# Umami: what changed from 2 to 3 - Product: Umami (https://whatsnew.fyi/product/umami) - Vendor: Umami Software - Range: changelog entries numbered after v2.20.2 up to and including v3.3.1, stable releases only - Entries below: 8 releases (newest first) - Resolved: 2 is v2.20.2 and 3 is v3.3.1, the newest stable release of each major we track - Carrying security changes: 5 · CVEs mentioned: 1 · Mentioning breaking changes: 1 · Removing or deprecating something: 1 - Page: https://whatsnew.fyi/product/umami/compare/2...3 What's New is an index, not a publisher: every entry below links to the vendor's own release notes, which are the authoritative source. Entries are labelled where they are hand-curated sample data, pre-releases, or drawn from a secondary source such as a developer blog. Reuse: the summaries, labels and curation here are © What's New. Quote freely with attribution and a link back; wholesale republication of the corpus is not permitted — terms: https://whatsnew.fyi/terms. The vendors' own release notes remain their publishers'. ## What changed (148 changes, grouped by kind) ### Added #### v3.3.1 (2026-08-20) - Add broader coverage for 2FA status, setup, verification, disable, admin, team, and login flows - Add missing 2FA translations and polish Traditional Chinese 2FA copy #### v3.3.0 (2026-08-12) - Two-Factor Authentication (2FA) support with TOTP-based authentication for self-hosted installs - 2FA setup with QR code and manual key entry - Backup codes for account recovery - User security settings page - Team-level 2FA enforcement settings - Admin security settings and 2FA reset for users - Session identity stitching to link identified sessions across devices and visits - Session and event property filtering across data views - Board cloning feature to duplicate and iterate on dashboards - Sparklines display in Website, Link, and Pixel tables for quick visual overview of activity - Tracking code workflow that walks users through installing tracking code when adding a new website - Linked ID displayed in the session profile - Session delete feature for relational databases - Punycode domain support - IRR (Iranian Rial) added to supported currencies - Organic Facebook traffic channel attribution #### v3.2.0 (2026-06-24) - Heatmaps are now available as a first-class website report with click and scroll heatmaps to understand visitor interactions - Snapshot-based heatmap rendering with iframe previews and page path filtering - Screen-width grouping for responsive layouts in heatmaps with depth labels and improved overlay scaling - Self-hosted heatmap recording and storage support - Replay filters for finding sessions faster - Event data filters for booleans, dates, and arrays - Event data charts for arrays, booleans, dates, and numeric values - Session data screens with filtering, pivot tables, and property charts - Cumulative mode for revenue charts - Manual table/card view toggle for DataGrid - Sorting on non-analytics tables, including websites, boards, links, pixels, teams, and admin tables - data-auto-pageview tracker attribute to suppress SPA pageview tracking when auto-pageview is disabled - Share page options for filtering and theme enforcement - Share-token permissions for websites, boards, links, and pixels #### v3.1.0 (2026-04-16) - Create custom dashboards with Boards feature including row/column layout editor, per-component website binding, TextBlock components, board sharing and duplication, and dashboard-wide date range and filter controls - Session Replay feature to watch real user sessions replayed in the browser with configurable masking levels, per-visit recording, filterable replays table, and replay modal with mobile-friendly playback - Web Vitals performance tracking for Core Web Vitals (LCP, INP, CLS, FCP, TTFB) with industry-standard calculations and rating badges - OR logic across filters, segments, and cohorts - Regex operators for filter matching - Multiselect on equals and not-equals operators - UTM filters and fields exposed throughout the app - Exclude bounces toggle with filter-form integration - Per-step event property filters in funnel creation and overview - Wildcard support in the goals report - Custom slug support for Links - Pixel and Link detail pages with sharing - MetricsBar added to the Events page - Event type filter on Journeys - Time unit selector (hour/day/month) - Distinct ID available as a filter and metric dimension - Cache-control headers on GET responses - SKIP_BUILD_GEO environment variable to skip geo database build #### v3.0.0 (2025-11-07) - Add segments as saved sets of filters that can be reused across the application - Add cohorts to track groups of users who share a common event or experience during a specific time period - Introduce links as short URLs for tracking clicks and downloads with dedicated stats pages - Introduce pixels as invisible images for tracking traffic and measuring metrics like email open rates with dedicated stats pages - Add dedicated admin page for admin users to view and manage all users, websites, and teams in the system ### Changed #### v3.3.1 (2026-08-20) - Improve expanded metrics query performance and fix