Last 7 days
1
Features: 0
Changes: 0
Fixes: 1
Deprecations: 0
Privacy-focused web analytics platform with a managed cloud offering.
Latest Umami changelog updates, official release notes, breaking changes, security patches, pricing changes, and developer reactions in one product feed.
Follow this Umami release-notes page to spot useful features, risky migrations, noisy announcements, and source links before they hit your backlog.
Changes.Watch links back to official changelog and release-note sources so summaries stay easy to verify.
Use channels to follow groups of tools around a stack, workflow, or topic.
Rolling windows show how many product updates landed in the last 7, 30, 90, and 365 days, grouped by existing changelog semantics.
1
2
3
11
Hardened two‑factor authentication with stricter API enforcement, expanded 2FA flow coverage and added missing translations
Added TOTP‑based two‑factor authentication with admin enforcement, backup codes, and rate‑limiting
Introduced first‑class Heatmaps reports with click/scroll visualizations and self‑hosted recording support
Introduced Boards for custom dashboards, Session Replay built on rrweb, and Web Vitals performance tracking.
Patch release addressing the latest Next.js security vulnerability
Fixed security vulnerability in Next.js as per the latest advisory
Update Next.js and React to patch the disclosed security vulnerability (CVE)
Patch the identified Next.js CVE affecting v2
Fix critical Next.js RSC vulnerability (CVE‑3829)
Fixed numerous critical bugs including password manager detection, timezone handling, and API data inconsistencies (e.g., null fields in website stats, missing revenue, and broken Geo location tracking).
Updated UI with new navigation, separate report pages, and universal filter sharing via query strings
Add UI data export with CSV download for overview page and individual stats.
Fix incorrect channel metrics caused by missing ReferrerQuery data
Added Attribution report with revenue data, distinct ID session property, and a data‑before‑send hook for payload inspection/modification
Added batch sending via `/api/batch` and payload overrides (custom IP, userAgent, timestamp) for `/api/send`
Fix Create user error (ID 3247)
Added Channels view and grouped referrers view, with option to exclude URL hash via tracker tag attribute
Hotfix for MySQL and ARM users addressing an OpenSSL compatibility issue in Prisma.
Added partial URL matching in funnel reports and enabled text search on city, region, and country names, including localized names.
Added a revenue report and hash‑based routing support, plus redirect to last selected team on login.
Fixed incorrect referrer handling (issue 2765).
Fixed incomplete chart data and date sorting issues
Introduced new Events and Sessions screens with event activity tables, hourly traffic breakdown, and visitor profile pages.
Fix team settings visibility issue
Introduced extensive reporting upgrades: User Journey, Goals, Entry/Exit URLs, Hosts filtering, Comparison Mode, and a collapsible report menu.
Introduce Team Manager role allowing members to edit roles and remove team members.
Fixed tracker saving incorrect path info and corrected chart display for 'Last x' selections.
Fixed error with region filter handling
Added comprehensive visit tracking, partial‑matching filters, a new UTM report, enhanced funnel reports (event mixing, wildcards) and referrer icons, plus an option to exclude query parameters from tracking.
Fixed broken search functionality in MySQL
Restored missing “Transfer website to teams” functionality
Introduced full team collaboration with separate team contexts and a quick-switch dropdown
Added metrics filtering and external link support in pages; improved translations for location and device data
Introduced a new UI for adding websites to teams and updated mobile responsive styling
Added ARM server support and updated Prisma to 5.3.1.
Fixed tracker script name and collect API endpoint issues when running in Docker.
Fixed stats not saving in certain cases
Added navigation arrow buttons on the overview page and a new Filter button; cities now display country flags.
Added Insights and Retention reports with filter capabilities for pageviews and visitor retention data
Fix filters on overview page
Upgraded to Prisma v5.0.0, delivering noticeable database performance gains on serverless platforms like Vercel.
Fix critical security vulnerability in share URL generation
Added navigation menu on website details page and integrated realtime page for quicker access
Added country/region flag icons in the UI
Updated umami.track API: drop the `data` wrapper and allow passing events directly or custom payloads (breaking change).
