32 slides · use ← → · built from the report

existing-system audit

Solidus

A well-engineered open-source commerce framework that has quietly lost its steward for the second time in ten years — and a competitor that came back from the dead with a business model behind it.

See the full report ↗1 / 32

A set of Rails commerce libraries. You run everything; you own everything.

Solidus is not a hosted store: it is a set of Rails libraries you install into your own application — you run the servers, you own the database, you keep every customization.

See full: What Solidus actually is ↗2 / 32

observed

Forked from Spree in 2015. Its creator left in 2018; its steward, in 2024.

The arc in one line: forked from Spree in 2015, its creator gone by 2018, its steward's engineering gone by 2024 — and the machine still running on discipline the departed built.

See full: Timeline ↗3 / 32

observed

Technically healthy, strategically adrift.

Solidus is technically healthy and strategically adrift. Both are true, and the gap between them is the whole story.

See full: Executive Summary ↗4 / 32

observed

The whole story in four numbers.

  • 60% → 0.8%Nebulab's share of commits, 2023 → last 12 months
  • $45,760Already spent on the admin that never shipped
  • 3 yr 3 moAge of the new admin, still version 0.4
  • $132,180Cash held · nothing spent since July 2025
See full: Executive Summary ↗5 / 32

inferred

Losing the steward is this project's normal condition.

Losing the steward is not a shock this project suffered once; it is its normal condition, and in ten years the governance never grew a mechanism for handling it.

See full: Executive Summary ↗6 / 32

observed

Spree rides a business; Solidus rides a donation pot.

Spree's open source is a marketing cost carried on a real business; Solidus's is carried on a $25k donation pot.

See full: Executive Summary ↗7 / 32

observed

Every serious year funded a single engagement. 2021 and 2026: nothing.

Spending by year — and who received the bulk of it
YearPaid outExpensesWhere it went
2019$11,76810Conference costs — Sean Denny 43%, Cindy Backman 42%
2020$35,73624Peter Berkenbosch 80% — monthly "Development & Maintenance"
2021$00nothing at all
2022$5001One conference video-editing invoice
2023$45,7607The admin — Nebulab 79%, Andrea Iurisci 21%. 100% of the year.
2024$32,50616Logicielle B.V. 100% — 16 development invoices, Aug–Dec
2025$16,8886"e.c441" 100% — 6 development invoices, Feb–Jul
2026$00nothing at all
See full: Where the money went — and when it stopped ↗8 / 32

observed

Funded development stopped July 2025. $132,180 sits unspent while income keeps arriving.

The money in one line: funded development stopped on 5 July 2025, twelve and a half months of income have arrived since, and $132,180 sits unspent.

See full: Who can spend it ↗9 / 32

observed

Commit volume: the 2023 spike is one organization arriving and leaving.

20152,194
20162,244
20171,980
20181,070
2019883
20201,252
2021817
2022828
20231,810
20241,016
2025685
2026 ytd223
See full: Development volume by year ↗10 / 32

observed

Three rewrites look stalled. On the evidence, only the admin actually is.

The product in one line: three parallel rewrites read as systemic failure to finish, but promotions is a managed migration, the storefront a success — only the admin has stalled.

See full: The extension ecosystem ↗11 / 32

observed

The handover, in commits: 696 to 46 to 4 to zero.

Person (organization)20222023202420252026
Elia Schito (Nebulab)1336964640
Alberto Vena (Nebulab)7023252123
Rainer Dema (Nebulab)168200
Super Good Software (all)34314062136
See full: The withdrawal, year by year ↗12 / 32

observed

The steward wrote 60% of 2023's code — and 0.8% of last year's.

The people in one line: Nebulab supplied roughly 60% of all commits in 2023 and 0.8% over the last twelve months, and no announcement was ever made.

See full: Where decisions get made — and where they don't ↗13 / 32

observed

An excellent machine: tested against Rails and Ruby releases that don't exist yet.