funnel steps containing null event values #### v3.3.0 (2026-08-12) - Simplified bounce definition for SPA websites - Tracker build converted to TypeScript with published type definitions - Session modals use full-height layouts with improved mobile behavior - Same-domain referrers are no longer saved and path-only referrers resolve correctly - Improved Persian (fa-IR) support and Hebrew RTL support #### v3.2.0 (2026-06-24) - Fragmented replay events are normalized for playback - Full rrweb snapshots are handled as separate replay chunks - Replay payloads are chunked and oversized payloads are rejected - Replay events flush on pagehide with a shorter interval - Revenue reports have been split into focused APIs and views for better performance and flexibility - Website selector dropdown limit increased from 10 to 100 #### v3.1.0 (2026-04-16) - Redesigned share page with full mobile support, collapsible sidenav, per-share display options, ability to name share links, choose visible sections, and apply filtered navigation - Migrated from react-intl to next-intl with all 51 locale files translated #### v3.0.2 (2025-12-04) - Next.js updated to 15.5.7 - Prisma updated to 6.19.0 #### v3.0.0 (2025-11-07) - Update UI to be more user-friendly with a new navigation bar and separated reports into individual pages - Apply filters universally throughout the application via query string to allow sharing filtered URLs with teams - Enhance filter form to add and edit multiple filters at once - Update Next to v15.5.3 - Update Prisma to v6.18.0 ### Fixed #### v3.3.1 (2026-08-20) - Preserve the root path when REMOVE_TRAILING_SLASH is enabled and reset tracker visit state when a session drifts - Fix event property filtering so fields and values respect the selected event name - Preserve events without matching session records and stabilize relational event pagination - Preserve zero and false values in website value responses - Improve handling of username conflicts involving deleted users - Preserve menu item actions in admin dropdowns - Fix expanded-menu spacing and realtime search bar styling #### v3.3.0 (2026-08-12) - Rate limiting with 429 responses on repeated failed attempts - Transactional backup code handling to prevent double-use race conditions - Transactional OTP handling in 2FA encryption - Unique session data entries enforced at the database level - Optimized bounce detection queries - recorder.js CORS header support - Minimum 8-character slug enforced on share link create and update #### v3.2.0 (2026-06-24) - Retention report completeness - Dashboard and Board editing in Firefox - Funnel alias issues - Ambiguous query errors - Username login case-insensitivity - Redirect logged-in users away from the login page - Active users indicator realtime link - DataGrid pagination preserving query params - Long URLs in Links table pushing action buttons off-screen - Invalidates authenticated sessions after password changes #### v3.0.2 (2025-12-04) - Time range selection back and forward arrows not jumping with correct steps - Links and Pixels are prefetched on dashboard - Chart legend extends beyond container boundaries when URL is too long, disrupting page layout - User is not able to switch back to My Account after switching to the Team - Reset of website stats is not possible after entries in Revenue table - Team workspace is not selectable after login - Error with long UTM parameters and click IDs - Direct visitors are missing on Channels - Last seen and First seen fields broken - Tests are failing - Revenue sums not showing - Read-only prevents user from joining team - URL theme and lang parameters no longer work for public share links #### v3.0.1 (2025-11-18) - Password managers unable to detect email field on login form - Support local timezone for date period - Event data raw query failure - Website Stats API Call returns null in some fields - Loop when login page not accessed directly - Geo-location tracking (Country) broken in v3.0, showing "Unknown" for majority of visitors - Prevent exporting empty datasets - Events view for "Today" doesn't show all hourly columns - Realtime activity view basically unusable on mobile - No Revenue showing after update to 3.0.0 - Deprecated timezone 'Asia/Saigon' causes PostgreSQL error in Umami - Long links are cut off - Queries fail with Asia/Calcutta timezone causing Postgres 22023 / Prisma P2010 error - Location statistics broken when tracking IPv6 clients - Invalid reference to FROM-clause entry for table "session_data" ### Removed #### v3.0.0 (2025-11-07) - Remove support for MySQL as a database option, only PostgreSQL is now supported ### Security #### v3.3.1 (2026-08-20) - Harden two-factor authentication when TWO_FACTOR_ENCRYPTION_KEY is missing or invalid with safer API enforcement and clearer configuration feedback #### v3.3.0 (2026-08-12) - Server-side validation for website name and domain input - Hardened event data deletion - Hardened report references in boards - Channel metrics literals escaped in queries - Docker runtime image CVE fixes and bundled npm removed #### v3.2.0 (2026-06-24) - Sanitizes sensitive data in logs - Hides internal Prisma and database