Skip to content
CAI
Software that uses CAICheck a score

umami-software/umami

46.4

Weak · 28 September 2026

72.8k

lines of production code

TypeScript

primary language

3

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is a self-hosted web analytics platform that collects and processes visitor data, including page views, events, and session replays, using a hybrid PostgreSQL and ClickHouse database architecture. It provides a comprehensive suite of reporting features such as attribution, funnels, heatmaps, and performance metrics, accessible through a modern React-based dashboard and a generated REST API. The platform also supports team collaboration, role-based access control, and integration with AI assistants via the Model Context Protocol.

How it got here

2020–2025 — Next.js App Router and React Zen migration

137 changes.

The project underwent a comprehensive architectural overhaul, migrating from the legacy Pages Router to the Next.js App Router and replacing the UI framework with the react-zen design system. This period focused on rebuilding the frontend components, state management, and routing structure while simultaneously expanding the backend to support advanced analytics features like session replays, heatmaps, and detailed attribution tracking.

2026 — analytics expansion and security hardening

71 changes.

This period focused on significantly expanding the analytics capabilities by introducing session replays, heatmaps, and detailed attribution and journey tracking, alongside a comprehensive overhaul of the sharing system with white-labeling and granular permissions. Simultaneously, the platform implemented robust two-factor authentication across the application and introduced Model Context Protocol (MCP) support to enable AI-driven analytics access. These features were underpinned by a shift to a generated OpenAPI contract and a new typed API client to ensure type safety and consistent documentation.

Features

Add 2FA setup confirmation API with rate limiting and backup code generation

This change introduces the \/api/2fa/setup/confirm\ endpoint, allowing users to finalize two-factor authentication setup by submitting a TOTP token. The implementation includes security hardening with rate limiting (returning 429 on too many attempts), OTP replay prevention, and atomic database transactions to enable the 2FA account and generate backup codes. It also handles configuration errors gracefully (503 if encryption keys are missing) and is disabled in cloud mode. A generated OpenAPI contract and comprehensive unit tests are included to document and verify this behavior.

src/app/api/2fa/setup/confirm · high confidence

Add API endpoints for website annotation management

This change introduces the backend API routes and generated OpenAPI contracts for managing website annotations. Users can now create new annotations (POST /api/websites/{websiteId}/annotations), retrieve paginated and searchable lists of annotations (GET /api/websites/{websiteId}/annotations), and perform individual annotation operations including retrieval, updates, and deletion (routes under /\[annotationId\]). The implementation enforces access control, requiring update permissions for creation/modification and view permissions for retrieval, and includes validation for annotation data such as date and note fields.

src/app/api/websites/\[websiteId\]/annotations · high confidence

Add Podman deployment support with systemd integration

Users can now deploy Umami using Podman via a new set of configuration files in the podman directory. This includes a podman-compose.yml file to orchestrate the application and database containers, an environment sample file (env.sample) that exposes the API\_URL configuration for internal UI calls, and a systemd service unit (umami.service) along with an installation script to enable running the stack as a persistent user service.

podman · high confidence

Add SQL queries for event data analysis and property metrics

New SQL query implementations have been added to the \src/queries/sql/events\ directory to support detailed event data analysis. These queries enable retrieving paginated event data, calculating numeric statistics (sum, average, median, min, max), generating time-series data for arrays, dates, and numeric properties, and providing pivot table views for event properties. The implementation supports both PostgreSQL (via Prisma) and ClickHouse backends, allowing users to filter and analyze event properties by type (string, number, date, array, boolean) and view aggregated metrics across websites.

src/queries/sql/events · high confidence

Add account API key management

Users can now create, view, and delete API keys from the Settings \> API keys page. The new interface allows creating a key with a custom name and immediately copying the generated secret, while listing existing keys with their name, prefix, creation date, and last-used timestamp, and providing a confirmation dialog for deletion. This feature is only available in non-cloud modes.

src/app/(main)/settings/api-keys · high confidence

Add click and scroll heatmap reports with mobile-optimized UI

The Heatmaps report page now supports both click and scroll heatmap modes, allowing users to toggle between them via a filter button. The interface includes a search field to filter pages by URL path and a page picker to select specific pages for analysis. The layout is fully responsive, with a mobile-optimized view that uses a modal for page selection and adjusts controls for smaller screens. The feature is gated behind the 'replays' subscription feature in cloud mode, displaying an upgrade prompt if the user's plan does not include it. The UI has been migrated to use the 'react-zen' component library and theme tokens for consistent styling.

src/app/(main)/websites/\[websiteId\]/(reports)/heatmaps · high confidence

Add core two-factor authentication library with TOTP, backup codes, and security controls

Introduces the foundational two-factor authentication logic in src/lib/two-factor, including TOTP generation and verification, secure backup code creation and validation, and AES-256-GCM encryption for storing secrets. The library enforces security best practices by gating functionality when the TWO\_FACTOR\_ENCRYPTION\_KEY is missing or invalid, implementing rate limiting for failed attempts, and preventing OTP replay attacks. Comprehensive test coverage is added for all core utility behaviors.

src/lib/two-factor · high confidence

New API endpoints have been added to allow users to view and create shares for both links and pixels. The GET endpoints at \/api/links/\[linkId\]/shares\ and \/api/pixels/\[pixelId\]/shares\ retrieve existing shares with filtering and paging support, while the POST endpoints allow authenticated users to create new shares by providing a name and optional parameters. These changes are accompanied by generated OpenAPI contracts for both endpoints to document the API structure.

src/app/api/links/\[linkId\]/shares, src/app/api/pixels/\[pixelId\]/shares · high confidence

Add two-factor authentication setup, disable, and success modals

Users can now manage two-factor authentication through new modals: the setup modal guides users through scanning a QR code or entering a manual key, verifying the code, and securely displaying backup codes with a download option; the disable modal requires a password and verification code to turn off 2FA; and the success modal confirms activation and ensures backup codes are saved before closing. These components are built using the react-zen UI library and ControlledDialog for consistent state management.

src/components/modals · high confidence

Add two-factor authentication step to the login flow

Users can now complete two-factor authentication during login. A new page at /login/two-factor presents an OTP input field (using the OtpInput component) and an option to switch to a backup code entry. The page validates the code or backup code, handles account lockouts with a timed lock message, and upon success, stores the auth token and redirects the user to their intended destination.

src/app/login/two-factor · high confidence

Add user-facing API key management endpoints

Users can now create, list, and delete their own API keys via the \/api/me/api-keys\ endpoints. Creating a key generates a unique identifier and returns the plaintext value only once, while subsequent requests and storage use hashed versions for security. The list endpoint shows key metadata like name and creation date, and the delete endpoint allows revocation. These features are currently disabled in cloud mode, returning 404 errors when the environment variable \CLOUD\_MODE\ is set.

src/app/api/me/api-keys · high confidence

Add user-facing security settings page for two-factor authentication

A new Security settings page has been added to the application, allowing users to view their two-factor authentication (2FA) status and manage their 2FA configuration. The page displays whether 2FA is active or not configured, and provides controls to enable or disable 2FA via modals, with appropriate disabling of controls when 2FA is required by policy.

src/app/(main)/settings/security · high confidence

Added SQL query implementations for funnels and goals

New SQL query modules have been added for generating funnel analysis and tracking goal conversions. The \getFunnel\ implementation constructs SQL queries with Common Table Expressions (CTEs) to calculate visitor counts, drop-off rates, and remaining users across sequential steps, supporting both exact matches and wildcard patterns (e.g., \/blog/\*\) via \LIKE\ operators. The \getGoal\ implementation provides a query to count distinct sessions matching specific event or path criteria, returning both the goal count and the total session count for the period. Both modules support dual database backends (Prisma/Postgres and Clickhouse) and include comprehensive unit tests verifying SQL generation, parameter binding, and result formatting.

