← Back to home
Comparison · Collab

BookStack vs Joplin

A side-by-side editorial comparison of BookStack and Joplin — release velocity, themes, recent moves, and the top alternatives to consider.

BookStack vs Joplin: at a glance

FeatureBookStackJoplin
SectorCollabCollab
Velocity score5.06.3
Sparks · 30d01
Top themesself-hosted, security, permissions, documentationnote-taking, ai-integration, privacy, mcp
Last editorial update20d ago1d ago
WebsiteVisit →Visit →

What is BookStack?

Five security releases in four months, this one closing an import RCE

BookStack's release stream since v26.05 has been almost entirely security patches. This release fixes a range of issues: attachments updatable without permission, XSS through the drawing endpoints, draft endpoints altering non-draft pages, other users' drafts leaking into search results, remote code execution through crafted ZIP imports, and page visibility not updating in recycle-bin scenarios. The feature release it patches, v26.05, added a page contents view, tag API and separately controlled revision permissions.

Read the full BookStack trajectory →

What is Joplin?

Joplin 3.7 ships AI chat, semantic search, and MCP integration — all off by default, all controllable by the user.

Joplin 3.7 is the product's first real AI release: an in-app chat panel for querying the currently open note, semantic (meaning-based) search across notebooks, and an MCP server that lets external AI assistants connect to Joplin's note graph. The implementation is privacy-first by design — AI is disabled by default, local models (Ollama, LM Studio) are explicitly supported, and cloud AI services only receive the specific note content relevant to a request rather than the full notebook. A companion documentation post published September 14 lays out the privacy model explicitly.

Read the full Joplin trajectory →

BookStack vs Joplin: editorial side-by-side

B
BookStack
COLLAB
5.0

Five security releases in four months, this one closing an import RCE

◆ Current state

BookStack's release stream since v26.05 has been almost entirely security patches. This release fixes a range of issues: attachments updatable without permission, XSS through the drawing endpoints, draft endpoints altering non-draft pages, other users' drafts leaking into search results, remote code execution through crafted ZIP imports, and page visibility not updating in recycle-bin scenarios. The feature release it patches, v26.05, added a page contents view, tag API and separately controlled revision permissions.

◆ Where it's heading

The pattern is a substantial feature release followed by a run of point releases that are purely security, each crediting outside reporters. That cadence suggests sustained external scrutiny of the permission and import paths rather than a project shipping features in small increments. Every advisory in this run touches either permission checking or content handling on import and export — the two places where a self-hosted wiki with untrusted editors is most exposed.

◆ Prediction

Nothing in this stream points to the next feature release; on the current pattern the next tag is more likely to be another point release closing reported issues in the same permission and import surfaces.

J
Joplin
COLLAB
6.3

Joplin 3.7 ships AI chat, semantic search, and MCP integration — all off by default, all controllable by the user.

◆ Current state

Joplin 3.7 is the product's first real AI release: an in-app chat panel for querying the currently open note, semantic (meaning-based) search across notebooks, and an MCP server that lets external AI assistants connect to Joplin's note graph. The implementation is privacy-first by design — AI is disabled by default, local models (Ollama, LM Studio) are explicitly supported, and cloud AI services only receive the specific note content relevant to a request rather than the full notebook. A companion documentation post published September 14 lays out the privacy model explicitly.

◆ Where it's heading

Joplin is repositioning from a sync-agnostic note-taking app into an AI-native knowledge base, differentiated by opt-in, local-first controls. The HMD Terra M preload partnership and the warrant canary point to a deliberate push toward privacy-conscious enterprise and professional users who distrust cloud-first tools. The MCP integration is particularly strategic: it makes Joplin's note graph accessible to external orchestration pipelines without locking into any particular AI provider.

◆ Prediction

The next major release will likely expand AI chat to multi-note context — currently limited to the open note — and add more configurable MCP tools. The HTR (handwritten text recognition) project from the 2024 French government partnership is also likely to appear in a near-term release.

Alternatives to BookStack and Joplin

Other Collab products tracked by Sparkpulse, ranked by recent ship velocity. Each card links to a full editorial trajectory and lets you pivot into a head-to-head comparison with either BookStack or Joplin.

See all BookStack alternatives → · See all Joplin alternatives →

Recent activity from BookStack and Joplin

Latest ship moves from both products, interleaved chronologically. ⚡ = editorial spark.

  1. 2d agoJoplinYour notes and AI: privacy first
  2. 16d agoJoplinWhat's new in Joplin 3.7
  3. 23d agoBookStackSecurity release closes a ZIP-import RCE and permission bypasses
  4. 1mo agoBookStackSecurity release fixes five issues including auth matching
  5. 2mo agoBookStackURL filtering, redirects and permission checks hardened
  6. 3mo agoBookStackAttachment metadata leak and file:// export risk closed
  7. 3mo agoBookStackv26.05 adds page contents view, tag API and revision permissions
  8. 3mo agoBookStackRate limiting added to MFA verification routes
  9. 4mo agoJoplinWhat's new in Joplin 3.6
  10. 6mo agoJoplinIntroducing our Warrant Canary
  11. 7mo agoJoplinJoplin will come preloaded on the HMD Terra M
  12. 8mo agoJoplinWhat's new in Joplin 3.5

Frequently asked questions

What is the difference between BookStack and Joplin?

They serve adjacent needs but don't currently overlap on shipped themes. Joplin is currently shipping more aggressively (velocity 6.3 vs 5.0), with 1 editorial sparks in the last 30 days against 0. See the at-a-glance table above for a side-by-side breakdown of velocity, recent sparks, and editorial themes.

Is BookStack better than Joplin?

Sparkpulse doesn't pick a winner — we score release velocity, not feature parity. Joplin is currently shipping more aggressively (velocity 6.3 vs 5.0), with 1 editorial sparks in the last 30 days against 0. For your specific use case, the alternatives sections above list other Collab products to evaluate alongside.

What are the best alternatives to BookStack?

Top BookStack alternatives in Collab are ranked by recent ship velocity. Browse the "BookStack alternatives" section above for the current picks, or visit /alternatives/bookstack for the full list with editorial commentary on each.

What are the best alternatives to Joplin?

Top Joplin alternatives in Collab are ranked by recent ship velocity. Browse the "Joplin alternatives" section above for the current picks, or visit /alternatives/joplin for the full list with editorial commentary on each.