errors from API responses - Hardens analytics writes and avoids leaking internal server errors to clients - Validates SSO redirect URLs before setting auth tokens - Restricts team owner assignment to admins - Enforces team role hierarchy on user updates and removals - Fixes share token confusion vulnerabilities - Tightens API access checks by website section and share permissions - Sanitizes CSV exports against formula injection - Limits batch API payloads to 500 items - Uses authenticated Redis keys on logout #### v3.0.3 (2025-12-12) - Updated Next.js to address a security vulnerability #### v3.0.2 (2025-12-04) - Address Next.js CVE-2025-66478 critical vulnerability in RSC ## Release notes ### v3.3.1 - Date: 2026-08-20 - Version: v3.3.1 - Original notes: https://github.com/umami-software/umami/releases/tag/v3.3.1 - Permalink: https://whatsnew.fyi/product/umami/releases/v3.3.1 - **security** — Harden two-factor authentication when TWO_FACTOR_ENCRYPTION_KEY is missing or invalid with safer API enforcement and clearer configuration feedback - **fixed** — Preserve the root path when REMOVE_TRAILING_SLASH is enabled and reset tracker visit state when a session drifts - **fixed** — Fix event property filtering so fields and values respect the selected event name - **fixed** — Preserve events without matching session records and stabilize relational event pagination - **changed** — Improve expanded metrics query performance and fix funnel steps containing null event values - **fixed** — Preserve zero and false values in website value responses - **fixed** — Improve handling of username conflicts involving deleted users - **added** — Add broader coverage for 2FA status, setup, verification, disable, admin, team, and login flows - **fixed** — Preserve menu item actions in admin dropdowns - **fixed** — Fix expanded-menu spacing and realtime search bar styling - **added** — Add missing 2FA translations and polish Traditional Chinese 2FA copy Umami `v3.3.1` is a maintenance release focused on safer upgrades, tracking correctness, analytics accuracy, and UI fixes. ##### Updates - Hardened two-factor authentication when **TWO_FACTOR_ENCRYPTION_KEY** is missing or invalid, with safer API enforcement and clearer configuration feedback. #4443 - Preserved the root path when **REMOVE_TRAILING_SLASH** is enabled and reset tracker visit state when a session drifts. #4152 - Fixed event property filtering so fields and values respect the selected event name. #4461 - Preserved events without matching session records and stabilized relational event pagination. #4462 - Improved expanded metrics query performance and fixed funnel steps containing null event values. - Preserved zero and false values in website value responses. - Improved handling of username conflicts involving deleted users. - Added broader coverage for 2FA status, setup, verification, disable, admin, team, and login flows. - Preserved menu item actions in admin dropdowns. #4453 - Fixed expanded-menu spacing and realtime search bar styling. - Added missing 2FA translations and polished Traditional Chinese 2FA copy. ##### Migrations - Added prisma/migrations/24_lowercase_username to normalize usernames from pre-3.2 installations while safely handling conflicts with soft-deleted accounts. ##### Thanks @nrps9909 @tomazic89 @NoiceHax **Full Changelog**: https://github.com/umami-software/umami/compare/v3.3.0...v3.3.1 ### v3.3.0 - Date: 2026-08-12 - Version: v3.3.0 - Original notes: https://github.com/umami-software/umami/releases/tag/v3.3.0 - Permalink: https://whatsnew.fyi/product/umami/releases/v3.3.0 - **added** — Two-Factor Authentication (2FA) support with TOTP-based authentication for self-hosted installs - **added** — 2FA setup with QR code and manual key entry - **added** — Backup codes for account recovery - **added** — User security settings page - **added** — Team-level 2FA enforcement settings - **added** — Admin security settings and 2FA reset for users - **added** — Session identity stitching to link identified sessions across devices and visits - **added** — Session and event property filtering across data views - **added** — Board cloning feature to duplicate and iterate on dashboards - **added** — Sparklines display in Website, Link, and Pixel tables for quick visual overview of activity - **added** — Tracking code workflow that walks users through installing tracking code when adding a new website - **added** — Linked ID displayed in the session profile - **added** — Session delete feature for relational databases - **added** — Punycode domain support - **added** — IRR (Iranian Rial) added to supported currencies - **added** — Organic Facebook traffic channel attribution - **changed** — Simplified bounce definition for SPA websites - **changed** — Tracker build converted to TypeScript with published type definitions - **changed** — Session modals use full-height layouts with improved mobile behavior - **changed** — Same-domain referrers are no longer saved and path-only referrers resolve correctly - **changed** — Improved Persian (fa-IR) support and Hebrew RTL support - **fixed** — Rate limiting with 429 responses on repeated failed attempts - **fixed** — Transactional backup code handling to prevent double-use race conditions - **fixed** — Transactional OTP handling in 2FA encryption - **fixed** — Unique session data entries enforced at the database level - **fixed** — Optimized bounce detection queries - **fixed** — recorder.js CORS header support - **fixed** — Minimum 8-character slug enforced on share link create and update - **security** — Server-side validation for website name and domain input - **security** — Hardened event data deletion - **security** — Hardened report references in boards - **security** — Channel metrics literals escaped in queries - **security** — Docker runtime image CVE fixes and bundled npm removed Umami `v3.3.0` is here with new **Two-Factor Authentication**, session identity stitching, property filtering, board cloning, sparklines, improved bounce detection, and a large set of security, performance, and UI fixes. ##### New features ###### Two-Factor Authentication (2FA) image Umami now supports TOTP-based two-factor authentication for self-hosted installs. - 2FA setup with QR code and manual key entry - Backup codes for account recovery - 2FA step integrated into the login flow - User security settings page - Team-level 2FA enforcement settings - Admin security settings and 2FA reset for users - Rate limiting with `429` responses on repeated failed attempts - Transactional backup code handling to prevent double-use race conditions ###### Session identity stitching image Sessions are now stitched together when a visitor is identified, giving you a complete view of activity across devices and visits. - Identified sessions are linked for post-identify reads - Linked ID displayed in the session profile - Session delete feature for relational databases #2940 - Session modals use full-height layouts with improved mobile behavior ###### Session and event property filtering image Filter your data using session and event properties. #2945 #4008 - Property filters across session and event data views - Unique session data entries enforced at the database level - Duplicate data types resolved using dominant type logic - Performance improvements for session activity queries ###### Board cloning Boards can now be cloned, making it easy to duplicate and iterate on dashboards. ###### Sparklines image Website, Link, and Pixel tables now display sparklines for a quick visual overview of activity. ###### Tracking code workflow Adding a new website now walks you through installing the tracking code. ###### Bounce detection - Simplified bounce definition for SPA websites - Optimized bounce detection queries ###### Tracker and API improvements - Tracker build converted to TypeScript with published type definitions - `recorder.js` CORS header support #4426 - Punycode domain support #2170 - Same-domain referrers are no longer saved and path-only referrers resolve correctly - IRR (Iranian Rial) added to supported currencies - Improved Persian (fa-IR) support and Hebrew RTL support - Organic Facebook traffic channel attribution #4297 - Web app manifest fetched with credentials ##### Security - Server-side validation for website name and domain input - Hardened event data deletion #4435 - Hardened report references in boards - Minimum 8-character slug enforced on share link create/update #4376 - Channel metrics literals escaped in queries - Docker runtime image CVE fixes and bundled npm removed - 2FA encryption key validation and transactional OTP handling ##### Migrations This release includes schema migrations for session linking, 2FA, and session data: - `prisma/migrations/21_add_session_link` - `prisma/migrations/22_add_2fa` - `prisma/migrations/23_update_session_data` Migrations run automatically during the build process. ##### Fixes - Funnel validation #4434 - Revenue query filtering #4286 - Board funnel and goal preview - ComboBox and MultiSelect issues #4355 - Session modal issues on mobile #4358 - Session modals dismiss when clicking outside - Dashboard empty-state Edit label - `formatLongNumber` billions calculation - Custom `CLIENT_IP_HEADER` not parsing `x-forwarded-for` chains - `G _[Truncated at 4000 characters — full notes: https://github.com/umami-software/umami/releases/tag/v3.3.0]_ ### v3.2.0 - Date: 2026-06-24 - Version: v3.2.0 - Original notes: https://github.com/umami-software/umami/releases/tag/v3.2.0 - Permalink: https://whatsnew.fyi/product/umami/releases/v3.2.0 - **added** — Heatmaps are now available as a first-class website report with click and scroll heatmaps to understand visitor interactions - **added** — Snapshot-based heatmap rendering with iframe previews and page path filtering - **added** — Screen-width grouping for responsive layouts in heatmaps with depth labels and improved overlay scaling - **added** — Self-hosted heatmap recording and storage support - **added** — Replay filters for finding sessions faster - **added** — Event data filters for booleans, dates, and arrays - **added** — Event data charts for arrays, booleans, dates, and numeric values - **added** — Session data screens with filtering, pivot tables, and property charts - **added** — Cumulative mode for revenue charts - **added** — Manual