src/queries/sql/funnels, src/queries/sql/goals · high confidence

Added SQL query logic for website journey analysis

Introduced a new SQL query implementation in \src/queries/sql/journeys/getJourney.ts\ that constructs dynamic SQL statements to analyze user event sequences (journeys) across website visits. This component supports configurable step counts, start/end step filtering, and date range constraints, executing the generated queries against either a relational database (via Prisma) or ClickHouse depending on the configured data source.

src/queries/sql/journeys · high confidence

Added SQL retention query implementation for Postgres and ClickHouse

A new SQL query implementation for website retention metrics has been added to the codebase. The file src/queries/sql/retention/getRetention.ts introduces logic to calculate visitor retention cohorts over a 31-day period, supporting both PostgreSQL (via Prisma) and ClickHouse backends. The implementation handles date calculations and timezone adjustments to ensure consistent cohort grouping across different database engines.

src/queries/sql/retention · high confidence

Added a test console for validating tracking events

A new Test Console page is now available at the \/console/\[websiteId\]\ route, gated by the \ENABLE\_TEST\_CONSOLE\ environment variable. This interface allows users to manually trigger and verify various tracking scenarios, including page views, click events with attributes, revenue generation (with multiple currencies), and user identification. It also includes links to simulate navigation and external clicks, and loads the tracking script and session recorder to help validate data collection in real-time.

src/app/(main)/console · high confidence

New custom hooks (useBoard, useLink, usePixel, useShare, useTeam, useUser, useWebsite) have been added to the context module, each providing a convenient way to access their respective React contexts (BoardContext, LinkContext, PixelContext, ShareContext, TeamContext, UserContext, WebsiteContext) from anywhere in the application.

src/components/hooks/context · high confidence

Added executable Umami MCP CLI entry point

A new executable script, umami-mcp.js, has been added to the packages/mcp/bin directory. This file serves as the command-line entry point for the Umami MCP tool, using a Node.js shebang to import and execute the main CLI logic located in the dist folder.

packages/mcp/bin · high confidence

Added logout page with client-side session cleanup

A new logout page has been introduced at /logout that clears the client authentication token and resets the user state in the application store. Upon visiting the page, the client sends a request to the /auth/logout endpoint and then redirects the user to the login page, respecting the configured base path. The page is conditionally rendered and returns null if login is disabled or if the application is running in cloud mode.

src/app/logout · high confidence

Added telemetry endpoint with explicit OpenAPI contract

A new GET /api/scripts/telemetry route has been added to serve a JavaScript snippet that injects a telemetry pixel, respecting environment variables like DISABLE\_TELEMETRY and PRIVATE\_MODE to disable tracking in non-production or private modes. An explicit OpenAPI contract (contract.generated.ts) has been generated for this route, defining the operation details and response schema, ensuring the API documentation accurately reflects this new internal telemetry capability.

src/app/api/scripts · high confidence

Admin API for managing user two-factor authentication

New API routes have been added at \/api/admin/users/{userId}/2fa\ allowing administrators to manage two-factor authentication settings for specific users. The \GET\ endpoint returns whether 2FA is enabled for a user, while the \POST\ endpoint allows an admin to toggle the \twoFactorRequired\ flag on a user account (returning a 503 error if the system-wide 2FA encryption key is missing). The \DELETE\ endpoint resets a user's 2FA state by clearing their configuration, backup codes, OTP usage logs, and rate-limit data in a single transaction. These routes are disabled in cloud mode (returning 404) and require admin authentication. A generated OpenAPI contract and corresponding unit tests for these routes are also included.

src/app/api/admin/users/\[userId\] · high confidence

Admin API routes for enforcing 2FA requirements

New internal API endpoints have been added to allow administrators to enforce two-factor authentication (2FA) globally and per-team. The \POST /api/admin/2fa/global\ route updates the global \twoFactorRequiredGlobal\ setting, while \POST /api/admin/teams/{teamId}/2fa\ updates the \twoFactorRequired\ setting for a specific team. Both routes are restricted to self-hosted environments (returning 404 in cloud mode) and require specific permissions (\canEnforceTwoFactorAuthForEveryone\ or \canEnforceTwoFactorAuthForTeam\). Additionally, if a client attempts to enforce 2FA when the underlying 2FA infrastructure is not configured, the API returns a 503 Service Unavailable error. Generated OpenAPI contracts for these operations are also included.

src/app/api/admin/2fa, src/app/api/admin/teams/\[teamId\] · high confidence

Admin users endpoint now supports sorting and pagination

The admin users API endpoint now exposes query parameters for pagination (page, pageSize, maxResults), search, and sorting (orderBy, sortDescending). This allows administrators to efficiently browse and filter user lists, with results including user details and associated website counts.

src/app/api/admin/users · high confidence

Backend support for click and scroll heatmap data ingestion and querying

The system now captures and stores user interaction data for heatmaps, specifically click coordinates and scroll depth percentages, extracted from rrweb replay snapshots. This change introduces SQL query handlers that process these events from both relational and ClickHouse databases, allowing the frontend to retrieve aggregated click points, scroll buckets, and associated page metadata (such as viewport dimensions and URL paths) for visualization.

src/queries/sql/heatmap · high confidence

Board cloning capability added

Users can now clone existing boards via a new POST /api/boards/{boardId}/clone endpoint. The operation requires update permission on the source board and creation permissions for the target context (team website or personal website). It copies the board's name, description, and parameters, while enforcing validation on embedded reports and ensuring the source board is not a dashboard type.

src/app/api/boards/\[boardId\]/clone · high confidence

Board share management API endpoints

Added API routes for managing board shares, allowing users to retrieve a paginated list of shares for a specific board (GET /api/boards/{boardId}/shares) and create new shares with a name and optional parameters (POST /api/boards/{boardId}/shares). The implementation enforces view permissions for listing and update permissions for creating shares, and includes a generated OpenAPI contract for the endpoint.

src/app/api/boards/\[boardId\]/shares · high confidence

Browser tracker now supports distinct visitor identification

The browser tracker in src/tracker has been converted to TypeScript and now supports associating a distinct ID with visitors. This allows the tracker to send an 'identify' event before the initial page view when a distinct ID is provided via the script's data attributes, enabling better user tracking and segmentation.

src/tracker · high confidence

Centralized Prisma data access layer with session replay and annotation support

The application now uses a dedicated \src/queries/prisma\ module to handle all database interactions, replacing previous ad-hoc query patterns. This change introduces structured CRUD operations for core entities including websites, users, teams, links, pixels, boards, reports, segments, and shares. It also adds specific support for website annotations and a new session replay feature, allowing users to view, save, and manage replay chunks. Additionally, the data access layer enforces case-insensitive username lookups for authentication and implements robust cascading deletion logic to ensure dependent data (such as session replays and events) is cleaned up when websites, users, or teams are removed.

src/queries/prisma · high confidence

Dashboard API route and explicit OpenAPI contract

The dashboard API endpoint now exposes explicit GET and POST routes for retrieving and creating or updating a user's dashboard board, including validation of saved report references via \hasValidBoardReports\. An auto-generated OpenAPI contract (\contract.generated.ts\) has been added to formally define the request and response schemas for these operations, ensuring consistent API documentation and type safety.

src/app/api/dashboard · high confidence

Disable 2FA API route enforces environment and requirement checks

The new POST /api/2fa/disable endpoint allows users to turn off two-factor authentication, but it is restricted to non-cloud environments (returning 404 in CLOUD\_MODE) and blocks the action if 2FA is mandated globally, for the specific user, or for any of the user's teams. The route validates the user's password and TOTP token, enforces rate limiting with a 429 response on too many failed attempts, prevents OTP replay, and atomically removes the 2FA configuration and backup codes upon success.

src/app/api/2fa/disable · high confidence

Expanded metrics API now supports sessions, events, and channel breakdowns

The expanded metrics endpoint for websites now returns detailed breakdowns for sessions, events (including custom events), pageviews, and traffic channels. This change introduces new query parameters to filter by specific metric types and applies stricter permission checks, requiring users to have access to the 'overview' or 'compare' website sections to retrieve this data.

src/app/api/websites/\[websiteId\]/metrics/expanded · high confidence

Initial project scaffolding and configuration

This change introduces the foundational configuration files for the Umami project, establishing the build and development environment. It adds a Dockerfile and docker-compose files for containerized deployment and testing, along with a pnpm workspace configuration that includes security overrides for transitive dependencies. The project tooling is standardized with Biome for linting/formatting, TypeScript configuration files for the main app and tracker scripts, and Playwright/Vitest configs for testing. Additionally, it includes a new README, CONTRIBUTING guide, LICENSE, and Netlify/Vercel deployment configs, while removing legacy ESLint, Prettier, and Stylelint configurations.

