Mattermost
Mattermost v11.11 adds data spillage exposure tracking as v12.0 breaking changes loom
A side-by-side editorial comparison of BookStack and Document360 — release velocity, themes, recent moves, and the top alternatives to consider.
| Feature | BookStack | Document360 |
|---|---|---|
| Sector | Collab | Collab |
| Velocity score | 5.0 | 7.5 |
| Sparks · 30d | 0 | 1 |
| Top themes | self-hosted, security, permissions, documentation | knowledge-base, documentation, collaborative-editing, api-platform |
| Last editorial update | 20d ago | 7d ago |
| Website | Visit → | — |
Five security releases in four months, this one closing an import RCE
BookStack's release stream since v26.05 has been almost entirely security patches. This release fixes a range of issues: attachments updatable without permission, XSS through the drawing endpoints, draft endpoints altering non-draft pages, other users' drafts leaking into search results, remote code execution through crafted ZIP imports, and page visibility not updating in recycle-bin scenarios. The feature release it patches, v26.05, added a page contents view, tag API and separately controlled revision permissions.
Document360 ships collaborative editing and API v3 with OAuth 2.0 in back-to-back releases.
Document360 has shipped two major capability expansions in consecutive August releases: v12.8.2 introduced API v3 with OAuth 2.0 authentication and scoped API keys (the product's largest API overhaul to date), and v12.8.4 added real-time collaborative editing allowing multiple contributors to work on the same article simultaneously. The surrounding releases improved the AI assistant analytics layer (Eddy AI unanswered query tracking) and redesigned the navigation and publishing UX.
BookStack's release stream since v26.05 has been almost entirely security patches. This release fixes a range of issues: attachments updatable without permission, XSS through the drawing endpoints, draft endpoints altering non-draft pages, other users' drafts leaking into search results, remote code execution through crafted ZIP imports, and page visibility not updating in recycle-bin scenarios. The feature release it patches, v26.05, added a page contents view, tag API and separately controlled revision permissions.
The pattern is a substantial feature release followed by a run of point releases that are purely security, each crediting outside reporters. That cadence suggests sustained external scrutiny of the permission and import paths rather than a project shipping features in small increments. Every advisory in this run touches either permission checking or content handling on import and export — the two places where a self-hosted wiki with untrusted editors is most exposed.
Nothing in this stream points to the next feature release; on the current pattern the next tag is more likely to be another point release closing reported issues in the same permission and import surfaces.
Document360 has shipped two major capability expansions in consecutive August releases: v12.8.2 introduced API v3 with OAuth 2.0 authentication and scoped API keys (the product's largest API overhaul to date), and v12.8.4 added real-time collaborative editing allowing multiple contributors to work on the same article simultaneously. The surrounding releases improved the AI assistant analytics layer (Eddy AI unanswered query tracking) and redesigned the navigation and publishing UX.
Document360 is clearly targeting enterprise knowledge base teams: OAuth 2.0 on the API enables secure SSO-gated integrations, collaborative editing removes a key friction point for team-based documentation, and unanswered query analytics gives content managers data to prioritize gaps. The product is closing the gap to Confluence and Notion on collaboration and integration depth.
Expect role-based collaborative editing permissions (view-only, comment, edit) and API v3 expansion to cover content lifecycle endpoints — the OAuth infrastructure is the foundation for third-party workflow integrations.
Other Collab products tracked by Sparkpulse, ranked by recent ship velocity. Each card links to a full editorial trajectory and lets you pivot into a head-to-head comparison with either BookStack or Document360.
Mattermost v11.11 adds data spillage exposure tracking as v12.0 breaking changes loom
SiYuan v3.8.4 beta cycle adds agent-controlled database fields, MiniMax image gen, and skill file management
GitHub Copilot gets cost-aware inference tiers as enterprise AI tooling tightens across the platform.
Nextcloud runs three LTS branches in parallel, shipping bug fixes and quiet performance wins.
Teable adds Composio integration and Scheduled Routines, pivoting from spreadsheet to agentic workflow platform.
Happeo doubles down on SEO content to own intranet search terms for mid-market buyers.
See all BookStack alternatives → · See all Document360 alternatives →
Latest ship moves from both products, interleaved chronologically. ⚡ = editorial spark.
Both compete on the same themes — documentation — within Collab. Document360 is currently shipping more aggressively (velocity 7.5 vs 5.0), with 1 editorial sparks in the last 30 days against 0. See the at-a-glance table above for a side-by-side breakdown of velocity, recent sparks, and editorial themes.
Sparkpulse doesn't pick a winner — we score release velocity, not feature parity. Document360 is currently shipping more aggressively (velocity 7.5 vs 5.0), with 1 editorial sparks in the last 30 days against 0. For your specific use case, the alternatives sections above list other Collab products to evaluate alongside.
Top BookStack alternatives in Collab are ranked by recent ship velocity. Browse the "BookStack alternatives" section above for the current picks, or visit /alternatives/bookstack for the full list with editorial commentary on each.
Top Document360 alternatives in Collab are ranked by recent ship velocity. Browse the "Document360 alternatives" section above for the current picks, or visit /alternatives/document360 for the full list with editorial commentary on each.