Mattermost
Mattermost v11.11 adds data spillage exposure tracking as v12.0 breaking changes loom
A side-by-side editorial comparison of BookStack and Joplin — release velocity, themes, recent moves, and the top alternatives to consider.
Five security releases in four months, this one closing an import RCE
BookStack's release stream since v26.05 has been almost entirely security patches. This release fixes a range of issues: attachments updatable without permission, XSS through the drawing endpoints, draft endpoints altering non-draft pages, other users' drafts leaking into search results, remote code execution through crafted ZIP imports, and page visibility not updating in recycle-bin scenarios. The feature release it patches, v26.05, added a page contents view, tag API and separately controlled revision permissions.
Joplin 3.7 ships AI chat, semantic search, and MCP integration — all off by default, all controllable by the user.
Joplin 3.7 is the product's first real AI release: an in-app chat panel for querying the currently open note, semantic (meaning-based) search across notebooks, and an MCP server that lets external AI assistants connect to Joplin's note graph. The implementation is privacy-first by design — AI is disabled by default, local models (Ollama, LM Studio) are explicitly supported, and cloud AI services only receive the specific note content relevant to a request rather than the full notebook. A companion documentation post published September 14 lays out the privacy model explicitly.
BookStack's release stream since v26.05 has been almost entirely security patches. This release fixes a range of issues: attachments updatable without permission, XSS through the drawing endpoints, draft endpoints altering non-draft pages, other users' drafts leaking into search results, remote code execution through crafted ZIP imports, and page visibility not updating in recycle-bin scenarios. The feature release it patches, v26.05, added a page contents view, tag API and separately controlled revision permissions.
The pattern is a substantial feature release followed by a run of point releases that are purely security, each crediting outside reporters. That cadence suggests sustained external scrutiny of the permission and import paths rather than a project shipping features in small increments. Every advisory in this run touches either permission checking or content handling on import and export — the two places where a self-hosted wiki with untrusted editors is most exposed.
Nothing in this stream points to the next feature release; on the current pattern the next tag is more likely to be another point release closing reported issues in the same permission and import surfaces.
Joplin 3.7 is the product's first real AI release: an in-app chat panel for querying the currently open note, semantic (meaning-based) search across notebooks, and an MCP server that lets external AI assistants connect to Joplin's note graph. The implementation is privacy-first by design — AI is disabled by default, local models (Ollama, LM Studio) are explicitly supported, and cloud AI services only receive the specific note content relevant to a request rather than the full notebook. A companion documentation post published September 14 lays out the privacy model explicitly.
Joplin is repositioning from a sync-agnostic note-taking app into an AI-native knowledge base, differentiated by opt-in, local-first controls. The HMD Terra M preload partnership and the warrant canary point to a deliberate push toward privacy-conscious enterprise and professional users who distrust cloud-first tools. The MCP integration is particularly strategic: it makes Joplin's note graph accessible to external orchestration pipelines without locking into any particular AI provider.
The next major release will likely expand AI chat to multi-note context — currently limited to the open note — and add more configurable MCP tools. The HTR (handwritten text recognition) project from the 2024 French government partnership is also likely to appear in a near-term release.
Other Collab products tracked by Sparkpulse, ranked by recent ship velocity. Each card links to a full editorial trajectory and lets you pivot into a head-to-head comparison with either BookStack or Joplin.
Mattermost v11.11 adds data spillage exposure tracking as v12.0 breaking changes loom
SiYuan v3.8.4 beta cycle adds agent-controlled database fields, MiniMax image gen, and skill file management
GitHub Copilot gets cost-aware inference tiers as enterprise AI tooling tightens across the platform.
Nextcloud runs three LTS branches in parallel, shipping bug fixes and quiet performance wins.
Teable adds Composio integration and Scheduled Routines, pivoting from spreadsheet to agentic workflow platform.
Happeo doubles down on SEO content to own intranet search terms for mid-market buyers.
See all BookStack alternatives → · See all Joplin alternatives →
Latest ship moves from both products, interleaved chronologically. ⚡ = editorial spark.
They serve adjacent needs but don't currently overlap on shipped themes. Joplin is currently shipping more aggressively (velocity 6.3 vs 5.0), with 1 editorial sparks in the last 30 days against 0. See the at-a-glance table above for a side-by-side breakdown of velocity, recent sparks, and editorial themes.
Sparkpulse doesn't pick a winner — we score release velocity, not feature parity. Joplin is currently shipping more aggressively (velocity 6.3 vs 5.0), with 1 editorial sparks in the last 30 days against 0. For your specific use case, the alternatives sections above list other Collab products to evaluate alongside.
Top BookStack alternatives in Collab are ranked by recent ship velocity. Browse the "BookStack alternatives" section above for the current picks, or visit /alternatives/bookstack for the full list with editorial commentary on each.
Top Joplin alternatives in Collab are ranked by recent ship velocity. Browse the "Joplin alternatives" section above for the current picks, or visit /alternatives/joplin for the full list with editorial commentary on each.