← Back to home
Comparison · PM

Kanboard vs Tracecat

A side-by-side editorial comparison of Kanboard and Tracecat — release velocity, themes, recent moves, and the top alternatives to consider.

Shared themes:open-source

Kanboard vs Tracecat: at a glance

FeatureKanboardTracecat
SectorPMPM
Velocity score2.57.5
Sparks · 30d02
Top themeskanban, self-hosted, security-hardening, phpsecurity-automation, soar, mcp, open-source
Last editorial update17d ago10h ago
WebsiteVisit →Visit →

What is Kanboard?

Six straight releases of security hardening, now reaching the API's own response shape

Kanboard is a stable, self-hosted PHP kanban board whose release stream is now almost entirely security work. Version 1.2.54 continues that pattern and pushes it further than most: API procedures no longer return private user fields, and changing a password invalidates every existing session and remember-me token. Feature development is close to dormant; the maintenance effort is going into closing whole categories of vulnerability rather than adding surface.

Read the full Kanboard trajectory →

What is Tracecat?

Tracecat hits 1.0 RC with open-source agent presets, agent-case @mentions, and 20+ new security integrations.

Tracecat is in 1.0 release candidate territory, with RC.1 and RC.2 landing in quick succession. The platform has fundamentally expanded its case management system: agents can now be invoked from case comment @mentions, record their mutations back to cases, and have their runs filtered and linked to specific cases. The MCP catalog, agent presets, and skills were open-sourced in RC.1. The integration catalog grew by 20+ providers in beta.52 — Rippling, Jamf, Microsoft Graph, Databricks, Snowflake, Recorded Future, and others. RC.2 adds SSRF blocking for MCP and LLM requests and AWS role chaining.

Read the full Tracecat trajectory →

Kanboard vs Tracecat: editorial side-by-side

K2.5

Six straight releases of security hardening, now reaching the API's own response shape

◆ Current state

Kanboard is a stable, self-hosted PHP kanban board whose release stream is now almost entirely security work. Version 1.2.54 continues that pattern and pushes it further than most: API procedures no longer return private user fields, and changing a password invalidates every existing session and remember-me token. Feature development is close to dormant; the maintenance effort is going into closing whole categories of vulnerability rather than adding surface.

◆ Where it's heading

The arc from 1.2.49 through 1.2.54 is a systematic audit that works outward from one surface to the next — LDAP escaping, SSRF, deserialization, CSRF, comment visibility, bulk-operation ownership, and now API response shape and session lifetime. Each release also tightens the deployment story, from trusted-proxy configuration to an nginx config that only lets front controllers execute PHP. New user-facing features arrive rarely and small: opt-in full-text search, RTL support, richer API links.

◆ Prediction

Expect the audit to keep moving through remaining surfaces, with more permission checks in API procedures and continued PHP-version and base-image maintenance. Nothing in these entries points to a new feature direction.

T7.5

Tracecat hits 1.0 RC with open-source agent presets, agent-case @mentions, and 20+ new security integrations.

◆ Current state

Tracecat is in 1.0 release candidate territory, with RC.1 and RC.2 landing in quick succession. The platform has fundamentally expanded its case management system: agents can now be invoked from case comment @mentions, record their mutations back to cases, and have their runs filtered and linked to specific cases. The MCP catalog, agent presets, and skills were open-sourced in RC.1. The integration catalog grew by 20+ providers in beta.52 — Rippling, Jamf, Microsoft Graph, Databricks, Snowflake, Recorded Future, and others. RC.2 adds SSRF blocking for MCP and LLM requests and AWS role chaining.

◆ Where it's heading

Tracecat is building toward a security automation platform where agents are primary workflow participants, not external integrations. The agent@mention model in case comments, combined with open-sourcing the MCP catalog for community contributions, signals a bet on collaborative human-agent case investigation rather than just automated runbooks. Dropping pydantic-ai in beta.52 in favor of a custom durable runtime reflects a commitment to owning the agent execution stack — the kind of choice that enables the SSRF blocking and error classification work shipping in parallel.

◆ Prediction

The 1.0 stable release will ship shortly and will lead with the agent-case interaction model as the headline capability. Post-stable, watch for expansion of the open-source MCP catalog driven by community contributions and a push around the enterprise entitlement and SCIM system for larger SOC teams.

Alternatives to Kanboard and Tracecat

Other PM products tracked by Sparkpulse, ranked by recent ship velocity. Each card links to a full editorial trajectory and lets you pivot into a head-to-head comparison with either Kanboard or Tracecat.

See all Kanboard alternatives → · See all Tracecat alternatives →

Recent activity from Kanboard and Tracecat

Latest ship moves from both products, interleaved chronologically. ⚡ = editorial spark.

  1. 15h agoTracecatTracecat 1.0.0-rc.2
  2. 1d agoTracecatTracecat 1.0.0-rc.1
  3. 4d agoTracecatTracecat 1.0.0-beta.53-rc.1: Case aggregation and skill tool grants
  4. 4d agoTracecatTracecat 1.0.0-beta.52: Agent @mentions in cases and 20+ new integrations
  5. 7d agoTracecatTracecat 1.0.0-beta.52-rc.24
  6. 12d agoTracecatTracecat 1.0.0-beta.52-rc.23
  7. 18d agoKanboardPassword changes now kill sessions; API stops leaking private fields
  8. 1mo agoKanboardSecurity fixes and opt-in full-text task search
  9. 5mo agoKanboardComment visibility rules and timing-safe token checks
  10. 6mo agoKanboardSSRF protection and safer deserialization
  11. 7mo agoKanboardAuthorization and CSRF checks across controllers
  12. 8mo agoKanboardLDAP injection fix and trusted-proxy config

Frequently asked questions

What is the difference between Kanboard and Tracecat?

Both compete on the same themes — open-source — within PM. Tracecat is currently shipping more aggressively (velocity 7.5 vs 2.5), with 2 editorial sparks in the last 30 days against 0. See the at-a-glance table above for a side-by-side breakdown of velocity, recent sparks, and editorial themes.

Is Kanboard better than Tracecat?

Sparkpulse doesn't pick a winner — we score release velocity, not feature parity. Tracecat is currently shipping more aggressively (velocity 7.5 vs 2.5), with 2 editorial sparks in the last 30 days against 0. For your specific use case, the alternatives sections above list other PM products to evaluate alongside.

What are the best alternatives to Kanboard?

Top Kanboard alternatives in PM are ranked by recent ship velocity. Browse the "Kanboard alternatives" section above for the current picks, or visit /alternatives/kanboard for the full list with editorial commentary on each.

What are the best alternatives to Tracecat?

Top Tracecat alternatives in PM are ranked by recent ship velocity. Browse the "Tracecat alternatives" section above for the current picks, or visit /alternatives/tracecat for the full list with editorial commentary on each.