← Back to home
Comparison · PM

Leantime vs OpenProject

Side-by-side trajectory, velocity, and editorial themes.

L0.0

Leantime swaps its rich-text engine, ships experimental PostgreSQL, and spends a month fixing the fallout.

◆ Current state

Leantime just landed 3.7, which replaced TinyMCE with a Tiptap-based editor across every rich-text surface, redesigned the wiki, and added experimental PostgreSQL support beside MySQL/MariaDB. The three follow-up patches in three weeks are real bug-fix work — PostgreSQL ROUND/GROUP BY errors, ticket PATCH 500s, session lifetime regressions — not cosmetic tidying. The team also pushed accessibility to WCAG 2.1 AA in the prior 3.6 line.

◆ Where it's heading

Leantime is mid-modernization: editor stack, database portability, and design-system tokens are all moving at once. The volume of PostgreSQL-specific bug fixes since 3.7.0 suggests Postgres is being driven by real users hitting real edges, not just a checklist item. Editor-related fixes show Tiptap migration is still settling in.

◆ Prediction

Expect 3.7.4 within a couple of weeks closing the remaining migration-era bugs, then a clearer 3.8 push around design-token rollout or PostgreSQL going non-experimental.

O7.5

OpenProject leans into Jira migration and agile parity while absorbing a sustained bug-bounty wave

◆ Current state

OpenProject is shipping aggressively across five maintained release branches simultaneously. 17.4 promotes the Jira Migrator out of feature-flag status with basic custom-field migration, and 17.3 reshapes the agile primitives — dedicated sprint objects, all action board types moved into the free Community edition, in-place project attribute editing, nested groups. The codebase is also absorbing a continuous stream of security disclosures (CVE-2026-44731 through -44736, GHSA-r85r, GHSA-hh5p, others) from an EU-sponsored YesWeHack bug bounty, with backported fixes landing across 16.6.x, 17.0.x, 17.1.x, 17.2.x, and 17.3.x on the same day as the headline release.

◆ Where it's heading

The dual focus — Jira parity (custom-field migration, sprint objects, flexible backlogs) and a deliberate Community-edition expansion (all action boards now free) — reads as a coordinated squeeze on Jira during Atlassian's Cloud-only migration push. The bug-bounty volume is unusual for a project this size and suggests OpenProject has crossed into enterprise-credibility scrutiny; the response pattern — same-day backports five branches deep — shows the maintainers treating security disclosures as cross-branch events by default.

◆ Prediction

The next minor release will likely round out the Jira Migrator — workflow and automation migration are the obvious next pieces given custom fields are now beta-complete. Continued public bounty intake will keep producing authorization and IDOR fixes; expect another coordinated cross-branch security cut within weeks.

See more alternatives to Leantime
See more alternatives to OpenProject