Umami

Productivity

A simple, fast, privacy-focused alternative to Google Analytics.

Latest v3.2.0 · by Umami SoftwareWebsiteumami-software/umami

Release activity

Release activity — 9 releases across 8 days in the last year. Each cell is one day; darker means more releases that day. Older weeks are hidden at this screen width.
MayJunJulAug
SundayNo releases on Apr 26, 2026No releases on May 3, 2026No releases on May 10, 2026No releases on May 17, 2026No releases on May 24, 2026No releases on May 31, 2026No releases on Jun 7, 2026No releases on Jun 14, 2026No releases on Jun 21, 2026No releases on Jun 28, 2026No releases on Jul 5, 2026No releases on Jul 12, 2026No releases on Jul 19, 2026No releases on Jul 26, 2026No releases on Aug 2, 2026No releases on Aug 9, 2026
MondayNo releases on Apr 27, 2026No releases on May 4, 2026No releases on May 11, 2026No releases on May 18, 2026No releases on May 25, 2026No releases on Jun 1, 2026No releases on Jun 8, 2026No releases on Jun 15, 2026No releases on Jun 22, 2026No releases on Jun 29, 2026No releases on Jul 6, 2026No releases on Jul 13, 2026No releases on Jul 20, 2026No releases on Jul 27, 2026No releases on Aug 3, 2026No releases on Aug 10, 2026
TuesdayNo releases on Apr 28, 2026No releases on May 5, 2026No releases on May 12, 2026No releases on May 19, 2026No releases on May 26, 2026No releases on Jun 2, 2026No releases on Jun 9, 2026No releases on Jun 16, 2026No releases on Jun 23, 2026No releases on Jun 30, 2026No releases on Jul 7, 2026No releases on Jul 14, 2026No releases on Jul 21, 2026No releases on Jul 28, 2026No releases on Aug 4, 2026
WednesdayNo releases on Apr 29, 2026No releases on May 6, 2026No releases on May 13, 2026No releases on May 20, 2026No releases on May 27, 2026No releases on Jun 3, 2026No releases on Jun 10, 2026No releases on Jun 17, 20261 release on Jun 24, 2026No releases on Jul 1, 2026No releases on Jul 8, 2026No releases on Jul 15, 2026No releases on Jul 22, 2026No releases on Jul 29, 2026No releases on Aug 5, 2026
ThursdayNo releases on Apr 30, 2026No releases on May 7, 2026No releases on May 14, 2026No releases on May 21, 2026No releases on May 28, 2026No releases on Jun 4, 2026No releases on Jun 11, 2026No releases on Jun 18, 2026No releases on Jun 25, 2026No releases on Jul 2, 2026No releases on Jul 9, 2026No releases on Jul 16, 2026No releases on Jul 23, 2026No releases on Jul 30, 2026No releases on Aug 6, 2026
FridayNo releases on May 1, 2026No releases on May 8, 2026No releases on May 15, 2026No releases on May 22, 2026No releases on May 29, 2026No releases on Jun 5, 2026No releases on Jun 12, 2026No releases on Jun 19, 2026No releases on Jun 26, 2026No releases on Jul 3, 2026No releases on Jul 10, 2026No releases on Jul 17, 2026No releases on Jul 24, 2026No releases on Jul 31, 2026No releases on Aug 7, 2026
SaturdayNo releases on May 2, 2026No releases on May 9, 2026No releases on May 16, 2026No releases on May 23, 2026No releases on May 30, 2026No releases on Jun 6, 2026No releases on Jun 13, 2026No releases on Jun 20, 2026No releases on Jun 27, 2026No releases on Jul 4, 2026No releases on Jul 11, 2026No releases on Jul 18, 2026No releases on Jul 25, 2026No releases on Aug 1, 2026No releases on Aug 8, 2026

