Teable
Secrets get encrypted at rest while the computed-field engine keeps getting shored up
A side-by-side editorial comparison of Elgg and SOGo — release velocity, themes, recent moves, and the top alternatives to consider.
A social-networking engine in careful maintenance across two supported branches.
Elgg is running a two-branch release cadence: a 7.0.x line taking bug fixes and a 6.3.x line receiving backports. The recent pairs shipped within two hours of each other — 7.0.5 carrying a single performance fix that stops likes generating ajax response data for unsupported entities, while 6.3.8 carries the longer list: improved sanitization of installer config values, a valid client IP for the core, embedded-image handling in notification emails, mute-option validation, and a permission check before a profile header image can be changed. Contributor counts stay in the low single digits with the same one or two maintainers on nearly every release.
SOGo's release notes have become a vulnerability disclosure channel with a version number attached.
SOGo is a self-hosted groupware suite — webmail, calendaring and contacts — maintained by Alinto. Four of the last six releases exist primarily to fix security vulnerabilities: XSS through malicious mail, SQL injection, OpenID impersonation, script execution via theme and hint query parameters. The newest, 5.12.10, fixes four more and states that all previous versions are affected, with CVE identifiers still pending at publication.
Elgg is running a two-branch release cadence: a 7.0.x line taking bug fixes and a 6.3.x line receiving backports. The recent pairs shipped within two hours of each other — 7.0.5 carrying a single performance fix that stops likes generating ajax response data for unsupported entities, while 6.3.8 carries the longer list: improved sanitization of installer config values, a valid client IP for the core, embedded-image handling in notification emails, mute-option validation, and a permission check before a profile header image can be changed. Contributor counts stay in the low single digits with the same one or two maintainers on nearly every release.
This is a mature project maintaining a stable base rather than pushing new capability, and the balance between the branches is worth noting: the older 6.3 line is receiving more substantive hardening than the current 7.0 line, which has already settled into single-commit patches. That is what a project looks like when most of its deployments have not migrated yet. The 6.3.8 items — input sanitization, permission validation before a mutating action — are the security-shaped fixes that earlier 6.3 releases summarised only as 'small security update'.
Expect the alternating pattern to continue: 7.0.x patches as issues surface, with matching 6.3.x backports carrying the hardening work, until a 7.1 cycle opens. The entries give no indication of when that might be.
SOGo is a self-hosted groupware suite — webmail, calendaring and contacts — maintained by Alinto. Four of the last six releases exist primarily to fix security vulnerabilities: XSS through malicious mail, SQL injection, OpenID impersonation, script execution via theme and hint query parameters. The newest, 5.12.10, fixes four more and states that all previous versions are affected, with CVE identifiers still pending at publication.
The pattern is a codebase whose input-handling surface is being systematically probed, largely by the community reporting to the project's bug address, and patched in batches. Release numbering has stopped being reliable as a timeline — 5.12.7 shipped after 5.12.8 — so version order tells you nothing about what a deployment contains. The two non-security releases in this window were both regression repairs from the security releases that preceded them, which is the cost of shipping fixes at this cadence.
Given four security batches in five months and CVE identifiers still being assigned retroactively, another batch on the same cadence is the most likely next release, with a regression patch following it.
Other Collab products tracked by Sparkpulse, ranked by recent ship velocity. Each card links to a full editorial trajectory and lets you pivot into a head-to-head comparison with either Elgg or SOGo.
Secrets get encrypted at rest while the computed-field engine keeps getting shored up
Security and governance controls catch up to the Copilot build-out
7.1.3 ships on the Mac, closing a release spent almost entirely on rebuilding Feedly sync.
HumHub's public feed carries only betas, and 1.19's is still about surviving the upgrade.
Hive keeps tightening the same three seams: planned time, admin control, and AI review scope
A dated canary most days, with the beta line carrying the same commits later.
Latest ship moves from both products, interleaved chronologically. ⚡ = editorial spark.
They serve adjacent needs but don't currently overlap on shipped themes. Elgg is currently shipping more aggressively (velocity 5.0 vs 2.5), with 0 editorial sparks in the last 30 days against 0. See the at-a-glance table above for a side-by-side breakdown of velocity, recent sparks, and editorial themes.
Sparkpulse doesn't pick a winner — we score release velocity, not feature parity. Elgg is currently shipping more aggressively (velocity 5.0 vs 2.5), with 0 editorial sparks in the last 30 days against 0. For your specific use case, the alternatives sections above list other Collab products to evaluate alongside.
Top Elgg alternatives in Collab are ranked by recent ship velocity. Browse the "Elgg alternatives" section above for the current picks, or visit /alternatives/elgg for the full list with editorial commentary on each.
Top SOGo alternatives in Collab are ranked by recent ship velocity. Browse the "SOGo alternatives" section above for the current picks, or visit /alternatives/sogo for the full list with editorial commentary on each.