table/card view toggle for DataGrid - **added** — Sorting on non-analytics tables, including websites, boards, links, pixels, teams, and admin tables - **added** — data-auto-pageview tracker attribute to suppress SPA pageview tracking when auto-pageview is disabled - **added** — Share page options for filtering and theme enforcement - **added** — Share-token permissions for websites, boards, links, and pixels - **changed** — Fragmented replay events are normalized for playback - **changed** — Full rrweb snapshots are handled as separate replay chunks - **changed** — Replay payloads are chunked and oversized payloads are rejected - **changed** — Replay events flush on pagehide with a shorter interval - **changed** — Revenue reports have been split into focused APIs and views for better performance and flexibility - **changed** — Website selector dropdown limit increased from 10 to 100 - **fixed** — Retention report completeness - **fixed** — Dashboard and Board editing in Firefox - **fixed** — Funnel alias issues - **fixed** — Ambiguous query errors - **fixed** — Username login case-insensitivity - **fixed** — Redirect logged-in users away from the login page - **fixed** — Active users indicator realtime link - **fixed** — DataGrid pagination preserving query params - **fixed** — Long URLs in Links table pushing action buttons off-screen - **fixed** — Invalidates authenticated sessions after password changes - **security** — Sanitizes sensitive data in logs - **security** — Hides internal Prisma and database errors from API responses - **security** — Hardens analytics writes and avoids leaking internal server errors to clients - **security** — Validates SSO redirect URLs before setting auth tokens - **security** — Restricts team owner assignment to admins - **security** — Enforces team role hierarchy on user updates and removals - **security** — Fixes share token confusion vulnerabilities - **security** — Tightens API access checks by website section and share permissions - **security** — Sanitizes CSV exports against formula injection - **security** — Limits batch API payloads to 500 items - **security** — Uses authenticated Redis keys on logout Umami `v3.2.0` is here with new **Heatmaps**, improved properties reporting, better Session Replay controls, revenue report improvements, and a large set of security, performance, and UI fixes. ##### New features ###### Heatmaps image Heatmaps are now available as a first-class website report. Use click and scroll heatmaps to understand where visitors interact with each page, with overlays rendered from captured replay snapshots. - Click and scroll heatmap reports - Snapshot-based rendering with iframe previews - Page path filtering - Screen-width grouping for responsive layouts - Depth labels and improved overlay scaling - Self-hosted heatmap recording and storage support ###### Session Replay improvements Session Replay received a round of reliability, filtering, and playback improvements. - Replay filters for finding sessions faster - Fragmented replay events are normalized for playback - Full rrweb snapshots are handled as separate replay chunks - Replay payloads are chunked and oversized payloads are rejected - Replay events flush on `pagehide` with a shorter interval - Mobile layout and modal styling improvements ###### Event and session property reporting image Property reports now support richer data types and reusable charting across both event data and session data. - Event data filters for booleans, dates, and arrays - Event data charts for arrays, booleans, dates, and numeric values - Session data screens with filtering, pivot tables, and property charts - Property filter UI shared across event and session data - Query optimizations for session property filters ###### Revenue reporting Revenue reports have been split into focused APIs and views for better performance and flexibility. - Cumulative mode for revenue charts - Separate revenue chart, metrics, stats, and session queries - Revenue metrics table and metrics bar - Improved realtime report UI ###### DataGrid and table improvements - Manual table/card view toggle for DataGrid - Sorting on non-analytics tables, including websites, boards, links, pixels, teams, and admin tables - Horizontal scrolling for overflowing tables - Stable event chart colors across date range changes - Hidden events stay hidden when the date range changes ###### Tracker and API improvements - `data-auto-pageview` tracker attribute to suppress SPA pageview tracking when auto-pageview is disabled - Tracker click handling for annotated containers - Graceful handling for invalid `pushState` URLs - URL query values included in pages report display - LLM channel logic - URL pageview metric and expanded metric support - Configurable internal API URL handling ###### Sharing - Share page options for filtering and theme enforcement - Share-token permissions for websites, boards, links, and pixels - Board share entity authorization fixes - Unrestricted access for share tokens without section flags ##### Security - Invalidates authenticated sessions after password changes - Sanitizes sensitive data in logs - Hides internal Prisma and