9 releases in the last year, busiest day 2

Changelog

v3.2.0

Added 14
  • Heatmaps are now available as a first-class website report with click and scroll heatmaps to understand visitor interactions
  • Snapshot-based heatmap rendering with iframe previews and page path filtering
  • Screen-width grouping for responsive layouts in heatmaps with depth labels and improved overlay scaling
  • Self-hosted heatmap recording and storage support
  • Replay filters for finding sessions faster
  • Event data filters for booleans, dates, and arrays
Changed 6
  • Fragmented replay events are normalized for playback
  • Full rrweb snapshots are handled as separate replay chunks
  • Replay payloads are chunked and oversized payloads are rejected
  • Replay events flush on pagehide with a shorter interval
  • Revenue reports have been split into focused APIs and views for better performance and flexibility
  • Website selector dropdown limit increased from 10 to 100
Fixed 10
  • Retention report completeness
  • Dashboard and Board editing in Firefox
  • Funnel alias issues
  • Ambiguous query errors
  • Username login case-insensitivity
  • Redirect logged-in users away from the login page
Security 11
  • Sanitizes sensitive data in logs
  • Hides internal Prisma and database errors from API responses
  • Hardens analytics writes and avoids leaking internal server errors to clients
  • Validates SSO redirect URLs before setting auth tokens
  • Restricts team owner assignment to admins
  • Enforces team role hierarchy on user updates and removals

Umami v3.2.0 is here with new Heatmaps, improved properties reporting, better Session Replay controls, revenue report improvements, and a large set of security, performance, and UI fixes.

New features
Heatmaps

Heatmaps are now available as a first-class website report. Use click and scroll heatmaps to understand where visitors interact with each page, with overlays rendered from captured replay snapshots.

  • Click and scroll heatmap reports
  • Snapshot-based rendering with iframe previews
  • Page path filtering
  • Screen-width grouping for responsive layouts
  • Depth labels and improved overlay scaling
  • Self-hosted heatmap recording and storage support
Session Replay improvements

Session Replay received a round of reliability, filtering, and playback improvements.

  • Replay filters for finding sessions faster
  • Fragmented replay events are normalized for playback
  • Full rrweb snapshots are handled as separate replay chunks
  • Replay payloads are chunked and oversized payloads are rejected
  • Replay events flush on pagehide with a shorter interval
  • Mobile layout and modal styling improvements
Event and session property reporting

Property reports now support richer data types and reusable charting across both event data and session data.

  • Event data filters for booleans, dates, and arrays
  • Event data charts for arrays, booleans, dates, and numeric values
  • Session data screens with filtering, pivot tables, and property charts
  • Property filter UI shared across event and session data
  • Query optimizations for session property filters
Revenue reporting

Revenue reports have been split into focused APIs and views for better performance and flexibility.

  • Cumulative mode for revenue charts
  • Separate revenue chart, metrics, stats, and session queries
  • Revenue metrics table and metrics bar
  • Improved realtime report UI
DataGrid and table improvements
  • Manual table/card view toggle for DataGrid
  • Sorting on non-analytics tables, including websites, boards, links, pixels, teams, and admin tables
  • Horizontal scrolling for overflowing tables
  • Stable event chart colors across date range changes
  • Hidden events stay hidden when the date range changes
Tracker and API improvements
  • data-auto-pageview tracker attribute to suppress SPA pageview tracking when auto-pageview is disabled
  • Tracker click handling for annotated containers
  • Graceful handling for invalid pushState URLs
  • URL query values included in pages report display
  • LLM channel logic
  • URL pageview metric and expanded metric support
  • Configurable internal API URL handling
Sharing
  • Share page options for filtering and theme enforcement
  • Share-token permissions for websites, boards, links, and pixels
  • Board share entity authorization fixes
  • Unrestricted access for share tokens without section flags
Security
  • Invalidates authenticated sessions after password changes
  • Sanitizes sensitive data in logs
  • Hides internal Prisma and database errors from API responses
  • Hardens analytics writes and avoids leaking internal server errors to clients
  • Validates SSO redirect URLs before setting auth tokens
  • Restricts team owner assignment to admins
  • Enforces team role hierarchy on user updates and removals
  • Fixes share token confusion vulnerabilities
  • Tightens API access checks by website section and share permissions
  • Sanitizes CSV exports against formula injection
  • Limits batch API payloads to 500 items
  • Uses authenticated Redis keys on logout
Migrations

This release includes schema migrations for Heatmaps and event/session data pivot support:

  • prisma/migrations/20_add_heatmap

Migrations run automatically during the build process.