(repo-wide) · high confidence

Introduce 2FA setup initiation and cancellation API routes

This change adds the backend API endpoints for initiating and cancelling two-factor authentication setup. The new \/api/2fa/setup/initiate\ route allows users to start the 2FA enrollment process by generating a TOTP secret, returning a QR code and manual key, while enforcing checks for missing encryption keys (returning 503) and preventing duplicate setups for already-enabled accounts (returning 400). The \/api/2fa/setup/cancel\ route allows users to abort a pending setup by deleting the stored secret. Both routes are disabled in cloud mode (returning 404) and require bearer authentication. Generated OpenAPI contracts and unit tests for the initiate route are also included.

src/app/api/2fa/setup/initiate · high confidence

Introduce @umami/mcp package for AI analytics via Model Context Protocol

This change adds a new \@umami/mcp\ package that exposes Umami analytics data to AI coding assistants and chatbots through the Model Context Protocol (MCP). The package provides a set of read-only tools—such as \list\_websites\, \get\_website\_stats\, \run\_funnel\, and \get\_performance\—that allow users to query traffic, events, sessions, and Core Web Vitals using natural language. It supports both self-hosted instances (enabled via \MCP\_ENABLED=1\) and Umami Cloud, authenticating via API keys rather than OAuth. The implementation uses the \@umami/api-client\ to ensure all data access respects existing user and team permissions, and it is built to support both ESM and CommonJS environments.

packages/mcp · high confidence

Introduce API endpoints for saving and managing session replays

This change adds new API routes under \/api/websites/\[websiteId\]/replays/saved\ that allow users to list, retrieve, and toggle the saved status of specific session replays. The \GET /saved\ endpoint returns a paginated list of saved replays for a website, while \GET /saved/\[replayId\]\ checks if a specific replay is saved. The \POST /saved/\[replayId\]\ endpoint allows authenticated users with update permissions to save or unsave a replay by setting an \isSaved\ boolean flag and optionally providing a name. These endpoints are backed by generated OpenAPI contracts and enforce access controls based on website view and update permissions.

src/app/api/websites/\[websiteId\]/replays/saved · high confidence

Introduce Umami MCP server with analytics tools and stdio/HTTP transports

This change adds a new Model Context Protocol (MCP) server for Umami, exposing a comprehensive set of read-only analytics tools including website stats, traffic trends, custom event analysis, session details, funnels, goals, and performance metrics. The package provides both a stdio CLI entry point for local agent integration and an HTTP handler for remote connections, utilizing the \@umami/api-client\ for API communication. It includes robust error handling, structured logging, and input validation via Zod schemas, with tools organized into core analytics and higher-level report categories.

packages/mcp/src · high confidence

Introduce automated OpenAPI contract generation and validation

The application now automatically generates a public OpenAPI specification (\public/openapi.json\) for all App Router API handlers. The system infers baseline contracts from route source code and allows developers to provide curated, Zod-backed contracts for precise control over schemas and operation IDs. A new validation layer checks for contract alignment, duplicate operations, and path parameter mismatches, ensuring the generated API client remains stable and accurate. This includes support for explicit operation descriptions, field-level documentation, and audience-based filtering (public, internal, collect).

src/openapi · high confidence

Introduce board management and cloning capabilities

Users can now create, edit, and delete boards via a dedicated list view and dialog forms, and clone existing boards to create copies linked to the same website, pixel, or link. The new BoardProvider manages board state and layout persistence, while the board component registry enables flexible dashboard composition with metrics, charts, and text blocks.

src/app/(main)/boards · high confidence

Introduce rrweb-based session recording with replay and heatmap support

The recorder module now implements session replay and heatmap collection using rrweb. It captures DOM mutations and sends them as structured payloads to the recording API, handling large events by fragmenting them into smaller chunks to respect payload size limits. The feature supports separate enablement flags and sampling rates for replay and heatmaps, with configurable flush intervals and event counts to optimize network usage. Data is masked according to a configurable level (defaulting to 'moderate') and sent via POST requests with keepalive support for background transmission.

src/recorder · high confidence

Introduce website share management API

Added a new API endpoint at \/api/websites/{websiteId}/shares\ that allows users to create named shares for a website and retrieve existing shares. The POST endpoint requires write permissions on the website and accepts a share name and optional parameters, while the GET endpoint requires view permissions and supports filtering and paging. This functionality is backed by a generated OpenAPI contract and Prisma queries for share creation and retrieval.

src/app/api/websites/\[websiteId\]/shares · high confidence

New /api/config endpoint exposes runtime configuration

A new API route at /api/config has been introduced to expose the application's current configuration state to clients. The endpoint returns a JSON object containing boolean flags for cloud mode, private mode, telemetry, and updates, as well as URLs for the favicon, links, and pixels. Notably, the response now includes a sessionDeletionEnabled flag, which is determined by the isRelationalOnly() database check, reflecting the recent addition of session deletion features for relational databases. This change replaces previous server-action-based configuration retrieval with a standard GET API route, making the configuration data accessible via standard HTTP requests.

src/app/api/config · high confidence

New /api/me endpoint exposes user authentication context and API key details

A new GET /api/me route has been added that returns the current authentication context, including the authenticated user's ID, username, role, and administrator status, along with associated API key details and the type of authentication used (session, share, or API key). This endpoint is protected by bearer token authentication and is documented in the generated OpenAPI contract.

src/app/api/me · high confidence

New 2FA status API endpoint with encryption key and cloud-mode safeguards

A new GET /api/2fa/status endpoint has been added to report the current two-factor authentication state (enabled, required, configured, and global requirement). The endpoint now safely handles missing encryption keys by reporting 2FA as not required rather than failing, and it disables 2FA requirements entirely when running in cloud mode. An auto-generated OpenAPI contract and corresponding unit tests for these behaviors are included.

src/app/api/2fa/status · high confidence

New 2FA verification API endpoint with hardened security and explicit contracts

The \/api/2fa/verify\ route is now available, allowing users to complete two-factor authentication using either a TOTP token or a backup code. This endpoint enforces stricter security by rejecting partial tokens, binding the resulting session token to the user's current password hash (invalidating it on password change), and preventing OTP replay. It also includes rate limiting for failed attempts and returns explicit error codes for better client-side handling. An explicit OpenAPI contract has been generated for this route to standardize the API interface.

src/app/api/2fa/verify · high confidence

New API endpoint for retrieving website chart data

A new GET /api/websites/charts endpoint has been added to allow clients to fetch aggregated chart data for multiple websites. The endpoint accepts a comma-separated list of website IDs, optional start and end timestamps, and a timezone parameter (defaulting to UTC). It enforces permission checks to ensure the authenticated user can view the requested websites and returns a JSON object containing the chart values and totals for each site. An explicit OpenAPI contract has also been generated for this route to document the request and response schemas.

