Elgg
A social-networking engine in careful maintenance across two supported branches.
A side-by-side editorial comparison of CommaFeed and Outline — release velocity, themes, recent moves, and the top alternatives to consider.
| Feature | CommaFeed | Outline |
|---|---|---|
| Sector | Collab | Collab |
| Velocity score | 5.0 | 2.5 |
| Sparks · 30d | 0 | 0 |
| Top themes | rss-reader, self-hosted, security-hardening, ssrf | knowledge-base, mcp, agent-write-access, document-permissions |
| Last editorial update | 15h ago | 13d ago |
| Website | Visit → | — |
CommaFeed is patching its way through the attack surface a self-hosted reader inherits
CommaFeed's 7.x line has become a sustained security pass. The newest patch closes Host header injection on the password recovery endpoint and adds a commafeed.password-recovery-public-base-url setting so the email base URL is configured rather than taken from the request. Behind it: local address blocking made secure by default alongside Google Reader API support in 7.3.0, javascript: URLs filtered at parse time in 7.2.1, and SSRF limits on the image proxy in 7.2.0.
Outline gave AI assistants write access to the wiki, then spent months on the human side.
The April MCP expansion is the structural change in this window: assistants can patch documents, move and delete documents and collections, work with attachments, and create and resolve inline comments. Everything since has been human-facing and smaller — request-access flows for documents members cannot open, email subscriptions to publicly shared documents with change summaries, task list and checkbox handling in the editor, and profile cards on avatar hover.
CommaFeed's 7.x line has become a sustained security pass. The newest patch closes Host header injection on the password recovery endpoint and adds a commafeed.password-recovery-public-base-url setting so the email base URL is configured rather than taken from the request. Behind it: local address blocking made secure by default alongside Google Reader API support in 7.3.0, javascript: URLs filtered at parse time in 7.2.1, and SSRF limits on the image proxy in 7.2.0.
Every release in this stretch closes a path where content or a request from outside the instance was trusted too far - feed URLs reaching internal addresses, proxied images, javascript: links, and now a header shaping an outbound email. That is the checklist of a project being run as a multi-user hosted service rather than a single-user tool, and it follows directly from the 7.0.0 decision to sandbox filter expressions. Feature work continues in parallel but is clearly the smaller half.
The remaining untrusted-input surfaces - OPML import and the feed fetcher's redirect handling - are the likely next targets. The pattern of shipping each fix as its own patch release should continue rather than batching them.
The April MCP expansion is the structural change in this window: assistants can patch documents, move and delete documents and collections, work with attachments, and create and resolve inline comments. Everything since has been human-facing and smaller — request-access flows for documents members cannot open, email subscriptions to publicly shared documents with change summaries, task list and checkbox handling in the editor, and profile cards on avatar hover.
Two audiences are being served in sequence. The MCP work moved assistants from reading the knowledge base to editing it, including the collection structure itself. The releases after it close ordinary gaps in how people find, follow and get into documents — which is what a wiki needs before more of its edits arrive from automation. Release cadence is roughly monthly with entries that describe outcomes rather than changelogs.
Expect the human-facing polish to continue at its current pace, with any next structural move likely extending the MCP surface further into permissions and collection management, since that is where the existing tools stop.
Other Collab products tracked by Sparkpulse, ranked by recent ship velocity. Each card links to a full editorial trajectory and lets you pivot into a head-to-head comparison with either CommaFeed or Outline.
A social-networking engine in careful maintenance across two supported branches.
7.1.3 ships on the Mac, closing a release spent almost entirely on rebuilding Feedly sync.
HumHub's public feed carries only betas, and 1.19's is still about surviving the upgrade.
Hive keeps tightening the same three seams: planned time, admin control, and AI review scope
A dated canary most days, with the beta line carrying the same commits later.
Every v11 release pushes ABAC further out; the blog sells the air-gap story around it.
See all CommaFeed alternatives → · See all Outline alternatives →
Latest ship moves from both products, interleaved chronologically. ⚡ = editorial spark.
They serve adjacent needs but don't currently overlap on shipped themes. CommaFeed is currently shipping more aggressively (velocity 5.0 vs 2.5), with 0 editorial sparks in the last 30 days against 0. See the at-a-glance table above for a side-by-side breakdown of velocity, recent sparks, and editorial themes.
Sparkpulse doesn't pick a winner — we score release velocity, not feature parity. CommaFeed is currently shipping more aggressively (velocity 5.0 vs 2.5), with 0 editorial sparks in the last 30 days against 0. For your specific use case, the alternatives sections above list other Collab products to evaluate alongside.
Top CommaFeed alternatives in Collab are ranked by recent ship velocity. Browse the "CommaFeed alternatives" section above for the current picks, or visit /alternatives/commafeed for the full list with editorial commentary on each.
Top Outline alternatives in Collab are ranked by recent ship velocity. Browse the "Outline alternatives" section above for the current picks, or visit /alternatives/outline for the full list with editorial commentary on each.