Fixed multiple Docker-related issues: DB check preventing boot, tracker script name, collect API endpoint, and FORCE SSL.
Added city/region location, clean URLs, page titles, team sharing, and new language support (Sinhala, Khmer, Swiss German).
Fix share token permission and several UI bugs (mobile menu, share URL, calendar display)
Added Croatian language support.
Fixed owner assignment issue for websites (1614)
Resolved error 1603 that prevented editing website content.
Fixed migration issue affecting some PostgreSQL users
Fix rendering issue on share pages
Added a new UI button to query event JSON data with column selection and filters
Moved DB migration script to the build step for Vercel/Netlify and added Clickhouse, Kafka, and Redis support; Docker behavior unchanged.
Introduce new events model: replace type/value columns with single event name and a new event_data table; old events table renamed to event_old, requiring manual migration (breaking change).
Fixed issue where sessions were loaded incorrectly
UTM source data now appears in the More details view
Fixed COLLECT API endpoint requiring build‑time configuration
Added direct‑visit handling, reduced filter options, screen‑size details, and a customizable /api/collect endpoint via COLLECT_API_ENDPOINT.
check db script now automatically applies database changes
Switched to Prisma migrations with a new `check-db` script that validates DB connection and schema before app start, removing the manual database setup step and the required HASH_SALT env var.
Switch to fetch API in tracker script instead of navigator.sendBeacon
URL filter now also filters events
Added new filtering capabilities by browser, OS, device, and country, and allowed multiple tracker names (comma‑separated) in the tracker script name.
Added ability to rename the default admin account and introduced CORS headers for all website endpoints.
Events chart now updates with event type filters and tracker uses navigator.sendBeacon for reliable data transmission; added CSS events tracker param and subdomain filtering in referrers
Added a new mobile navigation menu, mobile‑optimized card layout, and expanded dashboard to show 10 websites at once.
Added new Lithuanian and Urdu language packs and three env vars (REMOVE_TRAILING_SLASH, TRACKER_SCRIPT_NAME, DISABLE_LOGIN) for URL handling, custom tracker name, and login disabling.
Added All‑time date filter, Language section on website details, Owner column in websites table, and current users count on Realtime page
Fix build issues reported in issue #856.
Add Vietnamese language support and new referrer filtering option with CLIENT_IP_HEADER environment variable
Added support for the en‑GB locale.
Add Slovenian language support
Added Korean language support
Added Hungarian language support.
Added Catalan and Arabic language support and updated Chinese, Mongolian, and Farsi translations
Added UI controls: hide/show charts button, system‑based default theme, and CIDR support for IGNORE_IP env var
Added Slovenian and Malay language support (plus Polish and Tamil updates) and new Prisma migrate integration
Added Persian language support
Date and time formats now respect locale settings
Added event‑type filter and count for Unknown metrics
Added Brazilian Portuguese language support
Fixed port check in the start environment script
Added Italian language support.
Add Hebrew language support;
Added Hindi language support.
Added Tamil language support.
Added multi‑device favicon support.
Added Polish language support.
Added a check to disable Umami tracking when "umami.disabled" is present in localStorage
Added Czech language support
Added Traditional Chinese language support.
Add Finnish language support
Add IP address filtering via IGNORE_IP env variable (comma‑delimited list).
Add Indonesian and Ukrainian language support
Added Norwegian Bokmål language with a new language selection menu.
Added Portuguese and Romanian language support
Added localized country names
Added automatic update check notifications for new releases.
Added page filters to display stats for a single page URL
Added dark mode support
Added Danish language support and timezone configuration
Added French and Mongolian language support and extended the date picker to allow single‑day or range selection with a configurable default range.
Add custom date range picker
Added support for English, Chinese, Dutch, German, Russian, and Turkish languages
Added internationalization (i18n) support with English and Chinese locales.
Add support for sending custom events via the global umami variable, enabling richer JavaScript‑driven tracking
Added toast notification support
Added an Events UI in website details with documentation for tracking events.