← Back to home
Comparison · PM

Grocy vs Wakapi

A side-by-side editorial comparison of Grocy and Wakapi — release velocity, themes, recent moves, and the top alternatives to consider.

Shared themes:self-hosted

Grocy vs Wakapi: at a glance

FeatureGrocyWakapi
SectorPMPM
Velocity score0.02.5
Sparks · 30d00
Top themesself-hosted, household-erp, barcode-lookup, plugin-interfacetime-tracking, self-hosted, oidc, auth-bypass
Last editorial update15d ago1h ago
WebsiteVisit →Visit →

What is Grocy?

Grocy opened a plugin seam for barcode lookups, then went quiet for a year.

Grocy releases on a slow, maintainer-paced rhythm — a handful of releases across 2024 and 2025, then a single 4.6.0 in March 2026 that makes PHP 8.5 with SQLite 3.40+ the only supported runtime. The functional work concentrates on stock handling: quantity-unit defaults that stay editable until a product has been in stock, automatic 1:1 unit conversions when no default applies, and a long tail of filter and validation fixes across the stock, shopping list and master data pages.

Read the full Grocy trajectory →

What is Wakapi?

A critical auth bypass lands in the middle of Wakapi's slow identity rebuild.

Wakapi's recent releases cluster around identity and deployment rather than time tracking itself: OpenID Connect login, then an OIDC-only mode, multiple API keys per user, and a switch from Alpine to a distroless nonroot container image. The 2.17.x line has carried two security fixes now — a responsibly disclosed issue in 2.17.3, and a critical authentication bypass in 2.17.6 caused by a shared cache key namespace. Release notes are mostly bare issue numbers, so several entries state that something changed without saying what.

Read the full Wakapi trajectory →

Grocy vs Wakapi: editorial side-by-side

G0.0

Grocy opened a plugin seam for barcode lookups, then went quiet for a year.

◆ Current state

Grocy releases on a slow, maintainer-paced rhythm — a handful of releases across 2024 and 2025, then a single 4.6.0 in March 2026 that makes PHP 8.5 with SQLite 3.40+ the only supported runtime. The functional work concentrates on stock handling: quantity-unit defaults that stay editable until a product has been in stock, automatic 1:1 unit conversions when no default applies, and a long tail of filter and validation fixes across the stock, shopping list and master data pages.

◆ Where it's heading

The notable structural move was 4.4.0, which introduced external barcode lookup as a product-picker workflow with a pluggable backend and shipped an Open Food Facts plugin on by default. That converted Grocy from a purely self-contained ledger into something that pulls product data from the outside world, and the releases since have mostly been refining that plugin — localized names, empty-name handling, image URLs with query parameters. Beyond it, the direction is consolidation: fewer rough edges, a tighter supported runtime, no expansion of scope.

◆ Prediction

Expect continued single-release years focused on stock and quantity-unit correctness. The barcode plugin interface is the one place where new capability could arrive without new maintainer surface, so additional lookup providers are the most plausible next addition.

W2.5

A critical auth bypass lands in the middle of Wakapi's slow identity rebuild.

◆ Current state

Wakapi's recent releases cluster around identity and deployment rather than time tracking itself: OpenID Connect login, then an OIDC-only mode, multiple API keys per user, and a switch from Alpine to a distroless nonroot container image. The 2.17.x line has carried two security fixes now — a responsibly disclosed issue in 2.17.3, and a critical authentication bypass in 2.17.6 caused by a shared cache key namespace. Release notes are mostly bare issue numbers, so several entries state that something changed without saying what.

◆ Where it's heading

The direction is a self-hosted tool making itself deployable somewhere other than one developer's server. External identity providers, an option to disable local login entirely, per-key credentials and a container that runs as a nonroot user are the requirements that come from someone else's security review. The 2.17.6 bypass sits awkwardly against that: a cache keyed without proper namespacing is exactly the class of bug that multi-tenant deployment surfaces, which suggests the auth work is now being exercised harder than the code was written for. Releases have also thinned to roughly one a month from a much faster earlier cadence.

◆ Prediction

The identity and packaging thread is the only sustained one in this feed, so further hardening in that area is the most likely continuation; the sparse release notes make anything more specific guesswork.

Alternatives to Grocy and Wakapi

Other PM products tracked by Sparkpulse, ranked by recent ship velocity. Each card links to a full editorial trajectory and lets you pivot into a head-to-head comparison with either Grocy or Wakapi.

See all Grocy alternatives → · See all Wakapi alternatives →

Recent activity from Grocy and Wakapi

Latest ship moves from both products, interleaved chronologically. ⚡ = editorial spark.

  1. 7h agoWakapiCritical auth bypass from a shared cache key namespace
  2. 1mo agoWakapiRelease 2.17.5
  3. 2mo agoWakapiRelease 2.17.4
  4. 4mo agoWakapiSecurity fix, relay endpoint dropped, summaries may need regenerating
  5. 5mo agoGrocyPHP 8.5 becomes the only supported runtime
  6. 5mo agoWakapiDistroless nonroot container image; SQLite permissions need fixing
  7. 6mo agoWakapiOIDC-only login mode disables local accounts
  8. 1y agoGrocyOpen Food Facts lookup fixes and a default-store column
  9. 1y agoGrocyLocalized product names and shopping list rounding fixes
  10. 1y agoGrocyBarcode plugin pointed at the production Open Food Facts API
  11. 1y agoGrocyExternal barcode lookup arrives as a pluggable workflow
  12. 1y agoGrocyStock form validation and Scan Mode fixes

Frequently asked questions

What is the difference between Grocy and Wakapi?

Both compete on the same themes — self-hosted — within PM. Wakapi is currently shipping more aggressively (velocity 2.5 vs 0.0), with 0 editorial sparks in the last 30 days against 0. See the at-a-glance table above for a side-by-side breakdown of velocity, recent sparks, and editorial themes.

Is Grocy better than Wakapi?

Sparkpulse doesn't pick a winner — we score release velocity, not feature parity. Wakapi is currently shipping more aggressively (velocity 2.5 vs 0.0), with 0 editorial sparks in the last 30 days against 0. For your specific use case, the alternatives sections above list other PM products to evaluate alongside.

What are the best alternatives to Grocy?

Top Grocy alternatives in PM are ranked by recent ship velocity. Browse the "Grocy alternatives" section above for the current picks, or visit /alternatives/grocy for the full list with editorial commentary on each.

What are the best alternatives to Wakapi?

Top Wakapi alternatives in PM are ranked by recent ship velocity. Browse the "Wakapi alternatives" section above for the current picks, or visit /alternatives/wakapi for the full list with editorial commentary on each.