BookStack vs Hive
Side-by-side trajectory, velocity, and editorial themes.
BookStack opened a real theme extension surface, then spent six weeks patching CVEs.
BookStack shipped v26.03 in mid-March 2026 with a meaningful new theme module system and several theme events (page render, pre-save, OIDC URL customization) — the first time the project's customization surface has had real extension points rather than just template overrides. The next six weeks were almost entirely security work: four security-marked patch releases (v25.12.9, v26.03.1, v26.03.2, v26.03.4) addressing role-escalation via registration, hidden content leaking through markdown exports, style-code injection in revision diffs, and attachment/webhook URL validation gaps. Multiple researchers credited per release.
The arc is 'open up the platform, then defend it' — adding extension points was the v26.03 push, and the subsequent CVE volume reads as a coordinated audit response (often two researchers credited per advisory, suggesting public attention from pen-testers). The 25.12.x line is also still being patched in parallel, indicating the team is supporting both branches rather than forcing rapid upgrades.
Expect another v26.03.x patch release if the audit cycle isn't complete, then a return to feature work — likely more theme-event coverage and exposing more lifecycle hooks to match what the new module system can attach to. The dual-branch maintenance pattern probably continues until v25.12 hits its support cutoff.
Hive's quarter is mobile parity, with chat and dashboards getting tidied on the side.
Hive is in a steady incremental polish phase. The dominant thread is pulling more of the desktop experience onto mobile: workflow visibility, time tracking from action cards, Gantt views, and a beefed-up universal search all landed within a week of each other. Chat got a parallel set of refinements (inline video, file gallery, history preservation when members leave), and dashboards picked up median aggregation.
Hive looks focused on closing the desktop-mobile gap rather than opening new product surface area. Each mobile release individually is small, but together they push Hive toward being usable as a primary-not-secondary work surface on phones, which matters most for project managers who actually move around. Expect this cleanup arc to continue for at least another release cycle before strategic capabilities (AI, automation depth) reappear.
Next likely additions on mobile: editing or creating actions/workflows (currently view-only) and richer dashboard interaction. On the desktop side, a feature touching AI or workflow authoring is overdue given the cadence of small fixes.
See more alternatives to BookStack →
See more alternatives to Hive →