← Back to home
Comparison · PM

Vikunja vs Wakapi

A side-by-side editorial comparison of Vikunja and Wakapi — release velocity, themes, recent moves, and the top alternatives to consider.

Shared themes:self-hosted

Vikunja vs Wakapi: at a glance

FeatureVikunjaWakapi
SectorPMPM
Velocity score0.02.5
Sparks · 30d00
Top themessecurity hardening, ssrf protection, idor fixes, account lockouttime-tracking, self-hosted, oidc, auth-bypass
Last editorial update3mo ago48m ago
WebsiteVisit →Visit →

What is Vikunja?

Vikunja crossed the v1.0 finish line and pivoted hard into security hardening.

Vikunja shipped two v1.0 release candidates through late 2025 and early 2026, then jumped to a v2 series whose first widely-tagged point release, v2.2.1, is dominated by security work. The latest release patches multiple SSRF and IDOR vulnerabilities, enforces disabled/locked-account semantics across every auth surface (OIDC, API tokens, CalDAV, LDAP), and adds a shared SSRF-safe HTTP client that webhooks and migrations now route through. User-facing feature work has slowed; the visible energy is in plumbing and audit cleanup.

Read the full Vikunja trajectory →

What is Wakapi?

A critical auth bypass lands in the middle of Wakapi's slow identity rebuild.

Wakapi's recent releases cluster around identity and deployment rather than time tracking itself: OpenID Connect login, then an OIDC-only mode, multiple API keys per user, and a switch from Alpine to a distroless nonroot container image. The 2.17.x line has carried two security fixes now — a responsibly disclosed issue in 2.17.3, and a critical authentication bypass in 2.17.6 caused by a shared cache key namespace. Release notes are mostly bare issue numbers, so several entries state that something changed without saying what.

Read the full Wakapi trajectory →

Vikunja vs Wakapi: editorial side-by-side

V0.0

Vikunja crossed the v1.0 finish line and pivoted hard into security hardening.

◆ Current state

Vikunja shipped two v1.0 release candidates through late 2025 and early 2026, then jumped to a v2 series whose first widely-tagged point release, v2.2.1, is dominated by security work. The latest release patches multiple SSRF and IDOR vulnerabilities, enforces disabled/locked-account semantics across every auth surface (OIDC, API tokens, CalDAV, LDAP), and adds a shared SSRF-safe HTTP client that webhooks and migrations now route through. User-facing feature work has slowed; the visible energy is in plumbing and audit cleanup.

◆ Where it's heading

The arc moves from feature-completion (S3 storage, drag-and-drop project moves, hover previews in late 2025) toward platform credibility — closing security gaps a self-hosted task tool needs to clear before serious team adoption. The rapid version-number jump from v1.0.0-rc4 to v2.2.1 in two months suggests v1.0 shipped and the team tagged a v2 line aimed at addressing accumulated authz debt. Expect the next several releases to keep the security-first posture rather than return to a feature push.

◆ Prediction

The next release will likely continue closing remaining authz edges (more IDOR audits, additional credential-stripping in API responses) and bundle a translations and dependency sweep. A user-facing feature push probably waits until the security work plateaus.

W2.5

A critical auth bypass lands in the middle of Wakapi's slow identity rebuild.

◆ Current state

Wakapi's recent releases cluster around identity and deployment rather than time tracking itself: OpenID Connect login, then an OIDC-only mode, multiple API keys per user, and a switch from Alpine to a distroless nonroot container image. The 2.17.x line has carried two security fixes now — a responsibly disclosed issue in 2.17.3, and a critical authentication bypass in 2.17.6 caused by a shared cache key namespace. Release notes are mostly bare issue numbers, so several entries state that something changed without saying what.

◆ Where it's heading

The direction is a self-hosted tool making itself deployable somewhere other than one developer's server. External identity providers, an option to disable local login entirely, per-key credentials and a container that runs as a nonroot user are the requirements that come from someone else's security review. The 2.17.6 bypass sits awkwardly against that: a cache keyed without proper namespacing is exactly the class of bug that multi-tenant deployment surfaces, which suggests the auth work is now being exercised harder than the code was written for. Releases have also thinned to roughly one a month from a much faster earlier cadence.

◆ Prediction

The identity and packaging thread is the only sustained one in this feed, so further hardening in that area is the most likely continuation; the sparse release notes make anything more specific guesswork.

Alternatives to Vikunja and Wakapi

Other PM products tracked by Sparkpulse, ranked by recent ship velocity. Each card links to a full editorial trajectory and lets you pivot into a head-to-head comparison with either Vikunja or Wakapi.

See all Vikunja alternatives → · See all Wakapi alternatives →

Recent activity from Vikunja and Wakapi

Latest ship moves from both products, interleaved chronologically. ⚡ = editorial spark.

  1. 6h agoWakapiCritical auth bypass from a shared cache key namespace
  2. 1mo agoWakapiRelease 2.17.5
  3. 2mo agoWakapiRelease 2.17.4
  4. 4mo agoWakapiSecurity fix, relay endpoint dropped, summaries may need regenerating
  5. 4mo agoVikunjav2.2.1: SSRF and IDOR patches plus disabled-account enforcement
  6. 5mo agoWakapiDistroless nonroot container image; SQLite permissions need fixing
  7. 6mo agoVikunjav1.0.0-rc4: drag-and-drop project moves, file-storage validation
  8. 6mo agoWakapiOIDC-only login mode disables local accounts
  9. 8mo agoVikunjav1.0.0-rc3: S3 storage, comment counts, hover task previews

Frequently asked questions

What is the difference between Vikunja and Wakapi?

Both compete on the same themes — self-hosted — within PM. Wakapi is currently shipping more aggressively (velocity 2.5 vs 0.0), with 0 editorial sparks in the last 30 days against 0. See the at-a-glance table above for a side-by-side breakdown of velocity, recent sparks, and editorial themes.

Is Vikunja better than Wakapi?

Sparkpulse doesn't pick a winner — we score release velocity, not feature parity. Wakapi is currently shipping more aggressively (velocity 2.5 vs 0.0), with 0 editorial sparks in the last 30 days against 0. For your specific use case, the alternatives sections above list other PM products to evaluate alongside.

What are the best alternatives to Vikunja?

Top Vikunja alternatives in PM are ranked by recent ship velocity. Browse the "Vikunja alternatives" section above for the current picks, or visit /alternatives/vikunja for the full list with editorial commentary on each.

What are the best alternatives to Wakapi?

Top Wakapi alternatives in PM are ranked by recent ship velocity. Browse the "Wakapi alternatives" section above for the current picks, or visit /alternatives/wakapi for the full list with editorial commentary on each.