← Back to home
Comparison · PM

Tracecat vs Vikunja

A side-by-side editorial comparison of Tracecat and Vikunja — release velocity, themes, recent moves, and the top alternatives to consider.

Tracecat vs Vikunja: at a glance

FeatureTracecatVikunja
SectorPMPM
Velocity score7.50.0
Sparks · 30d00
Top themesagentic-soar, sandbox-isolation, mcp, case-managementsecurity hardening, ssrf protection, idor fixes, account lockout
Last editorial update4d ago3mo ago
WebsiteVisit →Visit →

What is Tracecat?

Tracecat is turning case comments into an agent console while it hardens the sandbox around them

Tracecat is deep in a beta.52 release-candidate train, eight RCs in, following the beta.51 release that made the Action Gateway mandatory. Two threads dominate: agents are becoming addressable from inside case comments, and the sandbox that runs them is being bounded — socket budgets, registry artifact caches, egress filtering. The product is a security automation platform steadily converting its agent story from a feature into the primary interaction surface.

Read the full Tracecat trajectory →

What is Vikunja?

Vikunja crossed the v1.0 finish line and pivoted hard into security hardening.

Vikunja shipped two v1.0 release candidates through late 2025 and early 2026, then jumped to a v2 series whose first widely-tagged point release, v2.2.1, is dominated by security work. The latest release patches multiple SSRF and IDOR vulnerabilities, enforces disabled/locked-account semantics across every auth surface (OIDC, API tokens, CalDAV, LDAP), and adds a shared SSRF-safe HTTP client that webhooks and migrations now route through. User-facing feature work has slowed; the visible energy is in plumbing and audit cleanup.

Read the full Vikunja trajectory →

Tracecat vs Vikunja: editorial side-by-side

T7.5

Tracecat is turning case comments into an agent console while it hardens the sandbox around them

◆ Current state

Tracecat is deep in a beta.52 release-candidate train, eight RCs in, following the beta.51 release that made the Action Gateway mandatory. Two threads dominate: agents are becoming addressable from inside case comments, and the sandbox that runs them is being bounded — socket budgets, registry artifact caches, egress filtering. The product is a security automation platform steadily converting its agent story from a feature into the primary interaction surface.

◆ Where it's heading

The agent work is moving from 'you can invoke an agent' to 'the agent lives in the case thread' — mentions, session chat, activity shown inline, and now MCP integration references correlated on workspace pull. Running alongside it is a sustained isolation effort: every second RC raises or filters the NSTUN socket budget, which reads as capacity being tuned under real agent load rather than a one-off fix. The UI is catching up too, with a properties rail and editor redesign borrowed from Linear's density.

◆ Prediction

Expect beta.52 to land as a final release with agent-in-comments as its headline, and the NSTUN capacity raises to stop once the ceiling holds. Whether the MCP reference correlation grows into full workspace-level integration mapping is not yet visible in these entries.

V0.0

Vikunja crossed the v1.0 finish line and pivoted hard into security hardening.

◆ Current state

Vikunja shipped two v1.0 release candidates through late 2025 and early 2026, then jumped to a v2 series whose first widely-tagged point release, v2.2.1, is dominated by security work. The latest release patches multiple SSRF and IDOR vulnerabilities, enforces disabled/locked-account semantics across every auth surface (OIDC, API tokens, CalDAV, LDAP), and adds a shared SSRF-safe HTTP client that webhooks and migrations now route through. User-facing feature work has slowed; the visible energy is in plumbing and audit cleanup.

◆ Where it's heading

The arc moves from feature-completion (S3 storage, drag-and-drop project moves, hover previews in late 2025) toward platform credibility — closing security gaps a self-hosted task tool needs to clear before serious team adoption. The rapid version-number jump from v1.0.0-rc4 to v2.2.1 in two months suggests v1.0 shipped and the team tagged a v2 line aimed at addressing accumulated authz debt. Expect the next several releases to keep the security-first posture rather than return to a feature push.

◆ Prediction

The next release will likely continue closing remaining authz edges (more IDOR audits, additional credential-stripping in API responses) and bundle a translations and dependency sweep. A user-facing feature push probably waits until the security work plateaus.

Alternatives to Tracecat and Vikunja

Other PM products tracked by Sparkpulse, ranked by recent ship velocity. Each card links to a full editorial trajectory and lets you pivot into a head-to-head comparison with either Tracecat or Vikunja.

See all Tracecat alternatives → · See all Vikunja alternatives →

Recent activity from Tracecat and Vikunja

Latest ship moves from both products, interleaved chronologically. ⚡ = editorial spark.

  1. 4d agoTracecatMCP integration refs correlate on workspace pull
  2. 4d agoTracecatLinear-style properties rail lands with an editor and picker redesign
  3. 4d agoTracecatComment-invoked agent sessions get simpler, mentions get docs
  4. 5d agoTracecatTracecat beta.52-rc.5 bounds the registry artifact cache and adds custom field display names
  5. 6d agoTracecatTracecat beta.52-rc.4 lets agents be invoked from comment mentions
  6. 6d agoTracecatTracecat beta.52-rc.3 enforces filtered NSTUN egress
  7. 4mo agoVikunjav2.2.1: SSRF and IDOR patches plus disabled-account enforcement
  8. 6mo agoVikunjav1.0.0-rc4: drag-and-drop project moves, file-storage validation
  9. 8mo agoVikunjav1.0.0-rc3: S3 storage, comment counts, hover task previews

Frequently asked questions

What is the difference between Tracecat and Vikunja?

They serve adjacent needs but don't currently overlap on shipped themes. Tracecat is currently shipping more aggressively (velocity 7.5 vs 0.0), with 0 editorial sparks in the last 30 days against 0. See the at-a-glance table above for a side-by-side breakdown of velocity, recent sparks, and editorial themes.

Is Tracecat better than Vikunja?

Sparkpulse doesn't pick a winner — we score release velocity, not feature parity. Tracecat is currently shipping more aggressively (velocity 7.5 vs 0.0), with 0 editorial sparks in the last 30 days against 0. For your specific use case, the alternatives sections above list other PM products to evaluate alongside.

What are the best alternatives to Tracecat?

Top Tracecat alternatives in PM are ranked by recent ship velocity. Browse the "Tracecat alternatives" section above for the current picks, or visit /alternatives/tracecat for the full list with editorial commentary on each.

What are the best alternatives to Vikunja?

Top Vikunja alternatives in PM are ranked by recent ship velocity. Browse the "Vikunja alternatives" section above for the current picks, or visit /alternatives/vikunja for the full list with editorial commentary on each.