OpenProject vs Shortcut
Side-by-side trajectory, velocity, and editorial themes.
OpenProject leans into Jira migration and agile parity while absorbing a sustained bug-bounty wave
OpenProject is shipping aggressively across five maintained release branches simultaneously. 17.4 promotes the Jira Migrator out of feature-flag status with basic custom-field migration, and 17.3 reshapes the agile primitives — dedicated sprint objects, all action board types moved into the free Community edition, in-place project attribute editing, nested groups. The codebase is also absorbing a continuous stream of security disclosures (CVE-2026-44731 through -44736, GHSA-r85r, GHSA-hh5p, others) from an EU-sponsored YesWeHack bug bounty, with backported fixes landing across 16.6.x, 17.0.x, 17.1.x, 17.2.x, and 17.3.x on the same day as the headline release.
The dual focus — Jira parity (custom-field migration, sprint objects, flexible backlogs) and a deliberate Community-edition expansion (all action boards now free) — reads as a coordinated squeeze on Jira during Atlassian's Cloud-only migration push. The bug-bounty volume is unusual for a project this size and suggests OpenProject has crossed into enterprise-credibility scrutiny; the response pattern — same-day backports five branches deep — shows the maintainers treating security disclosures as cross-branch events by default.
The next minor release will likely round out the Jira Migrator — workflow and automation migration are the obvious next pieces given custom fields are now beta-complete. Continued public bounty intake will keep producing authorization and IDOR fixes; expect another coordinated cross-branch security cut within weeks.
Shortcut redesigns its API for AI agents and pushes Korey beyond its own walls.
Shortcut is making concrete bets on agent-based work. API v4 entered alpha on May 12 with explicit framing around expanded capabilities and 'agent compatibility' — a positioning shift, not just a version bump. Their in-house AI assistant Korey is expanding outward: right-click access in February, then a dedicated Chrome extension in April that runs on any webpage. Around the strategic work, smaller improvements (Teams on Roadmap, March's SLA Alerts) keep shipping, alongside feed-noise from brand-guide pages being scraped as if they were releases.
Shortcut is positioning itself as the project-management surface that AI agents naturally operate against, not just a PM tool with AI features bolted on. Korey is being pushed from in-app helper toward general-purpose web assistant; the API is being redesigned with external agent consumers in mind. That's a coherent strategic stance the bigger PM players — Jira, Linear, Asana — have not yet made as explicitly. Underlying release cadence stays steady, suggesting these are strategic plays, not panicked pivots.
Expect API v4 to surface MCP-style tooling endpoints and structured action surfaces aimed squarely at agent frameworks. Korey's Chrome extension is likely a stepping stone toward a 'Korey anywhere' positioning — deeper integrations with browser, email, and calendar are the natural next dominoes.
See more alternatives to OpenProject →
See more alternatives to Shortcut →