← Back to home
Comparison · PM

Vikunja vs Tracecat

A side-by-side editorial comparison of Vikunja and Tracecat — release velocity, themes, recent moves, and the top alternatives to consider.

Vikunja vs Tracecat: at a glance

FeatureVikunjaTracecat
SectorPMPM
Velocity score0.07.5
Sparks · 30d02
Top themessecurity hardening, ssrf protection, idor fixes, account lockoutsecurity-automation, soar, mcp, open-source
Last editorial update4mo ago10h ago
WebsiteVisit →Visit →

What is Vikunja?

Vikunja crossed the v1.0 finish line and pivoted hard into security hardening.

Vikunja shipped two v1.0 release candidates through late 2025 and early 2026, then jumped to a v2 series whose first widely-tagged point release, v2.2.1, is dominated by security work. The latest release patches multiple SSRF and IDOR vulnerabilities, enforces disabled/locked-account semantics across every auth surface (OIDC, API tokens, CalDAV, LDAP), and adds a shared SSRF-safe HTTP client that webhooks and migrations now route through. User-facing feature work has slowed; the visible energy is in plumbing and audit cleanup.

Read the full Vikunja trajectory →

What is Tracecat?

Tracecat hits 1.0 RC with open-source agent presets, agent-case @mentions, and 20+ new security integrations.

Tracecat is in 1.0 release candidate territory, with RC.1 and RC.2 landing in quick succession. The platform has fundamentally expanded its case management system: agents can now be invoked from case comment @mentions, record their mutations back to cases, and have their runs filtered and linked to specific cases. The MCP catalog, agent presets, and skills were open-sourced in RC.1. The integration catalog grew by 20+ providers in beta.52 — Rippling, Jamf, Microsoft Graph, Databricks, Snowflake, Recorded Future, and others. RC.2 adds SSRF blocking for MCP and LLM requests and AWS role chaining.

Read the full Tracecat trajectory →

Vikunja vs Tracecat: editorial side-by-side

V0.0

Vikunja crossed the v1.0 finish line and pivoted hard into security hardening.

◆ Current state

Vikunja shipped two v1.0 release candidates through late 2025 and early 2026, then jumped to a v2 series whose first widely-tagged point release, v2.2.1, is dominated by security work. The latest release patches multiple SSRF and IDOR vulnerabilities, enforces disabled/locked-account semantics across every auth surface (OIDC, API tokens, CalDAV, LDAP), and adds a shared SSRF-safe HTTP client that webhooks and migrations now route through. User-facing feature work has slowed; the visible energy is in plumbing and audit cleanup.

◆ Where it's heading

The arc moves from feature-completion (S3 storage, drag-and-drop project moves, hover previews in late 2025) toward platform credibility — closing security gaps a self-hosted task tool needs to clear before serious team adoption. The rapid version-number jump from v1.0.0-rc4 to v2.2.1 in two months suggests v1.0 shipped and the team tagged a v2 line aimed at addressing accumulated authz debt. Expect the next several releases to keep the security-first posture rather than return to a feature push.

◆ Prediction

The next release will likely continue closing remaining authz edges (more IDOR audits, additional credential-stripping in API responses) and bundle a translations and dependency sweep. A user-facing feature push probably waits until the security work plateaus.

T7.5

Tracecat hits 1.0 RC with open-source agent presets, agent-case @mentions, and 20+ new security integrations.

◆ Current state

Tracecat is in 1.0 release candidate territory, with RC.1 and RC.2 landing in quick succession. The platform has fundamentally expanded its case management system: agents can now be invoked from case comment @mentions, record their mutations back to cases, and have their runs filtered and linked to specific cases. The MCP catalog, agent presets, and skills were open-sourced in RC.1. The integration catalog grew by 20+ providers in beta.52 — Rippling, Jamf, Microsoft Graph, Databricks, Snowflake, Recorded Future, and others. RC.2 adds SSRF blocking for MCP and LLM requests and AWS role chaining.

◆ Where it's heading

Tracecat is building toward a security automation platform where agents are primary workflow participants, not external integrations. The agent@mention model in case comments, combined with open-sourcing the MCP catalog for community contributions, signals a bet on collaborative human-agent case investigation rather than just automated runbooks. Dropping pydantic-ai in beta.52 in favor of a custom durable runtime reflects a commitment to owning the agent execution stack — the kind of choice that enables the SSRF blocking and error classification work shipping in parallel.

◆ Prediction

The 1.0 stable release will ship shortly and will lead with the agent-case interaction model as the headline capability. Post-stable, watch for expansion of the open-source MCP catalog driven by community contributions and a push around the enterprise entitlement and SCIM system for larger SOC teams.

Alternatives to Vikunja and Tracecat

Other PM products tracked by Sparkpulse, ranked by recent ship velocity. Each card links to a full editorial trajectory and lets you pivot into a head-to-head comparison with either Vikunja or Tracecat.

See all Vikunja alternatives → · See all Tracecat alternatives →

Recent activity from Vikunja and Tracecat

Latest ship moves from both products, interleaved chronologically. ⚡ = editorial spark.

  1. 15h agoTracecatTracecat 1.0.0-rc.2
  2. 1d agoTracecatTracecat 1.0.0-rc.1
  3. 4d agoTracecatTracecat 1.0.0-beta.53-rc.1: Case aggregation and skill tool grants
  4. 4d agoTracecatTracecat 1.0.0-beta.52: Agent @mentions in cases and 20+ new integrations
  5. 7d agoTracecatTracecat 1.0.0-beta.52-rc.24
  6. 12d agoTracecatTracecat 1.0.0-beta.52-rc.23
  7. 5mo agoVikunjav2.2.1: SSRF and IDOR patches plus disabled-account enforcement
  8. 7mo agoVikunjav1.0.0-rc4: drag-and-drop project moves, file-storage validation
  9. 9mo agoVikunjav1.0.0-rc3: S3 storage, comment counts, hover task previews

Frequently asked questions

What is the difference between Vikunja and Tracecat?

They serve adjacent needs but don't currently overlap on shipped themes. Tracecat is currently shipping more aggressively (velocity 7.5 vs 0.0), with 2 editorial sparks in the last 30 days against 0. See the at-a-glance table above for a side-by-side breakdown of velocity, recent sparks, and editorial themes.

Is Vikunja better than Tracecat?

Sparkpulse doesn't pick a winner — we score release velocity, not feature parity. Tracecat is currently shipping more aggressively (velocity 7.5 vs 0.0), with 2 editorial sparks in the last 30 days against 0. For your specific use case, the alternatives sections above list other PM products to evaluate alongside.

What are the best alternatives to Vikunja?

Top Vikunja alternatives in PM are ranked by recent ship velocity. Browse the "Vikunja alternatives" section above for the current picks, or visit /alternatives/vikunja for the full list with editorial commentary on each.

What are the best alternatives to Tracecat?

Top Tracecat alternatives in PM are ranked by recent ship velocity. Browse the "Tracecat alternatives" section above for the current picks, or visit /alternatives/tracecat for the full list with editorial commentary on each.