← Back to all sparks
P

Postiz

MKT AUTO
Velocity0.0

Self-hostable social media scheduling and publishing tool

Postiz is hardening the plumbing: streamed uploads, no duplicate posts, and a sturdier MCP server.

social media schedulingreliabilitysecuritymcpself-hosted
◆Current state
Postiz, an open-source social scheduler, spent its last two visible releases on reliability and security. v2.21.10 was an urgent security fix, and v2.23.0 streams media uploads instead of buffering them, adds a pending-post workflow that stops duplicate publishes after interrupted attempts, and adds SSRF guards. Its MCP server also got stateless HTTP and OAuth discovery fixes.
◆Where it's heading
The work points to a product being run at larger scale by self-hosters and agencies: memory for large videos, idempotent publishing, and hardened fetch paths are operator problems. Continued MCP fixes show Postiz treats agent-driven posting as a supported entry point, not an experiment.
◆Prediction
Expect more MCP connector fixes and per-network upload tuning like the chunked X and LinkedIn video uploads; the entries do not show which new feature, if any, is next.

◆Recent moves

  1. 1mo ago

    Streamed media uploads, duplicate-post protection & MCP fixes

    v2.23.0 is the clearest statement of Postiz's current focus: streamed uploads cut worker memory for large videos, and a pending-post state prevents double posting when a publish is interrupted. Stateless MCP transport and SSRF protection round out a release about running Postiz reliably rather than adding surface area.

    View source ↗
  2. 3mo ago

    Postiz v2.21.10 patches security advisory PSA-2026-NWZN9J

    A security release for advisory PSA-2026-NWZN9J, with an instruction for all users to upgrade immediately. It set up the security hardening that continued into v2.23.0.

    View source ↗