src/app/api/websites/charts · high confidence

New API endpoint for retrieving website values and segments

A new GET endpoint at /api/websites/{websiteId}/values has been introduced to fetch specific data values for a website. This endpoint supports querying by type (events, sessions, or segments) and includes parameters for date ranges, timezones, units, and comparison modes (previous period or year-over-year). Access is strictly controlled via bearer token or share link, requiring the user to have view permissions for specific website sections such as overview, events, sessions, or segments. The implementation splits data retrieval between Prisma for segment names and raw SQL for other value types, ensuring efficient data access while maintaining security through section-based permission checks.

src/app/api/websites/\[websiteId\]/values · high confidence

New API endpoint to list website visitor sessions

A new GET /api/websites/{websiteId}/sessions endpoint has been added, allowing users to retrieve a paginated list of visitor sessions for a specific website. The endpoint supports filtering by date range, search terms (matching ID, city, browser, OS, or device), and standard pagination parameters. Access is controlled via bearer token or share link authentication, and enforces section-level permissions to ensure users can only view sessions for website sections they are authorized to access.

src/app/api/websites/\[websiteId\]/sessions · high confidence

New API endpoint to retrieve event data by ID

A new GET endpoint at /api/websites/{websiteId}/event-data/{eventId} has been added, allowing users to fetch specific event data records. The endpoint requires authentication via bearer token or share token and enforces section-level permissions (specifically 'events' view access) before returning the data. The response includes structured fields such as id, createdAt, websiteId, websiteEventId, dataKey, stringValue, numberValue, dateValue, and dataType.

src/app/api/websites/\[websiteId\]/event-data/\[eventId\] · high confidence

New API endpoints for managing and viewing website funnels and goals

This change introduces a complete set of REST API endpoints for creating, reading, updating, and deleting (CRUD) saved funnels and goals, along with dedicated endpoints to retrieve their analytics statistics. Users can now manage funnel and goal definitions via the \/api/websites/{websiteId}/funnels\ and \/api/websites/{websiteId}/goals\ routes, and access detailed performance data (such as visitor counts, drop-off rates, and conversion totals) through the corresponding \/stats\ sub-routes.

src/app/api/websites/\[websiteId\]/goals · high confidence

New API endpoints for managing website segments and cohorts

This change introduces new API routes for creating and retrieving website segments and cohorts. Users can now create segments with specific parameters via a POST request, which includes validation to ensure session property filters are only applied to segments and not cohorts. A GET endpoint allows listing segments and cohorts for a website, supporting filtering and search, with access controlled by website view permissions.

src/app/api/websites/\[websiteId\]/segments · high confidence

Added new GET endpoints at /api/links/charts and /api/pixels/charts that allow clients to retrieve time-series chart data for specific links or pixels. These endpoints accept a comma-separated list of IDs, optional start and end timestamps, and a timezone parameter (defaulting to UTC with a 7-day default range). The responses return structured data containing value arrays and totals for each requested ID, enabling the display of sparklines or charts in the UI. Explicit OpenAPI contracts have been generated for these routes to document the request and response schemas.

src/app/api/links/charts, src/app/api/pixels/charts · high confidence

New API endpoints for website date range and reset operations

This change introduces two new API endpoints for website management: a GET endpoint at \/api/websites/{websiteId}/daterange\ that retrieves the start and end dates for a website's data, and a POST endpoint at \/api/websites/{websiteId}/reset\ to reset website data. The date range endpoint supports both bearer token and share-based authentication, while the reset endpoint requires bearer token authentication and specific update permissions. Both endpoints include generated OpenAPI contracts and utilize new permission checks (\canViewSharedWebsite\ and \canUpdateWebsite\) and query handlers (\getWebsiteDateRange\ from SQL and \resetWebsite\ from Prisma).

src/app/api/websites/\[websiteId\]/daterange · high confidence

New Admin Security page for global 2FA settings

Administrators now have a dedicated Security page in the admin interface to manage global two-factor authentication requirements. This new page allows admins to toggle whether 2FA is required for all users globally, with UI feedback indicating if the feature is not yet configured or if an override note applies.

src/app/(main)/admin/security · high confidence

New Insights breakdown report with customizable columns

A new Insights report page has been added at the breakdown route, allowing users to view website metrics in a tabular format. The report includes standard metrics such as visitors, visits, views, bounce rate, and visit duration, and supports dynamic column selection via a dialog-based field picker that groups available metrics. The page integrates with existing date range controls and provides a download button to export the breakdown data.

src/app/(main)/websites/\[websiteId\]/(reports)/breakdown · high confidence

New Journeys report page with step and event-type filtering

A new Journeys report page is now available at the website reports section, allowing users to visualize visitor paths through a funnel-style interface. The page includes controls to select the number of steps (2–7), filter by start and end steps using a reusable website value combobox, and toggle between viewing all interactions, page views, or specific events. The journey visualization renders nodes for each step with visitor counts and drop-off metrics, supporting selection to highlight specific paths through the funnel.

src/app/(main)/websites/\[websiteId\]/(reports)/journeys · high confidence

New OpenAPI contract and route for listing website events

The events API endpoint now includes a formal OpenAPI contract (contract.ts) defining the GET /api/websites/{websiteId}/events operation, which lists pageviews and custom events with support for filtering by event name, free-text search, and date range. The corresponding route handler (route.ts) implements this endpoint using a standardized request parsing flow, enforcing access control via canViewWebsiteSection for the 'events' section and querying data through the SQL-based getWebsiteEvents function.

src/app/api/websites/\[websiteId\]/events · high confidence

New OpenAPI contract and route for website summary stats

The website stats endpoint now exposes a formal OpenAPI contract (contract.ts) and a new route handler (route.ts) that retrieves summary statistics including pageviews, unique visitors, visits, bounces, and total time on site. The implementation supports comparison periods (previous or year-over-year) and enforces access control via the \canViewWebsiteSection\ permission check for 'overview' and 'compare' sections, ensuring users can only access stats for websites they are authorized to view.

src/app/api/websites/\[websiteId\]/stats · high confidence

New Preferences settings page with configurable date range, language, timezone, and theme

A new Preferences page has been added to the application settings, allowing users to manage their personal preferences. This includes setting a default date range for views, selecting the application language with search support, choosing a timezone from a searchable list, and switching between light and dark themes. The page also displays the current application version as a read-only constant. These settings are persisted locally and provide a centralized location for user-specific configuration.

src/app/(main)/settings/preferences · high confidence

New Retention Report page for websites

A new Retention report has been added to the website analytics section, accessible via the /websites/\[websiteId\]/(reports)/retention route. This page displays a cohort-based retention grid showing visitor retention percentages over configurable day intervals (1, 2, 3, 4, 5, 6, 7, 14, 21, 28 days) for the current month. The implementation uses the new @umami/react-zen UI components for layout and styling, integrates with existing date range hooks to default to the current month, and includes responsive design adjustments for mobile viewing.

src/app/(main)/websites/\[websiteId\]/(reports)/retention · high confidence

New SQL query implementations for analytics metrics and real-time data

This change introduces a suite of new SQL query functions in src/queries/sql to power analytics features, including channel classification (getChannelMetrics, getChannelExpandedMetrics), real-time activity and data aggregation (getRealtimeActivity, getRealtimeData), active visitor counts (getActiveVisitors), and website statistics (getWebsiteStats, getWebsiteListCharts). These queries support both PostgreSQL (via Prisma) and ClickHouse backends, implementing logic for traffic source categorization (e.g., paid, organic, social, search), bounce rate calculation, and real-time visitor tracking. The entry also includes comprehensive test coverage for these new query modules.

