← Back to home
Comparison · PM

Phorge vs Wakapi

A side-by-side editorial comparison of Phorge and Wakapi — release velocity, themes, recent moves, and the top alternatives to consider.

Phorge vs Wakapi: at a glance

FeaturePhorgeWakapi
SectorPMPM
Velocity score0.02.5
Sparks · 30d00
Top themesphabricator-fork, code-review, legacy-maintenance, subversiontime-tracking, self-hosted, oidc, auth-bypass
Last editorial update13d ago1h ago
WebsiteVisit →Visit →

What is Phorge?

Phorge tags a release per fix, and years pass between the ones that reach this feed.

Phorge, the community continuation of Phabricator, tags releases named for the week they land and for the single change they carry. The entries visible here span three years and are all small defensive fixes: query errors instead of raw exceptions on malformed task IDs, a readable error screen when configuration fails to load, an empty authored date on Subversion commits, a crash in a commit hook when getenv returns false.

Read the full Phorge trajectory →

What is Wakapi?

A critical auth bypass lands in the middle of Wakapi's slow identity rebuild.

Wakapi's recent releases cluster around identity and deployment rather than time tracking itself: OpenID Connect login, then an OIDC-only mode, multiple API keys per user, and a switch from Alpine to a distroless nonroot container image. The 2.17.x line has carried two security fixes now — a responsibly disclosed issue in 2.17.3, and a critical authentication bypass in 2.17.6 caused by a shared cache key namespace. Release notes are mostly bare issue numbers, so several entries state that something changed without saying what.

Read the full Wakapi trajectory →

Phorge vs Wakapi: editorial side-by-side

P0.0

Phorge tags a release per fix, and years pass between the ones that reach this feed.

◆ Current state

Phorge, the community continuation of Phabricator, tags releases named for the week they land and for the single change they carry. The entries visible here span three years and are all small defensive fixes: query errors instead of raw exceptions on malformed task IDs, a readable error screen when configuration fails to load, an empty authored date on Subversion commits, a crash in a commit hook when getenv returns false.

◆ Where it's heading

This is a project in stewardship rather than development. The work concentrates on the places an inherited codebase breaks — Subversion paths that upstream barely exercised, error handling that assumed configuration always loads, exception types leaking to users — and each fix is documented with a reproduction and test plan in the old Phabricator review style. Nothing in this window suggests new capability; the goal visible in the changelog is that the software keeps running for the installs that already depend on it.

◆ Prediction

The pattern points to more individually tagged small fixes in legacy code paths and error handling; there is no signal here of a larger release being assembled.

W2.5

A critical auth bypass lands in the middle of Wakapi's slow identity rebuild.

◆ Current state

Wakapi's recent releases cluster around identity and deployment rather than time tracking itself: OpenID Connect login, then an OIDC-only mode, multiple API keys per user, and a switch from Alpine to a distroless nonroot container image. The 2.17.x line has carried two security fixes now — a responsibly disclosed issue in 2.17.3, and a critical authentication bypass in 2.17.6 caused by a shared cache key namespace. Release notes are mostly bare issue numbers, so several entries state that something changed without saying what.

◆ Where it's heading

The direction is a self-hosted tool making itself deployable somewhere other than one developer's server. External identity providers, an option to disable local login entirely, per-key credentials and a container that runs as a nonroot user are the requirements that come from someone else's security review. The 2.17.6 bypass sits awkwardly against that: a cache keyed without proper namespacing is exactly the class of bug that multi-tenant deployment surfaces, which suggests the auth work is now being exercised harder than the code was written for. Releases have also thinned to roughly one a month from a much faster earlier cadence.

◆ Prediction

The identity and packaging thread is the only sustained one in this feed, so further hardening in that area is the most likely continuation; the sparse release notes make anything more specific guesswork.

Alternatives to Phorge and Wakapi

Other PM products tracked by Sparkpulse, ranked by recent ship velocity. Each card links to a full editorial trajectory and lets you pivot into a head-to-head comparison with either Phorge or Wakapi.

See all Phorge alternatives → · See all Wakapi alternatives →

Recent activity from Phorge and Wakapi

Latest ship moves from both products, interleaved chronologically. ⚡ = editorial spark.

  1. 7h agoWakapiCritical auth bypass from a shared cache key namespace
  2. 1mo agoWakapiRelease 2.17.5
  3. 1mo agoPhorge2026.27: Maniphest search: Throw a Query Error when passing non-digit task IDs
  4. 2mo agoWakapiRelease 2.17.4
  5. 4mo agoWakapiSecurity fix, relay endpoint dropped, summaries may need regenerating
  6. 5mo agoWakapiDistroless nonroot container image; SQLite permissions need fixing
  7. 6mo agoWakapiOIDC-only login mode disables local accounts
  8. 8mo agoPhorge2025.51: Don't crash when failed to load configuration
  9. 1y agoPhorge2024.35: Subversion: fix empty "Authored on" date on commit pages
  10. 3y agoPhorge2023.23: Mobile: hide unuseful "Persistent Chat" checkbox
  11. 3y agoPhorge2023.17: Fix InvalidArgumentException on commit hook

Frequently asked questions

What is the difference between Phorge and Wakapi?

They serve adjacent needs but don't currently overlap on shipped themes. Wakapi is currently shipping more aggressively (velocity 2.5 vs 0.0), with 0 editorial sparks in the last 30 days against 0. See the at-a-glance table above for a side-by-side breakdown of velocity, recent sparks, and editorial themes.

Is Phorge better than Wakapi?

Sparkpulse doesn't pick a winner — we score release velocity, not feature parity. Wakapi is currently shipping more aggressively (velocity 2.5 vs 0.0), with 0 editorial sparks in the last 30 days against 0. For your specific use case, the alternatives sections above list other PM products to evaluate alongside.

What are the best alternatives to Phorge?

Top Phorge alternatives in PM are ranked by recent ship velocity. Browse the "Phorge alternatives" section above for the current picks, or visit /alternatives/phorge for the full list with editorial commentary on each.

What are the best alternatives to Wakapi?

Top Wakapi alternatives in PM are ranked by recent ship velocity. Browse the "Wakapi alternatives" section above for the current picks, or visit /alternatives/wakapi for the full list with editorial commentary on each.