Fixes
  • Retention report completeness
  • Dashboard and Board editing in Firefox #4168
  • Funnel alias issues #4144
  • Ambiguous query errors #4176
  • Username login case-insensitivity #3981
  • Redirect logged-in users away from the login page
  • Active users indicator realtime link
  • Website selector dropdown limit increased from 10 to 100
  • DataGrid pagination preserving query params
  • Long URLs in Links table pushing action buttons off-screen
  • Long distinct IDs in session info
  • Invalid dates causing Firefox event chart errors
  • NaN timestamps breaking event charts in Firefox
  • Pages report url_query display
  • Empty and null value handling
  • Malformed client IP handling in /api/send
  • Invalid IP and localhost lookup failures in location detection
  • Channel metrics queries
  • Column alias collisions in session filters
  • Pie chart rendering without a default height
  • Broken demo link in the README
  • Missing translations and consistency updates across multiple locales
  • Country and flag data updates
Updates
  • Next.js 16.2.6
  • Prisma 7.8.0
  • Cypress and Jest test suites migrated to Playwright and Vitest
  • GitHub workflows migrated to Blacksmith runners
  • Runtime, frontend, and security dependency updates
Thanks

@nurlennart @IEBqp @Maxime-J @Karthited @Nirator78 @manuelfesantos @JLUpengjiaji @yhyasyrian @tairosonloa @c0ball @anvme @yancat160 @seojcarlos @God-2077 @sputnik-mac @avasis-ai @SAYOUNCDR @nielskaspers @AymanAlSuleihi @gputier @ElfenB @ip00 @swayam-mishra @mturac @KadirFiratFTW @Kyzenkms

Full Changelog: https://github.com/umami-software/umami/compare/v3.1.0...v3.2.0

View originalPermalink
How v3.2.0 went

v3.1.0

Added 18
  • Create custom dashboards with Boards feature including row/column layout editor, per-component website binding, TextBlock components, board sharing and duplication, and dashboard-wide date range and filter controls
  • Session Replay feature to watch real user sessions replayed in the browser with configurable masking levels, per-visit recording, filterable replays table, and replay modal with mobile-friendly playback
  • Web Vitals performance tracking for Core Web Vitals (LCP, INP, CLS, FCP, TTFB) with industry-standard calculations and rating badges
  • OR logic across filters, segments, and cohorts
  • Regex operators for filter matching
  • Multiselect on equals and not-equals operators
Changed 2
  • Redesigned share page with full mobile support, collapsible sidenav, per-share display options, ability to name share links, choose visible sections, and apply filtered navigation
  • Migrated from react-intl to next-intl with all 51 locale files translated

Umami v3.1.0 is here with a ton of new features, including the much-anticipated Boards and Session Replay. This release also brings Web Vitals performance tracking, a redesigned share page, and hundreds of fixes and improvements.

New features
Boards

Boards are here! Create your own custom dashboards by composing components on a flexible row/column canvas. Pick from charts, tables, and metric components, bind them to any website, and share the finished board with your team.

  • Row/column layout editor with resize, reorder, and remove controls
  • Per-component website binding and live preview
  • Free-form TextBlock components for notes and section headers
  • Board sharing, duplication, and table-level edit/delete actions
  • Dashboard-wide date range and filter controls
Session Replay

Watch real user sessions replayed in the browser. Session Replay is built on rrweb and works alongside your existing tracker.

  • Configurable masking levels for privacy (defaults to moderate)
  • Per-visit recording so replays stay short and focused
  • Filterable replays table with event-level filtering
  • Replay modal with mobile-friendly playback
Web Vitals performance tracking

Track Core Web Vitals (LCP, INP, CLS, FCP, TTFB) from your visitors' browsers. The redesigned Performance page shows industry-standard calculations with rating badges for each metric.

