switch from Alpine to a distroless nonroot container image. The 2.17.x line has carried two security fixes now — a responsibly disclosed issue in 2.17.3, and a critical authentication bypass in 2.17.6 caused by a shared cache key namespace. Release notes are mostly bare issue numbers, so several entries state that something changed without saying what.

◆ Where it's heading

The direction is a self-hosted tool making itself deployable somewhere other than one developer's server. External identity providers, an option to disable local login entirely, per-key credentials and a container that runs as a nonroot user are the requirements that come from someone else's security review. The 2.17.6 bypass sits awkwardly against that: a cache keyed without proper namespacing is exactly the class of bug that multi-tenant deployment surfaces, which suggests the auth work is now being exercised harder than the code was written for. Releases have also thinned to roughly one a month from a much faster earlier cadence.

◆ Prediction

The identity and packaging thread is the only sustained one in this feed, so further hardening in that area is the most likely continuation; the sparse release notes make anything more specific guesswork.

Alternatives to OpenProject and Wakapi

Other PM products tracked by Sparkpulse, ranked by recent ship velocity. Each card links to a full editorial trajectory and lets you pivot into a head-to-head comparison with either OpenProject or Wakapi.

See all OpenProject alternatives → · See all Wakapi alternatives →

Recent activity from OpenProject and Wakapi

Latest ship moves from both products, interleaved chronologically. ⚡ = editorial spark.

  1. 14d agoOpenProjectOpenProject 17.8.0
  2. 28d agoWakapiCritical auth bypass from a shared cache key namespace
  3. 1mo agoOpenProjectOpenProject 17.7.2: bug fix release
  4. 1mo agoOpenProjectOpenProject 17.7.1: bug fix release
  5. 1mo agoOpenProjectOpenProject 17.7.0
  6. 2mo agoWakapiRelease 2.17.5
  7. 2mo agoOpenProjectOpenProject 17.6.0
  8. 3mo agoOpenProjectOpenProject 17.5.1: bug fix release
  9. 3mo agoWakapiRelease 2.17.4
  10. 5mo agoWakapiSecurity fix, relay endpoint dropped, summaries may need regenerating
  11. 6mo agoWakapiDistroless nonroot container image; SQLite permissions need fixing
  12. 7mo agoWakapiOIDC-only login mode disables local accounts

Frequently asked questions

What is the difference between OpenProject and Wakapi?

They serve adjacent needs but don't currently overlap on shipped themes. OpenProject is currently shipping more aggressively (velocity 6.3 vs 2.5), with 1 editorial sparks in the last 30 days against 0. See the at-a-glance table above for a side-by-side breakdown of velocity, recent sparks, and editorial themes.

Is OpenProject better than Wakapi?

Sparkpulse doesn't pick a winner — we score release velocity, not feature parity. OpenProject is currently shipping more aggressively (velocity 6.3 vs 2.5), with 1 editorial sparks in the last 30 days against 0. For your specific use case, the alternatives sections above list other PM products to evaluate alongside.

What are the best alternatives to OpenProject?

Top OpenProject alternatives in PM are ranked by recent ship velocity. Browse the "OpenProject alternatives" section above for the current picks, or visit /alternatives/openproject for the full list with editorial commentary on each.

What are the best alternatives to Wakapi?

Top Wakapi alternatives in PM are ranked by recent ship velocity. Browse the "Wakapi alternatives" section above for the current picks, or visit /alternatives/wakapi for the full list with editorial commentary on each.