Tracecat
Tracecat hits 1.0 RC with open-source agent presets, agent-case @mentions, and 20+ new security integrations.
A side-by-side editorial comparison of Kanboard and My Hours — release velocity, themes, recent moves, and the top alternatives to consider.
Six straight releases of security hardening, now reaching the API's own response shape
Kanboard is a stable, self-hosted PHP kanban board whose release stream is now almost entirely security work. Version 1.2.54 continues that pattern and pushes it further than most: API procedures no longer return private user fields, and changing a password invalidates every existing session and remember-me token. Feature development is close to dormant; the maintenance effort is going into closing whole categories of vulnerability rather than adding surface.
My Hours launches a Claude MCP connector, making AI-driven time logging a first-class workflow
My Hours is a time tracking platform with a strong invoicing and reporting core, now shipping in two distinct directions: an AI integration layer (Claude MCP connector, Sep 3) and expanded compliance-friendly tracking features (break tracking with payroll calculations, attendance reports, budget alerts). The September releases represent the most capability-dense period in the window, following a patch-heavy summer. The MCP connector runs on Keboola's Cloudflare infrastructure — zero install, OAuth-only.
Kanboard is a stable, self-hosted PHP kanban board whose release stream is now almost entirely security work. Version 1.2.54 continues that pattern and pushes it further than most: API procedures no longer return private user fields, and changing a password invalidates every existing session and remember-me token. Feature development is close to dormant; the maintenance effort is going into closing whole categories of vulnerability rather than adding surface.
The arc from 1.2.49 through 1.2.54 is a systematic audit that works outward from one surface to the next — LDAP escaping, SSRF, deserialization, CSRF, comment visibility, bulk-operation ownership, and now API response shape and session lifetime. Each release also tightens the deployment story, from trusted-proxy configuration to an nginx config that only lets front controllers execute PHP. New user-facing features arrive rarely and small: opt-in full-text search, RTL support, richer API links.
Expect the audit to keep moving through remaining surfaces, with more permission checks in API procedures and continued PHP-version and base-image maintenance. Nothing in these entries points to a new feature direction.
My Hours is a time tracking platform with a strong invoicing and reporting core, now shipping in two distinct directions: an AI integration layer (Claude MCP connector, Sep 3) and expanded compliance-friendly tracking features (break tracking with payroll calculations, attendance reports, budget alerts). The September releases represent the most capability-dense period in the window, following a patch-heavy summer. The MCP connector runs on Keboola's Cloudflare infrastructure — zero install, OAuth-only.
The Claude MCP connector signals a clear strategic bet: My Hours wants to be the time tracking tool you interact with through AI conversation rather than through a timer UI. The infrastructure choice (remote server on Cloudflare, not a local install) removes adoption friction, making it viable for teams already using Claude. Parallel development on attendance reports and break tracking points toward a compliance and HR use case — overtime tracking, payroll-ready break records — that broadens My Hours beyond professional services billing.
The MCP integration will expand to cover write operations beyond time logging — budget tracking, invoice creation, and report export are the most obvious additions. The attendance report launched in August suggests a near-term push toward HR and payroll integrations, potentially positioning My Hours against more compliance-focused tools like Harvest or Timely for regulated industries.
Other PM products tracked by Sparkpulse, ranked by recent ship velocity. Each card links to a full editorial trajectory and lets you pivot into a head-to-head comparison with either Kanboard or My Hours.
Tracecat hits 1.0 RC with open-source agent presets, agent-case @mentions, and 20+ new security integrations.
NocoBase adds an AI knowledge base retrieval API, connecting no-code workflows to external knowledge sources.
RentRedi embeds AI into its maintenance workflow end-to-end, handling tenant intake and drafting landlord replies.
Camunda 8.10 alpha cycles through broad platform bug fixes while 8.7 gets routine security patches
Asana embeds AI into Slack threads and closes the rich-text gap with Notion
Rize pivots from solo time tracker to agency operations platform with invoicing, profitability reporting, and a ChatGPT integration.
See all Kanboard alternatives → · See all My Hours alternatives →
Latest ship moves from both products, interleaved chronologically. ⚡ = editorial spark.
They serve adjacent needs but don't currently overlap on shipped themes. My Hours is currently shipping more aggressively (velocity 6.3 vs 2.5), with 1 editorial sparks in the last 30 days against 0. See the at-a-glance table above for a side-by-side breakdown of velocity, recent sparks, and editorial themes.
Sparkpulse doesn't pick a winner — we score release velocity, not feature parity. My Hours is currently shipping more aggressively (velocity 6.3 vs 2.5), with 1 editorial sparks in the last 30 days against 0. For your specific use case, the alternatives sections above list other PM products to evaluate alongside.
Top Kanboard alternatives in PM are ranked by recent ship velocity. Browse the "Kanboard alternatives" section above for the current picks, or visit /alternatives/kanboard for the full list with editorial commentary on each.
Top My Hours alternatives in PM are ranked by recent ship velocity. Browse the "My Hours alternatives" section above for the current picks, or visit /alternatives/myhours for the full list with editorial commentary on each.