Redesigned share page

Share pages have a fresh look with full mobile support, a collapsible sidenav, and per-share display options. You can now:

  • Name each share link
  • Choose which sections visitors can see (overview, events, etc.)
  • Apply filtered navigation so visitors only see what you want
Filters, segments, and cohorts
  • OR logic across filters, segments, and cohorts
  • Regex operators for more powerful matching
  • Multiselect on equals/not-equals operators
  • UTM filters and fields exposed throughout the app
  • Exclude bounces toggle with filter-form integration
Funnels
  • Per-step event property filters in both funnel creation and overview
  • Wildcard support in the goals report
Other improvements
  • Custom slug support for Links
  • Pixel and Link detail pages with sharing
  • MetricsBar added to the Events page
  • Event type filter on Journeys
  • Time unit selector (hour/day/month)
  • Distinct ID available as a filter and metric dimension
  • Cache-control headers on GET responses
  • SKIP_BUILD_GEO env variable to skip geo DB build
  • Configurable salt rotation period via env vars
  • EdgeOne geolocation headers
  • Version endpoint and settings display
  • Download for breakdown reports
  • Pagination limit on event charts, metrics tables, and UTM reports
Admin & internationalization
  • Migrated from react-intl to next-intl with all 51 locale files translated
  • Adopted the react-zen design system across the app
  • Consolidated top navigation with embedded selectors for websites, boards, links, and pixels
  • Team validation and redirect for invalid teams
  • Team-gated feature resolution via Redis
Security
  • Fixed IDOR vulnerabilities in reports and segments
  • Blocked share tokens from all editing permissions and API modifications
  • Restricted x-umami-client-* headers to cloud mode
  • Various dependency vulnerability fixes (tar, ajv, jws, brace-expansion, next)
Migrations

This release includes schema migrations for Boards, Shares, Session Replay, and board duplicate-key handling. Migrations run automatically during the build process.

Fixes
  • PostgreSQL 12/13 syntax error in Journeys #3970
  • Implicit alias syntax error in Postgres session and event queries #4147
  • name alias compatibility for Postgres 12 relational queries #3970
  • Table alias missing in filterQuery #3869
  • Timezone not applied to relational queries #3975
  • Revenue chart timezone mismatch #4107
  • Ambiguous session_id errors in SQL queries
  • Breakdown alias column not found
  • www. prefix not stripped during hostname comparison #3256
  • Minute label formatting #3088
  • Website select page size limited to 10 #3913
  • Deleted website visibility #3865
  • BASE_PATH support #4064
  • Pixel event tracking #4028
  • Pagination issues #4029
  • Login email case-sensitivity #3981
  • Tracker double-initialization when script injected more than once
  • Tracker fetch priority now set to low #3642
  • robots.txt fixes #3996
  • Goals wildcard support #4086
  • MetricsBar on Events page #3830
  • Distinct ID in filters / expanded metrics #3861
  • Team admin workflow for team members #2767
  • Event type filter for Journeys #2803
  • Salt rotation configurable via env #3427
  • Share token allowing access to pages with undefined share params
  • Fix #4058 (pixel tracking null referrer)
  • Autofill background color in forms
  • Denied storage access in tracker
  • Prisma session race condition
  • Docker Prisma migrate and stray query log
  • Monthly truncation timezone issue
  • Share page retention and logo margins
  • Filters persisting across website change
  • "All time" filter on websites with no data
  • Japanese translation for "breakdown" label
  • UAE emirate names in iso-3166-2.json
  • IPv6 handling for client IP detection
  • Numerous mobile UI fixes across admin, nav, share, and team screens
Updates
  • Next.js 16.2.4
  • Prisma 7.6.0
  • Minimum Node.js version bumped to 22 (Prisma 7 requirement)
Thanks

@Yashh56 @boutterudy @AymanAlSuleihi @juanisidoro @cryst-hq @RaenonX @PaiJi @Gouttfi @AlejandroGispert @lawrence3699 @kkhys @journry789 @sputnik-mac @sbozh @Mintimate @Mravuri96 @maphubs @maennenajere @XahidEx @IndraGunawan @GochoMugo @FEgor04 @Nayrode @diogotcorreia @dyanakiev @fauzora @BrentRobert @hilja

View originalPermalink
How v3.1.0 went

v2.20.1

Fixed 1
  • Fix Docker build issues
Security 1
  • Address Next.js CVE-2025-66478 by updating affected React versions

This is a patch release to address the Next.js CVE. The previous release did not update the affected React versions, only Next.js. This release also fixes some Docker build issues.