The machine in one line: every change tested against four Ruby–Rails combinations including unreleased versions, deprecations failing the build, fixes back-ported automatically — top-decile delivery machinery for a project this size.

See full: The Machine ↗14 / 32

observed

$45,760 and three years bought version 0.4. Abandonment produces no symptom.

The most expensive initiative in the project's history stopped without a sound: three years and $45,760 in, the new admin is at version 0.4 — and the architecture makes abandonment produce no symptom.

See full: Why it stopped — three compounding causes ↗15 / 32

observed

Solidus and Spree, measured on the same day.

MetricSolidusSpree
Commits in the last 52 weeks4002,190 — 5.5×
GitHub stars5,31715,572
Forks1,4005,287
Latest releasev4.7.0 · 15 Apr 2026v5.6.0 · 23 Jul 2026
Releases in the last five weeks07
Cumulative package downloads3.22M2.85M
See full: Spree, Measured ↗16 / 32

observed

Spree came back shipping 5.5× the code, with enterprise revenue behind it.

The competitor in one line: Spree ships five and a half times Solidus's commit volume, seven releases in the last five weeks, and its free edition is the sales funnel for a paid enterprise product.

See full: Feature comparison ↗17 / 32

observed

The strategy in force: real rules, enforced by machines — written down almost nowhere.

RuleWritten where?Health
S1Reject the JavaScript-framework direction on purpose. Simplicity, one stack, no fees, distributed governance.on the lead maintainer's company blogThe project's actual strategy — stated, just not here
S2Never break an existing store. Deprecate before removing; back-port fixes to old versions.ratifiedHolding — at a cost nobody has priced
S3Ship replacements alongside the old version as opt-in, with a written migration guide; the old one stays until stores have moved.in the gems, not the governanceWorking — see the promotions migration guide
S4Core stays lean; capabilities live in separate extensions.nowhereWeakening — four official extensions dormant
See full: The Strategy Already in Force ↗18 / 32

observed

The strategy in force: real rules, enforced by machines — written down almost nowhere.

RuleWritten where?Health
S5Merge authority belongs to a self-appointing Core Team. Money buys votes on spending, never on code.ratifiedYes — the separation is deliberate and healthy
S6Quality is enforced by machines; style is not argued about.only in CI configThe best-functioning rule in the project
S7All delivery is done by humans.by omissionUntested — no agent harness exists
See full: The Strategy Already in Force ↗19 / 32

observed

An unfunded initiative sitting next to an unspent budget.

The two causes compound into a single condition: an unfunded initiative sitting next to an unspent budget.

See full: Root Causes ↗20 / 32

inferred

Five risks, ranked by damage times likelihood times how quietly they land.

RiskFlagLikelihoodWould you notice?
R1Routine dependency drift between security releasesdowngradedLow for disclosed vulnerabilities — that path is covered. Medium for driftFor a disclosed CVE, yes. For gradual drift, no
R2Two firms are 78% of the money and most of the codehard to detectMedium — this has already happened twiceNot for months. A departure looks exactly like a quiet quarter
R3The half-built admin becomes a permanent third statehard to detectHigh — it is the current trajectoryNo. Every signal a maintainer looks at is green
R4Spree takes the new-project marketeasy to see coming
R5The new storefront breaks existing extensions by design
See full: Risk Register ↗21 / 32

inferred

The risk map: the stalled admin is both likely and quiet.

Impact if it lands
Plan & monitorAct nowWatchlistContingencyR3The new admin stays stalled — placed high because the silence is the findingR2Contributor concentration — one organization's withdrawal already proved the shapeR4Spree competition compounds while Solidus stands stillR5Extension breakage on major upgradesR1Routine dependency drift between security releases
Likelihood inside twelve months
  1. R3The new admin stays stalled — placed high because the silence is the finding
  2. R2Contributor concentration — one organization's withdrawal already proved the shape
  3. R4Spree competition compounds while Solidus stands still
  4. R5Extension breakage on major upgrades
  5. R1Routine dependency drift between security releases
Risk exposure.
See full: Risk Register ↗22 / 32

inferred

Four debts, paid every release — the biggest is invisible on every dashboard.