database errors from API responses - Hardens analytics writes and avoids leaking internal server errors to clients - Validates SSO redirect URLs before setting auth tokens - Restricts team owner assignment to admins - Enforces team role hierarchy on user updates and removals - Fixes share token confusion vulnerabilities - Tightens API access checks by website section and share permissions - Sanitizes CSV exports against formula injection - Limits batch API payloads to 500 items - Uses authenticated Redis keys on logout ##### Migrations This release includes schema migrations for Heatmaps and event/sessio _[Truncated at 4000 characters — full notes: https://github.com/umami-software/umami/releases/tag/v3.2.0]_ ### v3.1.0 - Date: 2026-04-16 - Version: v3.1.0 - Original notes: https://github.com/umami-software/umami/releases/tag/v3.1.0 - Permalink: https://whatsnew.fyi/product/umami/releases/v3.1.0 - **added** — Create custom dashboards with Boards feature including row/column layout editor, per-component website binding, TextBlock components, board sharing and duplication, and dashboard-wide date range and filter controls - **added** — Session Replay feature to watch real user sessions replayed in the browser with configurable masking levels, per-visit recording, filterable replays table, and replay modal with mobile-friendly playback - **added** — Web Vitals performance tracking for Core Web Vitals (LCP, INP, CLS, FCP, TTFB) with industry-standard calculations and rating badges - **changed** — Redesigned share page with full mobile support, collapsible sidenav, per-share display options, ability to name share links, choose visible sections, and apply filtered navigation - **added** — OR logic across filters, segments, and cohorts - **added** — Regex operators for filter matching - **added** — Multiselect on equals and not-equals operators - **added** — UTM filters and fields exposed throughout the app - **added** — Exclude bounces toggle with filter-form integration - **added** — Per-step event property filters in funnel creation and overview - **added** — Wildcard support in the goals report - **added** — Custom slug support for Links - **added** — Pixel and Link detail pages with sharing - **added** — MetricsBar added to the Events page - **added** — Event type filter on Journeys - **added** — Time unit selector (hour/day/month) - **added** — Distinct ID available as a filter and metric dimension - **added** — Cache-control headers on GET responses - **added** — SKIP_BUILD_GEO environment variable to skip geo database build - **changed** — Migrated from react-intl to next-intl with all 51 locale files translated Umami `v3.1.0` is here with a ton of new features, including the much-anticipated **Boards** and **Session Replay**. This release also brings Web Vitals performance tracking, a redesigned share page, and hundreds of fixes and improvements. ##### New features ###### Boards image Boards are here! Create your own custom dashboards by composing components on a flexible row/column canvas. Pick from charts, tables, and metric components, bind them to any website, and share the finished board with your team. - Row/column layout editor with resize, reorder, and remove controls - Per-component website binding and live preview - Free-form `TextBlock` components for notes and section headers - Board sharing, duplication, and table-level edit/delete actions - Dashboard-wide date range and filter controls ###### Session Replay image Watch real user sessions replayed in the browser. Session Replay is built on [rrweb](https://www.rrweb.io/) and works alongside your existing tracker. - Configurable masking levels for privacy (defaults to *moderate*) - Per-visit recording so replays stay short and focused - Filterable replays table with event-level filtering - Replay modal with mobile-friendly playback ###### Web Vitals performance tracking image Track Core Web Vitals (LCP, INP, CLS, FCP, TTFB) from your visitors' browsers. The redesigned Performance page shows industry-standard calculations with rating badges for each metric. ###### Redesigned share page image Share pages have a fresh look with full mobile support, a collapsible sidenav, and per-share display options. You can now: - Name each share link - Choose which sections visitors can see (overview, events, etc.) - Apply filtered navigation so visitors only see what you want ###### Filters, segments, and cohorts - **OR logic** across filters, segments, and cohorts - **Regex operators** for more powerful matching - **Multiselect** on equals/not-equals operators - UTM filters and fields exposed throughout the app - **Exclude bounces** toggle with filter-form integration ###### Funnels - Per-step event property filters in both funnel creation and overview - Wildcard support in the goals report ###### Other improvements - Custom slug support for Links - Pixel and Link detail pages with sharing - `MetricsBar` added to the Events page - Event type filter on Journeys - Time unit selector (hour/day/month) - Distinct ID available as a filter and metric dimension - Cache-control headers on `GET` responses - `SKIP_BUILD_GEO` env variable to skip geo DB build - Configurable