View originalPermalink
How v2.20.1 went

v2.20.0

Security 1
  • Address Next.js CVE-2025-66478

This release is only to address the the Next.js CVE for v2.

View originalPermalink
How v2.20.0 went

v3.0.2

Changed 2
  • Next.js updated to 15.5.7
  • Prisma updated to 6.19.0
Fixed 13
  • Time range selection back and forward arrows not jumping with correct steps
  • Links and Pixels are prefetched on dashboard
  • Chart legend extends beyond container boundaries when URL is too long, disrupting page layout
  • User is not able to switch back to My Account after switching to the Team
  • Reset of website stats is not possible after entries in Revenue table
  • Team workspace is not selectable after login
Security 1
  • Address Next.js CVE-2025-66478 critical vulnerability in RSC

This is a patch release to address the Next.js CVE and fixes many bugs.

Fixes
  • Nextjs/RSC critical vulnerability #3829
  • Time range selection back and forward arrows not jumping with correct steps #3828
  • Links and Pixels are prefetched on dashboard #3814
  • In the chart legend, when the URL is too long, the legend extends beyond the container boundaries, disrupting the page layout. #3813
  • User is not able to switch back to My Account after switching to the Team #3802
  • Reset of website stats is not possible after entries in Revenue table #3798
  • Team workspace is not selectable after login #3796
  • Error with long UTM parameters and click IDs #3790
  • Direct visitors are missing on Channels (3.0.1) #3789
  • "Last seen" - "First seen" fields broken since 3.0.1 #3775
  • Tests are failing in 3.0.1 #3773
  • Revenue sums not showing in 3.0.1 #3769
  • Read-only prevents user from joining team #3764
  • Regression: URL theme and lang parameters no longer work for public share links #3754
Updates
  • Next.js 15.5.7
  • Prisma 6.19.0
Thanks

@Lokimorty @imsyedabdullah @RaenonX @IndraGunawan

View originalPermalink
How v3.0.2 went

v3.0.1

Fixed 15
  • Password managers unable to detect email field on login form
  • Support local timezone for date period
  • Event data raw query failure
  • Website Stats API Call returns null in some fields
  • Loop when login page not accessed directly
  • Geo-location tracking (Country) broken in v3.0, showing "Unknown" for majority of visitors

This is a patch release that fixes many bugs.

Fixes
  • Password managers unable to detect email field on login form #3735
  • Support local timezone for date period #3733
  • Event data raw query failure #3732
  • Website Stats API Call returns null in some fields #3712
  • Loop when login page not accessed directly #3703
  • Geo-location tracking (Country) broken in v3.0, showing "Unknown" for majority of visitors #3701
  • UX – Prevent exporting empty datasets #3699
  • Events view for "Today" doesn't show all hourly columns #3697
  • Realtime activity view basically unusable on mobile #3694
  • No Revenue showing after update to 3.0.0 #3692
  • Deprecated timezone 'Asia/Saigon' causes PostgreSQL error in Umami (chart shows empty) #3691
  • Support local timezone for date period #3733
  • Long links are cut off #3680
  • Queries fail with Asia/Calcutta timezone → Postgres 22023 / Prisma P2010 (Umami 2.19.0) #3660
  • Location statistics broken when tracking IPv6 clients #3616
  • Invalid reference to FROM-clause entry for table "session_data" at character 362 #3545
Thanks

@Maxime-J @Mintimate @prince0xdev @mathis5711

View originalPermalink
How v3.0.1 went

v3.0.0

Added 5
  • Add segments as saved sets of filters that can be reused across the application
  • Add cohorts to track groups of users who share a common event or experience during a specific time period
  • Introduce links as short URLs for tracking clicks and downloads with dedicated stats pages
  • Introduce pixels as invisible images for tracking traffic and measuring metrics like email open rates with dedicated stats pages
  • Add dedicated admin page for admin users to view and manage all users, websites, and teams in the system
Changed 5
  • Update UI to be more user-friendly with a new navigation bar and separated reports into individual pages
  • Apply filters universally throughout the application via query string to allow sharing filtered URLs with teams
  • Enhance filter form to add and edit multiple filters at once
  • Update Next to v15.5.3
  • Update Prisma to v6.18.0
Removed 1
  • Remove support for MySQL as a database option, only PostgreSQL is now supported

We are excited to announce the release of Umami v3! This release comes with a new interface, lots of new features and enhancements and lays the groundwork for the future of the application. Read more about it on our blog post.

