Open-Source Project Management Software: Options and Trade-Offs

Open-source project management software swaps a subscription for a server you run yourself. What you take on when you self-host, how each option lets an AI assistant in, and the questions to answer before you install anything.

8 min read

Open-source project management software gives you the code and the right to run it, usually on your own server. That buys you control over where the data lives, no per-seat plan to outgrow, and the freedom to change the software. It costs you the work a vendor would otherwise do: installing, upgrading, backing up, patching and watching for security advisories. Most of the well-known options also sell a hosted version, and some keep features such as single sign-on or AI access for the paid edition. The useful question is not which tool is best but which of those jobs your team is willing to own.

If you are mainly comparing what each tool gives away at no cost, that comparison lives in free project planning software. This page is about running one.

What “open source” does and does not get you

The license decides what you may do with the code, and the licenses differ. OpenProject is under the GNU GPL v3 and Redmine under the GPL v2: you can run and change them, and if you distribute a changed version you share the source. Plane’s Community Edition is under the AGPL-3.0, which extends that duty to modified versions you offer to others over a network. Kanboard and WeKan are under the MIT license, which asks for little more than keeping the notice.

Open source also rarely means everything is in the open edition. Many projects are “open core”: a free community edition and a paid one with extra features. Plane’s own open-source page (opens in a new tab) lists what the Community Edition includes (unlimited projects, work items and cycles, the REST API and webhooks) and keeps workflows and approvals, audit trails, SSO, epics, and third-party integrations such as GitHub and Slack for its Commercial Edition. Read that list for any tool before you choose it, because the feature you need may be on the wrong side of it. (If epics are the feature in question, epics, features and user stories covers whether you need them at all.)

Self-hosted or hosted by the project

Choosing open source does not oblige you to run it. OpenProject offers a managed Enterprise cloud alongside the self-managed install, and Taiga offers a cloud-hosted service as well as on-premise hosting. The trade is the same one you make with any software:

  • Self-hosted: the data stays on infrastructure you control, you choose when to upgrade, and you can modify the code. You also own uptime, backups, patching, sign-in and every incident.
  • Hosted by the project: someone else runs and patches it, and you can still take the data and the code and move to your own server later. You give up control of the upgrade schedule and the data’s location.
  • Hosted by a third party: a reseller or managed host runs the open-source code for you. Check who patches it, how fast, and how you get your data out.

The general case is covered in cloud project management software. The rest of this page assumes you are leaning toward running it yourself.

The maintenance and security work you take on

A self-hosted tracker holds your plans, your customers’ names and often your unreleased work, and it is reachable from wherever your team works. Treat it like any other production system. NIST’s guide to enterprise patch management (opens in a new tab) describes patching as identifying, prioritizing, acquiring, installing and verifying the installation of updates, and every one of those steps is now yours.

  1. Name an owner. One person is responsible for upgrades and a second can do them when the first is away.
  2. Subscribe to the project’s security notices. Redmine keeps a security advisories page (opens in a new tab) listing each fixed vulnerability by severity and the release that fixed it; check the equivalent for whatever you run.
  3. Back up the database and the file attachments, and restore them to a spare machine once before you need to. A backup that has never been restored is a hope, not a backup.
  4. Serve it over HTTPS only, and decide how people sign in. Single sign-on is often a paid-edition feature, so find out before you promise it to your security reviewer.
  5. Plan the major upgrades. Moving between major versions can mean database migrations and plugins that no longer load; read the upgrade notes before the day.
  6. Check the project is alive. Look at release dates and the repository’s README before you commit, and again once a year.

That last check matters more than it sounds. Focalboard, once a common self-hosted Trello alternative, now says in its own repository that it is not maintained, so nobody is fixing its security issues. Kanboard’s README states that it is in maintenance mode: the author is not building major new features, while community contributions keep it going. That suits a team that wants a small tool that stays the same; it does not suit one waiting for new features.

A one-page self-hosting plan to fill in before you install
Tool and edition:        ______  License: ______
Feature we need that is paid-only?  yes / no  (which: ______)
Server:                  ______  (CPU, RAM, disk, where it runs)
Owner / backup owner:    ______ / ______
Upgrade check:           first Monday of each month
Security notices:        subscribed at ______
Backups:                 nightly, kept 30 days, stored off the server
Restore test:            done on ______ (date), took ___ minutes
Sign-in:                 local accounts / SSO / LDAP
Reachable from:          office network / VPN / public internet over HTTPS
AI assistant access:     none / API token / MCP server (which: ______)
Exit plan:               export format ______, tested on ______

AI assistant access: what each option offers

If you want Claude, ChatGPT, Cursor or another assistant to read and update the board, look at how it would connect and whose permissions it would carry. The options differ more here than anywhere else, and the answer can depend on the edition. (What MCP is and how it works is in our MCP explainer.)

