Shipped vs. planned
What's built, and what isn't yet
Wicker Money is pre-1.0 with a single maintainer. This page mirrorsthe project's ROADMAP.mddirectly rather than restating it loosely, so it can't drift into overpromising.
Shipped Milestones M1–M3
| Auth & ledger | Users, accounts, categories, rules, transactions and splits — all under row-level security. Account balances are derived from the ledger, never stored. |
| App shell & plugin host | Module Federation host with dashboard widgets contributed by plugins, and per-plugin database roles derived from each plugin’s manifest. |
| Import & categorization | CSV import with saved column mappings, duplicate detection and batch undo. Category rules with a preview, plus triage on the Transactions page. |
| Budgets plugin | Per-category budgets with per-line rollover. |
Two more bundled plugins, insights and spending-trends, also ship in the image — see the repo for what they currently cover.
Now Scope of v0.1.0
- First tagged release (v0.1.0): self-hosting quickstart, a published container image, published plugin-sdk and ui-kit.
- Hardening first-run and deployment: registration policy, secure cookie guidance.
Next
- Recurring items management in core, on its own page: create, edit and end recurring bills and income. The table and its export exist today, but nothing can populate it yet.
- An upcoming bills & income widget: read-only, from today through your next payday, with expected income and bills at their nominal dates and a warning if a checking account would fall below its buffer amount before payday. Credit card and loan payments count as bills; transfers between your own accounts sit behind an “all” option.
- Paid/landed matching for that widget — matching expected recurring items against real transactions, which also settles weekend and holiday shifts as expected versus cleared.
- Forecasting, using recurring items for the known part of the future.
- A plugin picker to enable and disable plugins from the UI. Plugins in the same area, such as several budgeting approaches, can be enabled together.
- A debt payoff plugin (snowball and avalanche), keeping its own per-debt balance, rate and minimum payment.
- A settings danger zone with two separately-confirmed actions: “erase my data” (your own rows across core and every plugin) and “erase this entire instance”.
- A per-plugin theme contribution point, so a plugin can ship an additional theme alongside the built-in light/dark/system switcher.
Later
- Cross-plugin data access — a plugin reading data another plugin owns, such as debt details feeding net worth or FIRE, or comparing two budgeting plugins side by side. Today a plugin only sees core tables.
- An envelope budgeting plugin alongside the existing budgets plugin.
- FIRE plugins (lean, fat, barista, coast), comparable side by side on a shared calculation module and light enough to run several at once, once forecasting exists.
- Extending the shortfall warning to savings and other accounts, measured against each account’s buffer amount, for planning larger purchases.
- Editing an occurrence from the calendar widget, and a month grid view.
- Suggesting recurring items by detecting patterns in your transaction history.
- Themes as a data-only plugin type: a validated set of design tokens, no code.
- Third-party plugin installation — blocked on plugin isolation, which doesn’t exist yet; all plugin code today runs fully trusted.
- Freezing the plugin API (SDK_MAJOR_VERSION) ahead of 1.0.
How the plugin model works
The core owns identity, money movement and the app shell. Everything thatinterprets money — budgets, forecasting, FIRE, importers — is a plugin built against @wickermoney/plugin-sdk. A fresh install is useful on its own; bundled plugins hold no privileges a third-party plugin couldn't also request.
The app and bundled plugins are AGPL-3.0. plugin-sdk andui-kit — the surface a plugin is built against — are Apache-2.0, which is what makes an independently-built, non-bundled plugin licensable on its own terms. Third-party plugin installation itself isn't built yet, since it depends on plugin isolation that doesn't exist today.