CommaFeed
CommaFeed is patching its way through the attack surface a self-hosted reader inherits
A side-by-side editorial comparison of Document360 and Wiki.js — release velocity, themes, recent moves, and the top alternatives to consider.
| Feature | Document360 | Wiki.js |
|---|---|---|
| Sector | Collab | Collab |
| Velocity score | 6.3 | 0.0 |
| Sparks · 30d | 1 | 0 |
| Top themes | api, oauth, mcp, knowledge base | wiki, self-hosted, security-patches, maintenance-mode |
| Last editorial update | 1d ago | 19d ago |
| Website | — | Visit → |
Document360 rebuilt its API for agents; now it's turning the AI inward on authoring.
Monthly point releases on a steady 12.x line, each a themed bundle rather than a fix list. The last three releases rebuilt the developer-facing surface: an interactive API reference with an in-page Try It! console, a ground-up API v3 with OAuth 2.0 and scoped keys, and a Widget 2.0 embedding architecture now rolling out with a migration deadline. Around that, Eddy AI and the MCP server have been gaining governance controls — reader-group restrictions, workflow permissions, usage analytics — more often than new capabilities.
Wiki.js 2.x is in security-maintenance mode, and the feed has been quiet since May
Six patch releases on the 2.5 line, most of them fixes. The substantive ones are security: a permissions flaw allowing user assignment to elevated groups, open redirect validation on the login redirect cookie, authentication for GraphQL subscription WebSocket connections, prototype pollution in Rocket.Chat auth, and secure cookie flags on HTTPS sites. Two small features appear — OIDC and OAuth2 avatar claim mapping, and MySQL socket path connections.
Monthly point releases on a steady 12.x line, each a themed bundle rather than a fix list. The last three releases rebuilt the developer-facing surface: an interactive API reference with an in-page Try It! console, a ground-up API v3 with OAuth 2.0 and scoped keys, and a Widget 2.0 embedding architecture now rolling out with a migration deadline. Around that, Eddy AI and the MCP server have been gaining governance controls — reader-group restrictions, workflow permissions, usage analytics — more often than new capabilities.
Two threads run through the year. One makes the knowledge base machine-readable and machine-writable: MCP server, automatic llms.txt, open-an-article-in-ChatGPT-or-Claude, then API v3. The other fences that access with admin controls before enterprise buyers have to ask. The newest release turns the AI inward for the first time — the redesigned Publish dialog puts suggestions and validation in the author's path rather than the reader's, which is a different customer for the same capability.
The AI suggestions now sitting in the Publish dialog are the obvious candidate to move into the editor itself, and the advanced v3 endpoints sold as an add-on look like the seed of a higher API tier. The Widget 2.0 forced migration is the near-term execution risk, since it puts required technical work on existing customers to a fixed timeline.
Six patch releases on the 2.5 line, most of them fixes. The substantive ones are security: a permissions flaw allowing user assignment to elevated groups, open redirect validation on the login redirect cookie, authentication for GraphQL subscription WebSocket connections, prototype pollution in Rocket.Chat auth, and secure cookie flags on HTTPS sites. Two small features appear — OIDC and OAuth2 avatar claim mapping, and MySQL socket path connections.
This is a mature 2.x line receiving externally reported vulnerability fixes and community contributions rather than product direction. Several fixes credit outside researchers and contributors, which is what maintenance looks like when the maintainer's attention is elsewhere. Release intervals stretched from days in January to nothing since early May.
More 2.5.x patches driven by reported vulnerabilities are the likely continuation. Nothing in this window indicates when feature work resumes.
Other Collab products tracked by Sparkpulse, ranked by recent ship velocity. Each card links to a full editorial trajectory and lets you pivot into a head-to-head comparison with either Document360 or Wiki.js.
CommaFeed is patching its way through the attack surface a self-hosted reader inherits
SiYuan stabilises 3.8.1 after a seven-build beta run, all of it widening the agent surface it opened in 3.8.0
Hive ships in batches, and this one is all planning accuracy and admin control.
Teable ships daily, and the work has moved from grid features to platform governance.
Simpplr publishes the research that names the gap, then ships the product that closes it.
NetNewsWire's 7.1.3 train has moved from rebuilding sync to sweeping up what the rebuild disturbed.
See all Document360 alternatives → · See all Wiki.js alternatives →
Latest ship moves from both products, interleaved chronologically. ⚡ = editorial spark.
They serve adjacent needs but don't currently overlap on shipped themes. Document360 is currently shipping more aggressively (velocity 6.3 vs 0.0), with 1 editorial sparks in the last 30 days against 0. See the at-a-glance table above for a side-by-side breakdown of velocity, recent sparks, and editorial themes.
Sparkpulse doesn't pick a winner — we score release velocity, not feature parity. Document360 is currently shipping more aggressively (velocity 6.3 vs 0.0), with 1 editorial sparks in the last 30 days against 0. For your specific use case, the alternatives sections above list other Collab products to evaluate alongside.
Top Document360 alternatives in Collab are ranked by recent ship velocity. Browse the "Document360 alternatives" section above for the current picks, or visit /alternatives/document360 for the full list with editorial commentary on each.
Top Wiki.js alternatives in Collab are ranked by recent ship velocity. Browse the "Wiki.js alternatives" section above for the current picks, or visit /alternatives/wiki-js for the full list with editorial commentary on each.