src/queries/sql · high confidence

New SQL query implementations for attribution and breakdown analytics

Added new SQL query modules for website-scoped analytics: \getAttribution\ in \src/queries/sql/attribution\ computes traffic source breakdowns (referrers, paid ads, UTM parameters) and totals using first-click or last-click attribution models, while \getBreakdown\ in \src/queries/sql/breakdown\ calculates aggregated metrics (views, visitors, visits, bounces, total time) grouped by specified fields. Both modules support dual database backends (Prisma/PostgreSQL and ClickHouse) via a unified \runQuery\ interface, allowing the application to execute these analytics queries against either database engine depending on configuration.

src/queries/sql/attribution, src/queries/sql/breakdown · high confidence

New SQL query layer for session data and activity analytics

The session analytics module now uses a new set of SQL query functions in \src/queries/sql/sessions\ that support both PostgreSQL (via Prisma) and ClickHouse. This includes creating sessions with conflict handling, retrieving session activity and data, and computing detailed property statistics, time series, and pivot tables. Users will see improved session tracking, more accurate property analysis, and better performance for session-related reports.

src/queries/sql/sessions · high confidence

New SSO authentication endpoint with Redis-backed session management

A new POST /api/auth/sso endpoint has been added to handle Single Sign-On flows. The route validates the request, checks that Redis is enabled, retrieves the user's password hash, and generates a new authentication token valid for 24 hours using the saveAuth utility. A corresponding generated OpenAPI contract (contract.generated.ts) documents this operation, specifying the expected user and token response structure along with standard 401 and 500 error handling.

src/app/api/auth/sso · high confidence

New Sessions page with profile, activity, and property analysis

A dedicated Sessions page has been added under the website navigation, providing a comprehensive view of user sessions. The main list displays key metrics (visitors, visits, views, countries) and a table of sessions with details like location, browser, OS, and device. Clicking a session opens a full-screen modal (or dedicated route) showing a profile with stats, user info (distinct ID, country, device), and three tabs: Activity (chronological list of page views and events with timezone formatting), Properties (filterable charts and pivot tables for session data attributes), and Replays (a table of rrweb-based session replays with an inline player). The profile also includes a delete button for sessions (when enabled and not on a share page) and hides replays on share pages.

src/app/(main)/websites/\[websiteId\]/sessions · high confidence

New Teams Settings page

A new Teams Settings page has been added at the /settings/teams route. It displays a header and a data table for managing teams within a panel layout.

src/app/(main)/settings/teams · high confidence

New UTM Parameters report page

A new UTM Parameters report page has been added under the website reports section. This page displays a breakdown of UTM metrics (source, medium, campaign, etc.) using a combination of list tables and doughnut charts, with responsive layout adjustments for stacked or side-by-side views.

src/app/(main)/websites/\[websiteId\]/(reports)/utm · high confidence

New UTM metrics endpoint for website analytics

A new API endpoint has been added at \/api/websites/{websiteId}/utm/metrics\ to retrieve UTM-based analytics data. This endpoint supports GET requests with query parameters for date ranges and metric types, returning an array of UTM sources and their corresponding view counts. Access is controlled via bearer token or share link authentication, requiring the user to have view permissions for the website's UTM section.

src/app/api/websites/\[websiteId\]/utm · high confidence

New Web Vitals performance report page

A new Performance page has been added to the website reports section, displaying core Web Vitals metrics (LCP, INP, CLS, FCP, TTFB). Users can view summary cards for each metric, select specific percentiles (p50, p75, p95), and view time-series trend charts. The page utilizes the new react-zen UI components and theme tokens for styling.

src/app/(main)/websites/\[websiteId\]/(reports)/performance · high confidence

New Zustand-based application stores for app state, dashboards, and version checks

The application now uses dedicated Zustand stores to manage global state, replacing previous mechanisms. The new \app\ store handles user settings (locale, theme, timezone), date ranges, and share data. A \dashboard\ store manages dashboard layout preferences and persists them to local storage. A \version\ store introduces automatic update checking by comparing the current version against a remote endpoint. Additionally, \websites\ and \cache\ stores provide isolated state management for per-website date ranges and general caching, respectively. Comprehensive test coverage has been added for all new store modules.

src/store · high confidence

New admin section with dedicated layout and navigation

A new admin section has been added, featuring a dedicated layout structure and navigation menu. The layout enforces admin-only access by checking user roles and cloud mode settings, while the navigation provides links to manage users, websites, teams, and security settings. This change introduces the foundational UI components for the admin interface, including a sidebar menu and back navigation.

src/app/(main)/admin · high confidence

New admin team settings page

A new admin section for team management has been added at the /admin/teams/\[teamId\] route. This page renders the existing TeamSettings component within a TeamProvider, allowing administrators to access and modify team-specific configurations through a dedicated interface.

src/app/(main)/admin/teams/\[teamId\] · high confidence

New admin user edit page with role, website, and 2FA management

Admins can now edit individual user details, including username, password, and role (view-only, user, or admin), via a new dedicated page at /admin/users/\[userId\]. This page also provides tabs to manage the websites associated with a user and to configure two-factor authentication settings, including enabling/disabling 2FA requirements per user and resetting 2FA for a specific user.

src/app/(main)/admin/users/\[userId\] · high confidence

New admin users management interface

A new Users section has been added to the admin panel, allowing administrators to view, create, and delete user accounts. The interface includes a data table with sortable columns for username, role, associated websites, and creation date, along with action menus to edit or delete specific users. Administrators can add new users via a modal form that enforces role selection and password requirements, and deletion is protected by a confirmation dialog.

src/app/(main)/admin/users · high confidence

New admin website settings page and expanded component library exports

A new admin page for website settings has been added at src/app/(main)/admin/websites/\[websiteId\], which wraps the existing WebsiteSettings component within a WebsiteProvider and Panel for consistent layout. Additionally, the src/index.ts file now exports a wide range of team, website, and common UI components (such as NavMenu, TeamsButton, and various charts), making these available for external consumption or reuse.

src · high confidence

New admin websites management page

A new admin section for managing websites has been added, accessible at /admin/websites. This page displays a sortable and searchable data grid of websites, showing details such as name, domain (with punycode support), owner (linking to team or user profiles), and creation date. Administrators can edit or delete websites directly from the table, with deletion handled via a controlled modal dialog.

src/app/(main)/admin/teams, src/app/(main)/admin/websites · high confidence

New auth verification and subscription endpoints with generated OpenAPI contracts

The application introduces two new API routes: POST /api/auth/verify, which returns the authenticated user's details along with their associated teams by querying the database, and GET /api/auth/subscription, which retrieves subscription status (including pro, business, and unlimited website flags) for the user or a specific team if authorized. Both endpoints are accompanied by generated OpenAPI contract files that document the request/response schemas and authentication requirements (bearer token for verify, bearer-or-share for subscription).

src/app/api/auth/verify · high confidence

New build, validation, and seed-data scripts

The scripts directory now includes a suite of new tooling: \build-geo.js\ downloads and extracts the GeoLite2-City database (supporting custom URLs and direct .mmdb files), \build-prisma-client.js\ bundles the Prisma client with esbuild, and \bump-components.js\ automates version increments for the components package. Validation and generation tools have been added, including \check-db.js\ for database connectivity and version checks, \check-env.js\ for environment variable validation, \check-missing-messages.js\ for i18n integrity, and TypeScript scripts (\generate-openapi.ts\, \check-openapi.ts\, \generate-openapi-contracts.ts\, \generate-api-client.ts\) for OpenAPI contract generation and API client creation. Additionally, \seed-data.ts\ and its supporting distribution modules provide a sample data generator for local development, while \download-country-names.js\ and \download-language-names.js\ fetch locale-specific name lists.

