← Back to home
Comparison · Collab

BookStack vs Wiki.js

A side-by-side editorial comparison of BookStack and Wiki.js — release velocity, themes, recent moves, and the top alternatives to consider.

Shared themes:self-hosted

BookStack vs Wiki.js: at a glance

FeatureBookStackWiki.js
SectorCollabCollab
Velocity score5.06.3
Sparks · 30d01
Top themesself-hosted, security, permissions, documentationwiki, self-hosted, enterprise-auth, sso
Last editorial update20d ago4d ago
WebsiteVisit →Visit →

What is BookStack?

Five security releases in four months, this one closing an import RCE

BookStack's release stream since v26.05 has been almost entirely security patches. This release fixes a range of issues: attachments updatable without permission, XSS through the drawing endpoints, draft endpoints altering non-draft pages, other users' drafts leaking into search results, remote code execution through crafted ZIP imports, and page visibility not updating in recycle-bin scenarios. The feature release it patches, v26.05, added a page contents view, tag API and separately controlled revision permissions.

Read the full BookStack trajectory →

What is Wiki.js?

Wiki.js 3.0 beta closes enterprise auth and SEO gaps at sprint pace

Wiki.js is running a dual-track strategy: v2.5.x is in maintenance, collecting only security and bug fixes, while v3.0.0 moves through beta weekly with substantial new features. The v3 beta has concentrated recent drops on two converging pillars — enterprise authentication (Entra ID, LDAP, SAML, Discord with group-to-role mapping) and operations infrastructure (Audit Log, admin metrics, sitemap serving, prerendering for anonymous requests). All active development runs through a single committer, shipping multiple named features per weekly beta build.

Read the full Wiki.js trajectory →

BookStack vs Wiki.js: editorial side-by-side

B
BookStack
COLLAB
5.0

Five security releases in four months, this one closing an import RCE

◆ Current state

BookStack's release stream since v26.05 has been almost entirely security patches. This release fixes a range of issues: attachments updatable without permission, XSS through the drawing endpoints, draft endpoints altering non-draft pages, other users' drafts leaking into search results, remote code execution through crafted ZIP imports, and page visibility not updating in recycle-bin scenarios. The feature release it patches, v26.05, added a page contents view, tag API and separately controlled revision permissions.

◆ Where it's heading

The pattern is a substantial feature release followed by a run of point releases that are purely security, each crediting outside reporters. That cadence suggests sustained external scrutiny of the permission and import paths rather than a project shipping features in small increments. Every advisory in this run touches either permission checking or content handling on import and export — the two places where a self-hosted wiki with untrusted editors is most exposed.

◆ Prediction

Nothing in this stream points to the next feature release; on the current pattern the next tag is more likely to be another point release closing reported issues in the same permission and import surfaces.

W
Wiki.js
COLLAB
6.3

Wiki.js 3.0 beta closes enterprise auth and SEO gaps at sprint pace

◆ Current state

Wiki.js is running a dual-track strategy: v2.5.x is in maintenance, collecting only security and bug fixes, while v3.0.0 moves through beta weekly with substantial new features. The v3 beta has concentrated recent drops on two converging pillars — enterprise authentication (Entra ID, LDAP, SAML, Discord with group-to-role mapping) and operations infrastructure (Audit Log, admin metrics, sitemap serving, prerendering for anonymous requests). All active development runs through a single committer, shipping multiple named features per weekly beta build.

◆ Where it's heading

The v3 beta is systematically filling the gaps that have kept Wiki.js out of enterprise environments: SSO across major identity providers, compliance tooling, SEO readiness, and theme customization for whitelabeled deployments. Each week's build adds a category that a production deployment actually requires. The remaining areas not yet visible in the beta changelog are storage/sync providers and full editor-module parity with v2 — those gaps are the logical preconditions for an RC.

◆ Prediction

The next beta cycle will likely address storage backends and remaining editor modules. A release candidate becomes the natural next step once those surface areas are covered.

Alternatives to BookStack and Wiki.js

Other Collab products tracked by Sparkpulse, ranked by recent ship velocity. Each card links to a full editorial trajectory and lets you pivot into a head-to-head comparison with either BookStack or Wiki.js.

See all BookStack alternatives → · See all Wiki.js alternatives →

Recent activity from BookStack and Wiki.js

Latest ship moves from both products, interleaved chronologically. ⚡ = editorial spark.

  1. 4d agoWiki.js3.0.0-beta.561
  2. 8d agoWiki.js3.0.0-beta.554
  3. 9d agoWiki.js3.0.0-beta.550
  4. 10d agoWiki.js3.0.0-beta.543
  5. 14d agoWiki.js3.0.0-beta.537
  6. 17d agoWiki.js3.0.0-alpha.530
  7. 23d agoBookStackSecurity release closes a ZIP-import RCE and permission bypasses
  8. 1mo agoBookStackSecurity release fixes five issues including auth matching
  9. 2mo agoBookStackURL filtering, redirects and permission checks hardened
  10. 3mo agoBookStackAttachment metadata leak and file:// export risk closed
  11. 3mo agoBookStackv26.05 adds page contents view, tag API and revision permissions
  12. 3mo agoBookStackRate limiting added to MFA verification routes

Frequently asked questions

What is the difference between BookStack and Wiki.js?

Both compete on the same themes — self-hosted — within Collab. Wiki.js is currently shipping more aggressively (velocity 6.3 vs 5.0), with 1 editorial sparks in the last 30 days against 0. See the at-a-glance table above for a side-by-side breakdown of velocity, recent sparks, and editorial themes.

Is BookStack better than Wiki.js?

Sparkpulse doesn't pick a winner — we score release velocity, not feature parity. Wiki.js is currently shipping more aggressively (velocity 6.3 vs 5.0), with 1 editorial sparks in the last 30 days against 0. For your specific use case, the alternatives sections above list other Collab products to evaluate alongside.

What are the best alternatives to BookStack?

Top BookStack alternatives in Collab are ranked by recent ship velocity. Browse the "BookStack alternatives" section above for the current picks, or visit /alternatives/bookstack for the full list with editorial commentary on each.

What are the best alternatives to Wiki.js?

Top Wiki.js alternatives in Collab are ranked by recent ship velocity. Browse the "Wiki.js alternatives" section above for the current picks, or visit /alternatives/wiki-js for the full list with editorial commentary on each.