salt rotation period via env vars - EdgeOne geolocation headers - Version endpoint and settings display - Download for breakdown reports - Pagination limit on event charts, metrics tables, and UTM reports ###### Admin & internationalization - Migrated from `react-intl` to `next-intl` with all 51 locale files translated - Adopted the [`react-zen`](https://zen.umami.is) design system across the app - Consolidated top navigation with embedded selectors for websites, boards, links, and pixels - Team validation and redirect for invalid teams - Team-gated feature resolution via Redis ##### Security - Fixed IDOR vulnerabilities in reports and segments - Blocked share tokens from all editing permissions and API modifications - Restricted `x-umami-client-*` headers to cloud mode - Various dependency vulnerability fixes (tar, ajv, jws, brace-expansion, next) ##### Migrations This release includ _[Truncated at 4000 characters — full notes: https://github.com/umami-software/umami/releases/tag/v3.1.0]_ ### v3.0.3 - Date: 2025-12-12 - Version: v3.0.3 - Original notes: https://github.com/umami-software/umami/releases/tag/v3.0.3 - Permalink: https://whatsnew.fyi/product/umami/releases/v3.0.3 - **security** — Updated Next.js to address a security vulnerability Patch release for the latest Next.js security issue. See https://nextjs.org/blog/security-update-2025-12-11 ### v3.0.2 - Date: 2025-12-04 - Version: v3.0.2 - Original notes: https://github.com/umami-software/umami/releases/tag/v3.0.2 - Permalink: https://whatsnew.fyi/product/umami/releases/v3.0.2 - **security** — Address Next.js CVE-2025-66478 critical vulnerability in RSC - **fixed** — Time range selection back and forward arrows not jumping with correct steps - **fixed** — Links and Pixels are prefetched on dashboard - **fixed** — Chart legend extends beyond container boundaries when URL is too long, disrupting page layout - **fixed** — User is not able to switch back to My Account after switching to the Team - **fixed** — Reset of website stats is not possible after entries in Revenue table - **fixed** — Team workspace is not selectable after login - **fixed** — Error with long UTM parameters and click IDs - **fixed** — Direct visitors are missing on Channels - **fixed** — Last seen and First seen fields broken - **fixed** — Tests are failing - **fixed** — Revenue sums not showing - **fixed** — Read-only prevents user from joining team - **fixed** — URL theme and lang parameters no longer work for public share links - **changed** — Next.js updated to 15.5.7 - **changed** — Prisma updated to 6.19.0 This is a patch release to address the Next.js [CVE](https://nextjs.org/blog/CVE-2025-66478) and fixes many bugs. ##### Fixes - Nextjs/RSC critical vulnerability #3829 - Time range selection back and forward arrows not jumping with correct steps #3828 - Links and Pixels are prefetched on dashboard #3814 - In the chart legend, when the URL is too long, the legend extends beyond the container boundaries, disrupting the page layout. #3813 - User is not able to switch back to My Account after switching to the Team #3802 - Reset of website stats is not possible after entries in Revenue table #3798 - Team workspace is not selectable after login #3796 - Error with long UTM parameters and click IDs #3790 - Direct visitors are missing on Channels (3.0.1) #3789 - "Last seen" - "First seen" fields broken since 3.0.1 #3775 - Tests are failing in 3.0.1 #3773 - Revenue sums not showing in 3.0.1 #3769 - Read-only prevents user from joining team #3764 - Regression: URL theme and lang parameters no longer work for public share links #3754 ##### Updates - Next.js `15.5.7` - Prisma `6.19.0` ##### Thanks @Lokimorty @imsyedabdullah @RaenonX @IndraGunawan ### v3.0.1 - Date: 2025-11-18 - Version: v3.0.1 - Original notes: https://github.com/umami-software/umami/releases/tag/v3.0.1 - Permalink: https://whatsnew.fyi/product/umami/releases/v3.0.1 - **fixed** — Password managers unable to detect email field on login form - **fixed** — Support local timezone for date period - **fixed** — Event data raw query failure - **fixed** — Website Stats API Call returns null in some fields - **fixed** — Loop when login page not accessed directly - **fixed** — Geo-location tracking (Country) broken in v3.0, showing "Unknown" for majority of visitors - **fixed** — Prevent exporting empty datasets - **fixed** — Events view for "Today" doesn't show all hourly columns - **fixed** — Realtime activity view basically unusable on mobile - **fixed** — No Revenue showing after update to 3.0.0 - **fixed** — Deprecated timezone 'Asia/Saigon' causes PostgreSQL error in Umami - **fixed** — Long links are cut off - **fixed** — Queries fail with Asia/Calcutta timezone causing Postgres 22023 / Prisma P2010 error - **fixed** — Location statistics broken when tracking IPv6 clients - **fixed** — Invalid reference to FROM-clause entry for table "session_data" This is a patch release that fixes many bugs. ##### Fixes - Password managers unable to detect email field on login form #3735 - Support local timezone for date period #3733 - Event data raw query failure #3732 - Website Stats API Call returns null in some fields #3712 - Loop when login page not accessed directly #3703 - Geo-location tracking (Country) broken in v3.0, showing "Unknown" for majority of visitors #3701 - UX – Prevent exporting empty datasets #3699 - Events view for "Today" doesn't show all hourly columns #3697 - Realtime activity view basically unusable on mobile #3694 - No Revenue showing after update to 3.0.0 #3692 - Deprecated timezone 'Asia/Saigon' causes PostgreSQL error in Umami (chart shows empty) #3691 - Support local timezone for date period #3733 - Long links are cut off #3680 - Queries fail with Asia/Calcutta timezone → Postgres 22023 / Prisma P2010 (Umami 2.19.0) #3660 - Location statistics broken when tracking IPv6 clients #3616 - Invalid reference to FROM-clause entry for table "session_data" at character 362 #3545 ##### Thanks @Maxime-J @Mintimate @prince0xdev @mathis5711 ### v3.0.0 - Date: 2025-11-07 - Version: v3.0.0 - Original notes: https://github.com/umami-software/umami/releases/tag/v3.0.0 - Permalink: https://whatsnew.fyi/product/umami/releases/v3.0.0 - **changed** — Update UI to be more user-friendly with a new navigation bar and separated reports into individual pages - **changed** — Apply filters universally throughout the application via query string to allow sharing filtered URLs with teams - **changed** — Enhance filter form to add and edit multiple filters at once - **added** — Add segments as saved sets of filters that can be reused across the application - **added** — Add cohorts to track groups of users who share a common event or experience during a specific time period - **added** — Introduce links as short URLs for tracking clicks and downloads with dedicated stats pages - **added** — Introduce pixels as invisible images for tracking traffic and measuring metrics like email open rates with dedicated stats pages - **added** — Add dedicated admin page for admin users to view and manage all users, websites, and teams in the system - **removed** — Remove support for MySQL as a database option, only PostgreSQL is now supported - **changed** — Update Next to v15.5.3 - **changed** — Update Prisma to v6.18.0 We are excited to announce the release of Umami v3! This release comes with a new interface, lots of new features and enhancements and lays the groundwork for the future of the application. Read more about it on our [blog post](https://umami.is/blog/umami-v3). ##### New features and improvements ###### Updated UI We've updated the UI to be more user friendly and help you see all your data at a glance. With the new navigation bar you can quickly see all your website content and even easily switch between websites with the embedded dropdown. Additionally, all the previous reports have been separated out into individual pages for easier access. image ###### Improved filters Filters are now applied universally everywhere in the application via the query string. That means you can copy the URL to share with your team and it will remember what filters were applied. We've also enhanced the filter form so that you can add and edit multiple filters at once. image ###### Segments and cohorts Segments are a set of filters that you can save to use for later. For example, you can create a segment called *Windows users from the United States*, and apply it to your data via the filter form. A cohort is a group of users who share a common event or experience during a specific time period, and are then tracked over time. For example, you can create a cohort called *Users who signed up in November*. You can then analyze retention or behavior over time. Just like segments, cohorts can be applied as a filter parameter. ###### Links and pixels Umami v3 introduces two additional elements you can use for tracking, links and pixels. Links are simply short URLs that redirect to another URL. You can use links to measure how often users are clicking on certain links or as download links to a file to see how many downloads it received. Pixels are invisible images your can embed elsewhere to measure traffic. For example, on external websites where you can't install a website tracker but can post images. You can also embed pixels into your emails to measure open rates, for example in a monthly newsletter to members. Both links and pixels have their own stats pages just like websites. ###### New admin page There is a new dedicated admin page for admin users. You can view and make changes to all the users, websites and teams in the system. image ###### Coming soon One feature that unfortunately didn't make it into this release was Boards. With boards, you would be able to create your own dashboards and components to display your data however you like. We're still hard at work on it and it will be available in the next release. ##### Breaking changes Umami v3 no longer supports MySQL as a database option, only PostgreSQL. If you want to migrate your data over we've written a [guide](https://umami.is/docs/guides/migrate-mysql-postgresql) to help you migrate. ##### Updates - Next `v15.5.3` - Prisma `v6.18.0` ##### Thanks @mdotme @mcnaveen @kronthto @malwarepad @nickcmaynard @andreynering @matiasfacello @halkeye @fauzora @0xflotus @badmike @fnwbr @markkuhar