scripts · high confidence

New chart components and annotation markers

The charts area now includes new BarChart, BubbleChart, DistributionBarChart, and PieChart components, all built on a refactored Chart base that supports custom tooltips and annotation markers. Annotation markers are rendered as clickable overlays on the chart canvas, displaying date, label, and a 'view more' action when multiple annotations share a position.

src/components/charts · high confidence

New cohorts management page for segment-based audience grouping

A new dedicated page at /websites/\[websiteId\]/cohorts has been added, allowing users to view, create, edit, and delete cohorts (segments) directly. The interface includes a data table listing existing cohorts with links to their details, alongside buttons to add new cohorts or modify/delete existing ones. The cohort editing form supports defining segment parameters such as action types, date ranges, and complex filters with match logic, providing a centralized location for managing audience definitions.

src/app/(main)/websites/\[websiteId\]/cohorts · high confidence

A new Links page has been added to the main application, replacing the previous inline or table-based view with a dedicated route. This page features a data table that displays link names, slugs, destination URLs, creation dates, and 7-day visitor sparklines. Users can now add, edit, and delete links via dialog-based forms; the edit form supports custom slugs (except in cloud mode) and validates destination URLs. Action buttons for editing and deleting are conditionally shown based on user roles, ensuring view-only users cannot modify links.

src/app/(main)/links · high confidence

New dedicated Websites settings page

A new settings route at /settings/websites has been introduced, displaying a page titled 'Websites' that lists websites for the current team. This page renders a data table of websites scoped to the specific team context, providing a centralized location for website management within the application's settings structure.

src/app/(main)/settings/websites · high confidence

New dedicated page for viewing and saving session replays

Users can now access a dedicated page for individual session replays, which includes a new playback interface and the ability to save specific replays. The new ReplayPlayback component displays the replay alongside session information, while the ReplayPlayer handles the actual playback using rrweb-player with improved mobile layout support and aspect ratio fitting. A new ReplaySaveForm allows users to bookmark replays for later reference, and the UI has been migrated to use react-zen components and theme tokens.

src/app/(main)/websites/\[websiteId\]/replays/\[replayId\] · high confidence

New dedicated website settings page

A new website settings page has been added at the /settings/websites/\[websiteId\] route. This page renders a layout containing a website settings header and the main settings form, wrapped in a WebsiteProvider to manage state. The page title is set to 'Website'.

src/app/(main)/settings/websites/\[websiteId\] · high confidence

New event series API endpoint with explicit OpenAPI contract

A new GET endpoint at /api/websites/{websiteId}/events/series has been added to retrieve event series data. The implementation uses Zod for request validation and integrates with the existing permission system via canViewWebsiteSection to ensure users can only access events for websites they are authorized to view. The endpoint supports filtering by time range (startAt, endAt), unit, timezone, and various event attributes (e.g., os, browser, device, country, referrer, utmSource). An explicit OpenAPI contract (contract.generated.ts) has been generated for this route, defining the operation ID getWebsiteEventSeries and specifying the required and optional parameters for public audience with bearer-or-share authentication.

src/app/api/websites/\[websiteId\]/events/series · high confidence

New event-data pivot API endpoints for series and stats

This location introduces the backend API routes and generated OpenAPI contracts for the event-data pivot feature, enabling users to query aggregated event metrics. The new endpoints include \/event-data-pivot\ for general pivots, plus specific series endpoints for arrays (\array-series\), dates (\date-series\), numeric values (\numeric-series\ and \numeric-stats\), and categorical properties (\property-series\). Each route enforces website-level permissions via \canViewWebsiteSection\ and supports filtering by event name, property name, timezone, unit, and various standard event properties (e.g., path, referrer, OS, browser). The \numeric-series\ endpoint additionally allows users to specify aggregation metrics (sum, avg, count). These changes provide the data-fetching layer that powers the event-data charts and pivot tables in the UI.

src/app/api/websites/\[websiteId\]/event-data-pivot · high confidence

New hooks for API, filtering, and date handling

The application introduces a new set of hooks in src/components/hooks to manage API interactions, URL filtering, and date parameters. useApi provides a standardized interface for HTTP requests with automatic auth and share token headers. useFilters and useFilterParameters parse URL query strings into structured filter objects, supporting column-based filters, session/event property filters, and share-gated restrictions. useDateParameters and useDateRange handle date range logic with timezone awareness, ensuring consistent date formatting and UTC conversion. Additional hooks like useConfig, useLocale, and useNavigation support configuration loading, internationalization, and URL parameter management.

src/components/hooks · high confidence

New icon library added to the application

A new set of React-based SVG icon components has been added to the \src/components/svg\ directory, providing a comprehensive library of visual assets for the UI. This includes icons for navigation and status (Dashboard, Overview, Reports, Settings, Security), user actions (AddUser, Download, Export, Redo, Pushpin), data visualization (BarChart, Gauge, Funnel, Network), and general utilities (Calendar, Clock, Lock, Link, Location). The library is centralized via an \index.ts\ barrel file, making it easy for other parts of the application to import and use these standardized icons consistently.

src/components/svg · high confidence

A new GET route at /q/\[slug\] has been added to handle link tracking. When a user visits a shortened link, the system now looks up the destination URL, optionally using Redis for caching (with a 24-hour TTL) if enabled, falling back to direct Prisma queries otherwise. It captures the referrer from request headers and forwards this event data to the existing /api/send endpoint before redirecting the user to the final destination. This change introduces a new tracking mechanism that supports both cached and non-cached link resolution.

src/app/(collect)/q · high confidence

New paged event-data API with grouped properties

A new GET endpoint at /api/websites/{websiteId}/event-data is now available, allowing users to retrieve website event data with pagination and filtering (by path, referrer, OS, browser, UTM parameters, etc.). The API requires bearer or share-token authentication and enforces section-level permissions. Responses return a paginated list of events where each event object includes an array of its associated properties, rather than individual rows per property.

src/app/api/websites/\[websiteId\]/event-data · high confidence

New pageview metrics and stats queries for Postgres and ClickHouse

Added new SQL query implementations for pageview analytics, including \getPageviewExpandedMetrics\, \getPageviewMetrics\, and \getPageviewStats\. These queries support both Prisma (Postgres) and ClickHouse backends, enabling detailed breakdowns of pageviews by referrer, entry/exit pages, and full paths (including URL query parameters). The implementation includes logic to exclude bounces, handle session joins, and filter by cohorts, with specific optimizations such as skipping bounce/duration calculations for expanded row views. A test suite was added to verify the generated SQL for both database modes.

src/queries/sql/pageviews · high confidence

New profile settings page with password change capability

A new Profile page has been added to the settings section, allowing users to view their username and role. In non-cloud mode, users can now change their password via a dedicated dialog form that enforces an 8-character minimum length and requires confirmation of the new password.

src/app/(main)/settings/profile · high confidence

New recorder configuration endpoint with CORS support

A new API route at /api/websites/{websiteId}/recorder now exposes the current recorder settings for a website, including flags for replay and heatmap enablement, sample rates, mask level, max duration, and block selectors. The endpoint supports CORS (including preflight OPTIONS requests) and caches responses for 60 seconds. A generated OpenAPI contract and corresponding unit tests for the CORS behavior have also been added.

src/app/api/websites/\[websiteId\]/recorder · high confidence

New remote MCP endpoint with API key authentication

A new remote Model Context Protocol (MCP) endpoint is now available at the \/mcp\ route, enabling external clients to interact with Umami via Streamable HTTP. This feature is disabled by default and requires setting the \MCP\_ENABLED\ environment variable to \1\. Access is secured using API key authentication (via bearer tokens) rather than OAuth, and the endpoint acts as a proxy, forwarding requests to the existing internal API handlers without direct database access.