New features and improvements
Updated UI

We've updated the UI to be more user friendly and help you see all your data at a glance. With the new navigation bar you can quickly see all your website content and even easily switch between websites with the embedded dropdown.

Additionally, all the previous reports have been separated out into individual pages for easier access.

Improved filters

Filters are now applied universally everywhere in the application via the query string. That means you can copy the URL to share with your team and it will remember what filters were applied.

We've also enhanced the filter form so that you can add and edit multiple filters at once.

Segments and cohorts

Segments are a set of filters that you can save to use for later. For example, you can create a segment called Windows users from the United States, and apply it to your data via the filter form.

A cohort is a group of users who share a common event or experience during a specific time period, and are then tracked over time. For example, you can create a cohort called Users who signed up in November. You can then analyze retention or behavior over time. Just like segments, cohorts can be applied as a filter parameter.

Links and pixels

Umami v3 introduces two additional elements you can use for tracking, links and pixels. Links are simply short URLs that redirect to another URL. You can use links to measure how often users are clicking on certain links or as download links to a file to see how many downloads it received.

Pixels are invisible images your can embed elsewhere to measure traffic. For example, on external websites where you can't install a website tracker but can post images. You can also embed pixels into your emails to measure open rates, for example in a monthly newsletter to members.

Both links and pixels have their own stats pages just like websites.

New admin page

There is a new dedicated admin page for admin users. You can view and make changes to all the users, websites and teams in the system.

Coming soon

One feature that unfortunately didn't make it into this release was Boards. With boards, you would be able to create your own dashboards and components to display your data however you like. We're still hard at work on it and it will be available in the next release.

Breaking changes

Umami v3 no longer supports MySQL as a database option, only PostgreSQL. If you want to migrate your data over we've written a guide to help you migrate.

Updates
  • Next v15.5.3
  • Prisma v6.18.0
Thanks

@mdotme @mcnaveen @kronthto @malwarepad @nickcmaynard @andreynering @matiasfacello @halkeye @fauzora @0xflotus @badmike @fnwbr @markkuhar

View originalPermalink
How v3.0.0 went

v2.19.0

Added 4
  • Export data directly from the UI with a download button on the overview page to get all stats in CSV format
  • Download individual stats from different sections and reports in CSV format
  • View custom event properties as a chart or as a table
  • Create a new table for holding revenue data via migration
Changed 2
  • Upgraded Next to 15.3.3
  • Upgraded Prisma to 6.7.0
Fixed 5
  • Fixed environment variables so they work in Docker at runtime
  • Fixed malformed frameAncestors
  • Added keepalive to tracker fetch
  • Improved performance of send
  • URL hash is not included in record

Today we're excited to release Umami v2.19.0! This will likely be the final release of the v2 series as we prepare for v3. In this release, we are preparing the underlying tables for the v3 migration.

Features
Data export

You can now export data directly from the UI. On the overview page, there is a download button that will get all the stats from the current page.

Additionally, you can download individual stats from different sections and from reports. All data returned is in CSV format.

Event properties chart/table view

You can now view custom event properties as a chart or as a table.

Migrations

This release includes a migration to create a new table for holding revenue data.

If you have any revenue data, you will need to run the migration under scripts/data-migrations/populate-revenue-table.sql.

Fixes
  • Fixed environment variables so they work in Docker at runtime #3412
  • Fixed malformed frameAncestors #3494
  • Added keepalive to tracker fetch #3489
  • Improved performance of send #3469
  • URL hash is not included in record #3445
Updates
  • Language updates: Vietnamese, Arabic
  • Upgraded Next to 15.3.3
  • Upgrade Prisma to 6.7.0
Thanks

@vedantbhavsar26 @sancho1952007 @sufyanfa @eoussama @abcsnoob @basbroek @vicke4 @AlexEscalante @alasjo @Sov3rain @KrakenWagen @querry43 @Nambers @ruchernchong @monyasau

View originalPermalink
How v2.19.0 went
View all

Discussion