DebtKind
D1Three unfinished rewritesstrategic
D2Governance describes a project that no longer existsorganizational
D3Architectural decisions are never recordedknowledge
D4The agent harness, and two small automation gapstechnical
See full: Debt Ledger ↗23 / 32

observed

Nine credits booked: every machine investment paid back; both product bets stalled.

CreditStatus
C1Test matrix including unreleased Rails 8.1 and Ruby 4.0confirmed
C2Deprecation build gateconfirmed
C3Automated back-portingconfirmed
C4Automated code styleconfirmed
C5Release and changelog automationconfirmed
C6Reproducible development environmentconfirmed
C7The storefrontconfirmed
C8solidus_promotionsoverdue
C9solidus_adminpast the point of write-off
See full: Credit Ledger ↗24 / 32

inferred

A role, not a comeback: the framework you can still own in ten years.

The conclusion this evidence supports is a role, not a comeback: the commerce framework you can still own in ten years, serving the merchants who already chose it.

See full: Choose a Role ↗25 / 32

inferred

Three legitimate roles. Drifting between them is the only illegitimate option.

The three roles, side by side
RoleThe moveThe catch
A — Steward the installed baseNo new initiatives; guarantee upgrades and security; finish promotions; cancel the admin and storefrontAn explicit acceptance of managed decline — some contributors will leave
B — Contest the agent channelShip the missing agent harness; sell "one runtime, one test command" to agent-driven buildersSpree shipped theirs first — a modifier on Role A, not an alternative
C — Converge with SpreeFold back into the project Solidus forked fromNobody inside will propose it, which is exactly why it must be written down
See full: Choose a Role ↗26 / 32

inferred

Nine bets, scored — most cost a meeting, a config file, or nothing.

BetVerdictAddressesCost
B2Restart funded development — buying an outcome, not sprintsDoR3, D1one meeting agenda item
B3Routine dependency-update automation (security updates already run)CheapR1a config file
B4Agent harness, scoped to executing B3 and B5DoD4, S7, Role B~a day
B5Name the release that removes legacy promotions — a policy statement, not labourDoD1, RC1free
B6Decide the admin — by manufacturing the evidence, not deliberating without itDecideR3, D1one hard screen
See full: Bets — for you to set ↗27 / 32

inferred

Nine bets, scored — most cost a meeting, a config file, or nothing.

BetVerdictAddressesCost
B7Match Spree's React storefrontKillR4
B8GraphQL / headless surfaceWaitR4
B9Dual asset-pipeline support, with an agent-executed migrationDoR1, D3, D4see template
B10Publish technical decisions — restart the status posts, file forward-looking roadmap itemsDoD2, D3, S1, R4an hour a month
See full: Bets — for you to set ↗28 / 32

inferred

The sequence: decisions now, delegable work after.

Now — weeks
Next quarter
Horizon 2
Bets
B6 · port one hard admin screen
B10 · publish decisions again
B4 · agent harness
B3 · dependency automation and audit
B5 · name the release that drops legacy promotions
Role A or A+B declared publicly
See full: Sequence ↗29 / 32

inferred

The fixes are cheap: publish decisions, name dates, fund outcomes — not sprints.

The moves in one line: none of the first steps is expensive — publish the decisions being made, name the release that removes legacy promotions, and fund outcomes rather than sprints.

See full: Sequence ↗30 / 32

Don't take the deck's word: every claim is tagged and checkable in the report.

Nothing here asks to be believed: every factual claim in this report carries a tag saying how it was arrived at, and the tags are counted by the build, never authored.

See full: What I Could Not Establish ↗31 / 32

Before the conclusions

97 tagged claims

observed63%61
web30%29
user0%0
inferred7%7
assumed0%0

How much of what you just heard was actually observed.

See the full report ↗32 / 32