src/app/mcp · high confidence

New segments management page with session property filtering

A new Segments page has been added under the website settings, allowing users to view, create, edit, and delete segments via a data grid and dialog-based forms. This update introduces support for session property filters within segment definitions, enabling more granular audience segmentation based on session-level data.

src/app/(main)/websites/\[websiteId\]/segments · high confidence

New session data pivot API endpoint with strict access controls

A new API endpoint at /api/websites/{websiteId}/session-data-pivot has been added to retrieve aggregated session data, supporting filtering by property name, time range, and various user attributes (e.g., OS, browser, location, UTM parameters). The endpoint enforces strict access control, requiring users to have 'sessions' view permissions for the specific website section, and supports both bearer token and share-token authentication. A generated OpenAPI contract is included to document the interface.

src/app/api/websites/\[websiteId\]/session-data-pivot · high confidence

New session property analysis views with pivot tables and activity charts

Users can now explore specific session properties through dedicated screens that include a pivot table for detailed row-level data and a distribution bar chart visualizing activity metrics (visitors, visits, views, events) by property value. These components support filtering and pagination, allowing for deeper inspection of session attributes directly within the website's session data interface.

src/app/(main)/websites/\[websiteId\]/session-data · high confidence

New session recording and heatmap collection API endpoint

A new POST endpoint at /api/record has been introduced to handle session replay and click heatmap data collection. This endpoint accepts a discriminated union of 'record' (for rrweb-based session replays) and 'heatmap' (for click and scroll events) payloads, enforcing a maximum of 200 events per request and a 1MB payload size limit. It requires a valid session token via the x-umami-cache header and validates that the associated website has the recorder enabled. In cloud mode, access is restricted to business subscriptions, while bot traffic is silently acknowledged with a 'beep' response. The API also includes full CORS support for preflight and POST requests.

src/app/api/record · high confidence

New session replay API endpoint with filtering and access control

A new API endpoint at /api/websites/{websiteId}/replays has been added to retrieve session replays. This endpoint supports comprehensive filtering via query parameters including date ranges, user attributes (OS, browser, device, country, region, city), navigation details (path, referrer, title), and search terms. Access is strictly controlled by website view permissions, ensuring users can only access replays for websites they are authorized to view. The API returns data based on the applied filters and pagination parameters.

src/app/api/websites/\[websiteId\]/replays · high confidence

New session stats API endpoint with explicit OpenAPI contract

A new GET endpoint at /api/websites/{websiteId}/sessions/stats has been added to retrieve session statistics for a specific website. The implementation uses Zod for request validation and enforces access control via the canViewWebsiteSection permission check, ensuring users can only access sessions data for websites they are authorized to view. The endpoint accepts query parameters for filtering by time range (startAt, endAt) and various session attributes (path, referrer, title, query, os, browser, device, country, region, city, tag, hostname, distinctId, language, event, utmSource, utmMedium, utmCampaign, utmContent, utmTerm). An explicit OpenAPI contract (contract.generated.ts) has been generated for this route, documenting the operation as 'getWebsiteSessionStats' under the 'Websites' tag with bearer-or-share authentication. The response returns metrics as a flat object with numeric values.

src/app/api/websites/\[websiteId\]/sessions/stats · high confidence

New session-data API endpoints with generated OpenAPI contracts

The session-data API area now exposes a set of new GET endpoints (array-series, date-series, numeric-series, numeric-stats, properties, property-series, stats, and values) under /api/websites/{websiteId}/session-data. Each endpoint accepts standard time-range and property filters, enforces bearer-or-share authentication, and checks website section permissions before returning data via SQL-backed queries. Alongside the route handlers, explicit OpenAPI contracts have been generated for these endpoints, providing structured API documentation for consumers.

src/app/api/websites/\[websiteId\]/session-data · high confidence

New settings page layout and navigation structure

The settings section now uses a dedicated layout and navigation component. A new SettingsLayout wraps the content, and a SettingsNav component provides a sidebar with links to Preferences, Profile, Teams, Security, and API Keys. The layout is conditionally rendered based on cloud mode, and metadata for the settings pages has been standardized.

src/app/(main)/settings · high confidence

New share creation API endpoint

A new POST /api/share endpoint has been added, allowing authenticated users to create or update a share record for a specific entity. The endpoint requires an entityId, shareType, name, and parameters, while the slug is optional (auto-generated if omitted). It enforces that the user has update permissions on the target entity before persisting the share data via the Prisma layer.

src/app/api/share · high confidence

New structured API endpoints for website performance data

The system now exposes dedicated API endpoints to retrieve specific aspects of website performance analytics. Users can fetch a performance chart via \/performance/chart\, detailed metrics (such as page titles, devices, and browsers) via \/performance/metrics\, and core web vitals statistics (LCP, INP, CLS, FCP, TTFB) via \/performance/stats\. Each endpoint includes defined request schemas and response structures, ensuring consistent data formats for charting, metric breakdowns, and statistical summaries.

src/app/api/websites/\[websiteId\]/performance · high confidence

New team management interface with member and website administration

The team settings page now includes dedicated sections for managing team members and associated websites. Users can edit team details, view and sort member lists, and modify member roles or remove them via inline dialogs. Similarly, websites linked to the team can be viewed in a sortable table with the ability to remove them. Team owners can also delete the entire team, and administrators can enforce two-factor authentication requirements for the team.

src/app/(main)/teams/\[teamId\] · high confidence

New teams management interface with role-based access controls

The teams section has been rebuilt with a new UI that allows users to create, join, and leave teams, as well as manage team members with specific roles (manager, member, view-only). The interface includes a data table for listing teams and forms for adding teams, joining via access code, and inviting members. View-only users can now join teams but cannot create new ones, addressing previous limitations.

src/app/(main)/teams · high confidence

New typed API client with generated operations and dual authentication

The \packages/api-client/src\ package now provides a new \UmamiClient\ that is generated from the OpenAPI specification (\public/openapi.json\) and exposes a method for every API operation. The client supports both Bearer token and API key authentication (sent via the \x-umami-api-key\ header), with API keys also accepted as bearer tokens for self-hosted compatibility. It includes compatibility overloads for legacy positional arguments (e.g., \client.getWebsiteStats(websiteId, params)\) alongside the canonical object-based input, and introduces a \call()\ method to invoke any operation by ID. Error handling is standardized through the \UmamiApiError\ class, which exposes status codes, error codes, and convenience properties like \isUnauthorized\ and \isRateLimited\. The client defaults to the Umami Cloud base URL (\https://api.umami.is/v1\) but allows custom base URLs for self-hosted instances, and supports per-request timeouts and custom fetch implementations.

packages/api-client/src · high confidence

New unified metrics and pageview analytics endpoints

The API now exposes dedicated endpoints for retrieving website analytics data. The new \/api/websites/{websiteId}/metrics\ endpoint allows users to fetch ranked metric rows for various dimensions (such as pages, referrers, countries, browsers, UTM parameters, events, and channels) with support for filtering, searching, and pagination. Additionally, the \/api/websites/{websiteId}/pageviews\ endpoint provides time-series data for pageviews and sessions, including optional comparison periods. Both endpoints enforce strict access controls based on website section permissions (e.g., overview, events, sessions, compare, breakdown, utm, attribution) and support bearer token or share-link authentication.

src/app/api/websites/\[websiteId\]/metrics · high confidence

New user management API endpoints with explicit permissions and OpenAPI contracts

This change introduces a new REST API for managing individual user accounts at \/api/users/{userId}\, supporting GET (retrieve user details), POST (update username, password, or role), and DELETE (remove a user) operations. Access is controlled by explicit permission checks (\canViewUser\, \canUpdateUser\, \canDeleteUser\) enforced via bearer token authentication, with specific business rules such as preventing self-deletion and restricting role/username changes to admins. The POST endpoint now accepts optional fields for username, password, and role, validating them with Zod schemas. Additionally, an auto-generated OpenAPI contract (\contract.generated.ts\) is provided to document these operations and their response schemas for clients.

src/app/api/users/\[userId\] · high confidence

New website analytics API endpoints for attribution, breakdown, heatmaps, and journeys

The API now exposes new GET routes under \/api/websites/{websiteId}\ to retrieve detailed analytics data. Users can fetch attribution data (referrers, paid ads, UTM parameters), page breakdowns (views, visitors, bounces), heatmap interactions (clicks, scrolls, snapshots), and user journey paths. These endpoints are secured via bearer tokens or share links (except heatmaps, which require bearer auth) and return structured JSON responses defined by the new OpenAPI contracts.