  • OpenProject has an MCP server, but its MCP server documentation (opens in a new tab) describes it as an Enterprise add-on for Enterprise cloud or Enterprise on-premises, not the Community edition. It signs in with a personal API token or OAuth, and actions use the permissions of the signed-in OpenProject user.
  • Plane publishes an MIT-licensed MCP server that, according to its developer documentation (opens in a new tab), works with a self-hosted instance by pointing PLANE_BASE_URL at it, and signs in with OAuth, a personal access token, or local environment variables.
  • Redmine has a REST API that an administrator switches on under Administration, Settings, API; each user then has an API key on their account page. Connecting an assistant means a community MCP server or one you write.
  • Kanboard’s API documentation (opens in a new tab) describes two kinds of access. The user API applies each user’s roles and project permissions. The application API uses a shared token and bypasses permission checks, so never hand that token to an assistant.
  • Taiga and WeKan both document REST APIs with token sign-in, so the same build-or-borrow choice applies.

Two cautions apply to all of them. First, an assistant connected with your API key acts as you, with all of your rights, and the tracker records its changes under your name; if you want its work told apart from yours, give it its own account with a narrower role. Second, a remote assistant needs to reach your server, so self-hosting behind a VPN can rule out cloud-hosted assistants unless you open a path for them. The trade-offs are laid out in local vs remote MCP servers.

The main options, in their own words

In alphabetical order, with no ranking. Each description comes from the project’s own site or repository as of October 1, 2026.

  • Kanboard. “Project management software that focuses on the Kanban methodology”, under the MIT license; in maintenance mode, as above.
  • OpenProject. Calls itself free and open-source project management software, under the GPL v3, with Gantt charts, agile boards for Scrum and kanban, and a team planner; self-managed or Enterprise cloud.
  • Plane. Community Edition under the AGPL-3.0, installable with Docker Compose, Kubernetes or Podman; epics, SSO and audit trails are in the Commercial Edition.
  • Redmine. “A flexible project management web application that can be self-hosted”, under the GPL v2, built on Ruby on Rails, with issue tracking, a Gantt chart, a calendar and multiple projects. Its 7.0.2 release came out on September 30, 2026.
  • Taiga. Describes itself as a free and open-source project management tool for agile teams, with Scrum and kanban modules that include epics and sub-tasks; cloud-hosted or self-hosted.
  • WeKan. A collaborative kanban board under the MIT license that presents itself as open source and privacy-focused, with self-hosting as the way to keep full control of your data.
  • Focalboard. Not maintained, by its own repository’s account. Do not start a new team on it.

When hosted is the better trade, and where fenbs fits

If nobody on the team wants to own upgrades and backups, a hosted tool is usually the honest choice. fenbs is one: it is a hosted service, not open source, and there is no version to install on your own server. If self-hosting is a requirement, it is not for you.

What it does instead is the AI part, without an edition gate. Every board connects to assistants at https://fenbs.ai/api/mcp with an OAuth sign-in or a token you issue under Settings with a name, scopes and an optional expiry, and revoking it ends access. Roles are set per company, so an assistant can hold less than you do, and History records every change with who made it, assistant included. The board itself is deliberately small: four lanes (To Do, Next Up, In Progress, Completed), three kinds of task (feature, enhancement, bug) and a priority from 1 to 10, with no epics, sprints, due dates or Gantt chart. Copy as Markdown copies the board out whenever you want it.

Related

Free plans compared: free project planning software. What to check in any tool an assistant will use: MCP server for project management: what to look for. Giving an assistant its own access: how to give an AI agent access to your project board. Setup: the MCP docs.

Questions people ask.

Is open source project management software really free?

The license costs nothing, but running it does not. You pay for a server, and your team spends time on installs, upgrades, backups and security patches. Many projects also sell a hosted or enterprise edition, and some features, such as single sign-on or an MCP server, may only be in that edition.

What is the difference between open source and self-hosted?

Open source describes the license: you can read, run and change the code. Self-hosted describes where it runs: on infrastructure you control. Most open-source trackers can be self-hosted, and many are also offered as a hosted service by the project itself.

Can AI assistants work with open source project management tools?

Yes, but how depends on the tool and edition. Plane publishes an MCP server that works with self-hosted instances. OpenProject has one as an Enterprise add-on. Redmine, Kanboard, Taiga and WeKan have APIs, so an assistant can connect through a community MCP server or one you build. Give the assistant its own account with a narrow role rather than your own key.

Is Focalboard still maintained?

No. As of October 1, 2026, its GitHub repository states that it is currently not maintained and asks for volunteers to take it over. A team starting fresh should pick a maintained tool.

Start with one thing.

There is nothing to set up first. Write one line and you’ve started.