Featured image of post Picking an Open-Source Accounting Base: jshERP vs Odoo vs ERPNext, Torn Down to Source Code

Picking an Open-Source Accounting Base: jshERP vs Odoo vs ERPNext, Torn Down to Source Code

107 parallel AI agents searching, fetching sources, and voting adversarially — plus a hands-on audit of the ERPNext China localization plugin running on my own server — comparing jshERP, Odoo Community + l10n_cn, and ERPNext down to the source code. Verdict: only Odoo Community has a real double-entry general ledger and a Chinese chart of accounts; jshERP's finance is a cash-flow ledger; ERPNext has zero China finance localization and its plugin has been dormant 8.5 months. What to do about marketing features and cracked Enterprise — solutions at the end.

TL;DR: Odoo Community + official l10n_cn. Don’t overthink it. It is the only one of the three with a real double-entry general ledger, a Chinese chart-of-accounts template, a VAT rate structure, and a complete accounting loop across receivables, payables, assets, and reports. jshERP’s “finance” module is a cash-flow ledger — no chart of accounts, no debit/credit vouchers; it cannot produce books that mean anything under accounting standards. ERPNext has a strong ledger, but zero China finance localization; its only Chinese plugin, erpnext_china, is a CRM/HRM localization that I audited on my own server — nothing to do with tax or accounting — and it has been unmaintained for 8+ months. Deep compliance (e-invoicing, Golden Tax, invoice verification) sits behind paid layers for all three; that is the ceiling of the entire open-source ecosystem, not an Odoo weakness.

How this research was run

I didn’t want to write another “feature-list relay” comparison — those articles are everywhere, they copy each other, and by the end even one-sentence-verifiable facts like “does jshERP have a general ledger?” come out wrong. This time, two legs:

Leg one: a 107-agent deep-research pipeline. Five parallel search tracks (overall comparison, China localization depth, licensing and commercialization, practitioner pitfalls, deployment and operations cost), roughly 20 primary sources pulled back (Odoo official module pages, GitHub repos, NVD/MITRE CVE databases, Frappe’s official licensing page), and every key claim sent to 3 adversarial verifiers whose only job was to refute it — 2 out of 3 refutations killed the claim. 949 tool calls, report in 20 minutes.

Leg two: my own hands. My server already runs an ERPNext v15 instance (Docker Compose, full six-container stack) with that erpnext_china plugin the Chinese community keeps recommending. This time I went into the container and read its source — which turned up the finding in the ERPNext section below.

The three candidates at a glance

jshERP (管伊佳)Odoo Community + l10n_cnERPNext (+ erpnext_china)
OriginChinese, formerly 华夏ERP, solo developerBelgian, 20 years, 627 community addonsIndian Frappe, GPLv3
StackJava: SpringBoot 2.0 + MyBatis + Vue 2Python monolith + PostgreSQLPython (Frappe) + MariaDB + Redis
DatabaseMySQL 8.0PostgreSQLMariaDB
GitHub4,609 stars / 1,512 forks54,552 stars39,512 stars
LicenseApache-2.0 (cleanest)LGPL-3 (Community)GPLv3 + trademark constraints
Maintainer14 contributors, one dominantOdoo SA + ecosystemFrappe + ecosystem

The two dimensions that decide it

Capability comparison
Five-axis assessment: chart of accounts / vouchers / VAT / GL loop are the hard gates

1. jshERP’s “finance” is not accounting — the easiest trap in this comparison

The README claims “inventory + finance + production.” I tore the source apart: AccountHead (financial document header) carries bill number, amount, handler, account ID. InOutItem (income/expense item) has exactly four fields: name, type, remark, sort. Across all 804 files — .java, .sql, .md, .vue — searches for accounting subjects, chart of accounts, debit/credit, Golden Tax, e-invoicing, VAT: zero hits. In the core schema, jsh_account is a cash account with opening/current balance, not an accounting account.

In plain terms: jshERP’s finance module is cash-flow bookkeeping around inventory documents (receipts, payments, transfers, AR/AP aging). It tracks who owes you and how much cash you hold; it does not care whether an expense belongs to administrative or selling expenses, or how to book a VAT input transfer. You can reconcile with it, but your bookkeeper still has to redo the books before anything can be filed.

It has real strengths: retail-style inventory (POS, purchasing, sales, multi-warehouse, assembly/disassembly BOM) is the most “shopkeeper-friendly” of the three, Apache-2.0 is the cleanest license, and 4.6k stars genuinely leads Chinese open-source ERP. If your need is fundamentally goods-and-cash, not books-and-filing, it’s a good tool — after you read the security section.

2. Odoo Community + l10n_cn: the only one that keeps real books

l10n_cn is Odoo’s officially maintained Chinese accounting localization, living in the main repo — not a third-party plugin of unknown origin. Its manifest is explicit: account types, chart-of-accounts templates, VAT structure, Chinese provinces, and two CoA templates (large-enterprise + small-business), plus voucher print formats. Install Odoo Community, pick China at database creation, and the accounts and standard VAT rates (13%, 9%, 6%, 3%) are laid out — general ledger, trial balance, AR/AP aging, asset depreciation, P&L and balance sheet, all working out of the box.

It is the only combination of the three with a complete double-entry accounting loop plus a Chinese CoA. The adversarial vote was 3-0.

Two traps to write into your decision:

  • Deep compliance is not in the open-source layer. Searching the Odoo app store for e-invoicing, Golden Tax, or Chinese bank reconciliation returns zero results (the same store offers free deep e-invoicing connectors for Saudi Arabia, Egypt, Jordan, and the UAE — China is a conspicuous exception). A third-party module that adds fapiao number fields to invoices exists for $43.66; it adds two fields and nothing else. The e-invoice and Golden Tax Phase IV interfaces are controlled by CAs and certified vendors — same roadblock for all three, only passable via paid layers or self-build.
  • Audit third-party China modules before installing. The free CoA module in the store bundles app_common and app_odoo_customize dependencies that modify official settings, sync from odooapp.cn, and inject vendor ads — you have to hand-edit the manifest to strip them; there is also a user report of crashes after install. Keep core bookkeeping on official l10n_cn and check dependency chains for everything else.

3. ERPNext: strong ledger, zero China finance localization, and the plugin is running on empty

First, the hands-on audit — the part of this research I’m most confident in, because I read the code myself.

erpnext_china (81 stars on GitHub) lists in its README: employee ID card fields, WeChat/QQ contact fields, China’s three-tier administrative divisions, WeCom login, translation polish. Sounds localized, right? I went into the container and read its module list: modules.txt contains exactly two modules — ERPNext China and HRMS China. Searches for fapiao, VAT, bank reconciliation in the code: zero hits. The only finance-adjacent thing in the whole plugin is a custom “manual split” field on Payment Entry.

So it is a CRM/HRM localization plugin, not a finance localization. The Chinese community recommends it as “the ERPNext China solution” — a textbook case of an error propagating by repetition.

Worse is the maintenance state: the last commit is 2026-01-07 — a README update. As of 2026-09-24 that is 8.5 months without substantive code. Four contributors, effectively one person (saoxia) doing everything. Depending on it as your company’s accounting base means betting China localization on an abandoned personal project.

Deployment cost, for the record: Frappe’s own self-hosting tutorial suggests 4 vCPU / 8 GB RAM, and under Docker, custom apps (like erpnext_china) must be built into a custom image and pushed to a registry — installing apps into a running container is explicitly unsupported (container immutability). Installing this dormant plugin costs you a CI image-build pipeline.

Security is jshERP’s dark hole, and this time it got verified thoroughly

This claim drew the most agents, because the numbers are ugly: roughly 35 CVEs recorded in NVD, spanning 2023-11 to 2026-09-21 — the latest batch published the month before this writing, affecting the latest version to date. Types include SQL injection, unauthenticated RCE (CVE-2025-60801), arbitrary file upload (CVE-2024-24000), path traversal (CVE-2026-1588, with public exploits), SSRF, privilege escalation, and tenant-isolation bypass.

Two details make it worse: first, its SQL-injection defense is a blacklist regex filter that can be bypassed with nested obfuscation, and that implementation is still on master today; second, in January 2024 someone opened an issue disclosing 4 SQLi + 1 file-upload PoCs — two and a half years, no maintainer response, no linked fix; the security-fix PR #166 is still open. Deploying it on the public internet is basically running a shop with the door open.

Licensing: if you want to commercialize, the order inverts

  • jshERP (Apache-2.0): cleanest — zero copyleft, zero redistribution restrictions, README explicitly allows commercial use. The cost: feature gaps are backfilled by the author’s paid Taobao plugins (the ¥198/year cloud is another route, but then it’s not self-hosting).
  • Odoo Community (LGPL-3): internal use and SaaS hosting are free; the real trap is the ecosystem — deep China finance modules are typically OPL-1 (no use without purchase, no redistribution). You cannot assemble deep compliance from the open-source layer.
  • ERPNext (GPLv3 + trademark): the code itself is commercially free (GPL constrains distribution, not internal use), but the trademark terms are hard bans — name/logo cannot appear in your product, domain, or company name; only referential use like “we provide ERPNext consulting” is allowed.

One sentence: for internal bookkeeping, none of the three licenses block you; if you plan to modify and resell, jshERP is easiest, Odoo Community is viable, ERPNext needs trademark care.

The recommendation

Accounting base: Odoo Community 18.0 + official l10n_cn. Three reasons: it is the only one with a real accounting loop; Python monolith + PostgreSQL runs with a single docker run, lowest operational complexity of the three; officially maintained with a 54k-star ecosystem — long-term viability isn’t bet on any individual maintainer. Accept two premises: deep compliance goes through external layers (the industry-wide reality), and third-party modules get dependency audits before install.

jshERP: consider it only when the need is fundamentally inventory + cash flow, and it runs on an intranet only (close the 35-CVE attack surface yourself before any public exposure).

ERPNext: unless your team is already deep in the Frappe ecosystem, it offers no China-specific advantage for bookkeeping — however strong the ledger, you lay out the CoA and VAT yourself from zero.

Appendix: what about the marketing features

I tore this apart too, since I wanted them as well. Straight to it:

Already in Community (source-level confirmed — these modules are all in the community repo): Email Marketing (mass_mailing, with templates, campaigns, unsubscribe management), SMS marketing (Twilio or local gateways), UTM source tracking + link click tracking, marketing cards, events/registration (the event family), website + blog + forms + live chat. For an SMB this covers 70-80% of everyday “marketing.”

Enterprise-only, exactly two things: Marketing Automation (drag-and-drop automation workflows — “customer signs up, no purchase in 3 days, auto-send email”) and Social Marketing (one board to schedule posts across multiple social accounts). Buying the full Enterprise suite for those two is bad math for a bookkeeping-first company.

Don’t touch cracked Enterprise: it’s pirated software with real enforcement precedent behind OPL modules; it can’t upgrade or patch; and running your accounting data on a system you never dare reinstall is exactly backwards. There is a legitimate road:

  • Automation workflows → Mautic: the open-source marketing automation benchmark (GPL) — drip sequences, behavior triggers, segmentation, landing-page A/B tests; connects to Odoo via webhook/API. The “3 days, no purchase” flow is finer-grained than Odoo Enterprise’s.
  • Social scheduling → Postiz (AGPL-3.0, active) or Mixpost (MIT): multi-platform scheduled publishing, a board view — essentially the open-source twin of Enterprise Social Marketing. Runs alongside Odoo; no conflict.

The plain stack: Odoo Community for books + inventory + email marketing, Mautic for automation journeys, Postiz for social — all open source, all self-hosted, zero subscription fees, zero legal gray zones.

Methodology and limits

107 agents, five search tracks, source fetching, 3-vote adversarial verification; one claim was downgraded 2-1 (“jshERP has the strongest inventory of the three” is a comparative judgment, qualified as “strongest in the retail-inventory style”). Four honest gaps: “no certified live open-source Golden Tax/e-invoice interface exists” is a directional judgment, not an exhaustive enumeration; Odoo Enterprise vs Community China-finance differences were not systematically compared (needed if you go paid); Frappe’s official l10n_cn CoA quality was not confirmed at the documentation page; real SMB deployment word-of-mouth was not in the claim set. None of this changes the direction of the three-way verdict, but don’t make a finer-grained paid-route decision from this post alone.

Primary sources

  1. Odoo l10n_cn source — official China accounting localization, CoA templates and VAT structure
  2. erpnext_china repo — 81 stars, last commit 2026-01-07, CRM/HRM localization
  3. jshERP repo — 4,609 stars, Apache-2.0, inventory + cash-flow finance
  4. NVD CVE database — ~35 jshERP CVEs, latest 2026-09
  5. Odoo store China invoice module — OPL-1, field-level features
  6. Odoo store free CoA module — ad injection and crash reports
  7. ERPNext license & trademark page — GPLv3 + hard trademark bans
  8. Frappe self-hosting tutorial — 4vCPU/8GB reference and container immutability
  9. jshERP issue #99 — 4 SQLi + file-upload PoCs, unanswered 2.5 years

This post is a technical selection record, not tax or legal advice. Consult a licensed bookkeeping agency or tax professional for compliance questions.