(repo-wide) · high confidence

New website comparison page with side-by-side metrics and UTM tracking

A new Compare page is now available for individual websites, allowing users to view current and previous period metrics side-by-side. The page includes a filter bar to switch between various breakdown dimensions (such as path, channel, referrer, and device) and explicitly supports UTM source, medium, campaign, content, and term filters. The layout presents a metrics table for the previous period alongside the current period, highlighting percentage changes between the two.

src/app/(main)/websites/\[websiteId\]/compare · high confidence

New website retention analytics endpoint

A new API endpoint has been added to retrieve website retention metrics. Users can now call GET /api/websites/{websiteId}/retention to receive an array of daily data points including visitor counts, return visitor counts, and retention percentages. The endpoint requires authentication and checks for specific 'retention' view permissions on the website before returning the data.

src/app/api/websites/\[websiteId\]/retention · high confidence

New website settings page with share, replay, and management controls

A new website settings page has been added, consolidating website management into a single interface. Users can now edit website details, view tracking code, and manage session replays and heatmaps (including sample rates, mask levels, and feature gating). The page also introduces a new share feature, allowing users to create, edit, and delete shareable links with customizable navigation sections, filter toggles, and theme settings. Additionally, users can transfer website ownership between teams and users, as well as reset or delete websites.

src/app/(main)/websites/\[websiteId\]/settings · high confidence

New weekly sessions API endpoint with explicit OpenAPI contract

A new GET endpoint at /api/websites/{websiteId}/sessions/weekly has been added to retrieve weekly session data. The route enforces access control via canViewWebsiteSection for 'overview' and 'sessions' sections and accepts query parameters for date ranges (startAt, endAt), timezone, and various filters (path, referrer, os, browser, etc.). An auto-generated OpenAPI contract (contract.generated.ts) defines the operation 'getWebsiteSessionsWeekly' with bearer-or-share authentication, ensuring consistent API documentation and client generation.

src/app/api/websites/\[websiteId\]/sessions/weekly · high confidence

Redesigned metrics components with new UI library and Web Vitals tracking

The metrics section has been rebuilt using the new @umami/react-zen component library, introducing a refreshed visual style and improved responsiveness. This update adds Web Vitals performance tracking (LCP, INP, CLS, FCP, TTFB) with a new PerformanceCard component that displays ratings based on standard thresholds. Existing components like MetricCard, ListTable, and EventsChart have been converted to use the new design system, featuring animated value transitions, custom date range selection via DatePickerForm, and enhanced data visualization. The changes also include a new WorldMap component for geographic data, a WeeklyTraffic heatmap, and improved handling of metric labels and filtering across the dashboard.

src/components/metrics · high confidence

Website annotation management with CRUD operations

Users can now add, edit, and delete annotations for a specific website via a new modal interface. This feature includes a date picker for setting annotation dates, a text area for notes (with a 500-character limit), and the ability to filter annotations by the current date range or view all notes. Annotations can be created, modified, or removed, with changes reflected in the UI and associated chart markers.

src/app/(main)/websites/\[websiteId\]/annotations · high confidence

Website transfer API with explicit OpenAPI contract

The website transfer endpoint now exposes a formal OpenAPI contract (contract.generated.ts) alongside the route implementation. Users can transfer a website to a specific user or team via a POST request, with the API enforcing authorization checks through dedicated permission functions (canTransferWebsiteToUser, canTransferWebsiteToTeam) before updating the website's ownership via Prisma.

src/app/api/websites/\[websiteId\]/transfer · high confidence

Removals

Removal of SQL database schema definitions

The SQL schema file containing table definitions for website, session, pageview, and event has been deleted. This change removes the structural definitions for the application's core data entities, meaning the database tables for tracking websites, user sessions, page views, and custom events are no longer defined in this location.

sql · high confidence

Removal of legacy collect and session API endpoints

The legacy \pages/api/collect.js\ and \pages/api/session.js\ endpoints have been removed. This eliminates the previous implementation that handled pageview collection and session creation/lookup via direct database calls, indicating a shift to a new event handling and session management architecture.

pages/api · high confidence

Removal of legacy database and utility modules

The \lib/db.js\ and \lib/utils.js\ files have been removed from the codebase. This eliminates the previous implementation that managed Prisma client connections (including automatic disconnects) and provided core utility functions for session parsing, device detection, and request handling. Users relying on these internal modules for database queries or request parsing will need to adopt the new refactored architecture.

lib · high confidence

Removed legacy Umami tracking script

The legacy Umami analytics script (scripts/umami/index.js) has been removed. This script previously handled session creation and pageview collection by posting JSON payloads to the Umami API, including screen dimensions, language, and URL details. Its removal indicates a shift away from this specific client-side implementation, likely replaced by a newer or different tracking mechanism.

scripts/umami · high confidence

Security

SSO page now validates redirect URLs before setting auth token

The SSO page now validates the redirect URL before setting the auth token, preventing potential open redirect vulnerabilities. The new SSOPage component checks if the URL starts with a single slash, does not start with double slashes, and does not include a colon to ensure it is a safe relative path. If the URL is unsafe, the user is redirected to the home page instead of proceeding with the authentication flow.

src/app/sso · high confidence

Website export API now sanitizes CSV data against formula injection

The website export endpoint now protects users from CSV formula injection attacks by prefixing cell values starting with formula triggers (such as =, +, -, @, tab, or carriage return) with a single quote before generating the downloadable ZIP archive. This change ensures that exported data for events, pages, referrers, browsers, OS, devices, and countries is safe when opened in spreadsheet applications, while also introducing an explicit OpenAPI contract for the route.

src/app/api/websites/\[websiteId\]/export · high confidence

API

Explicit OpenAPI contract and replay event merging logic for website replays

The API endpoint for retrieving a specific website replay now includes a generated OpenAPI contract (contract.generated.ts) that explicitly defines the GET /api/websites/{websiteId}/replays/{replayId} operation, including its bearer-or-share authentication requirement and response schema (sessionId, events, timestamps, counts). The underlying route implementation (route.ts) has been updated to handle fragmented replay data by fetching chunks, merging them with optional time/chunk/event index filtering, restoring event fragments, and ensuring events are sorted by timestamp before returning the final payload.

src/app/api/websites/\[websiteId\]/replays/\[replayId\] · high confidence

Explicit OpenAPI contract and typed request parsing for user teams endpoint

The /api/users/{userId}/teams endpoint now includes a generated OpenAPI contract (contract.generated.ts) that explicitly documents the GET operation, including pagination (page, pageSize, maxResults), sorting (orderBy, sortDescending), and the expected team data structure. The route implementation (route.ts) has been updated to use a centralized parseRequest method with Zod schemas for paging and sorting parameters, ensuring consistent validation and error handling for API consumers.

src/app/api/users/\[userId\]/teams · high confidence

Explicit OpenAPI contract generation for event-data events endpoint

The event-data events API route now includes a generated OpenAPI contract file (contract.generated.ts) that explicitly defines the GET endpoint's parameters, including required startAt and endAt timestamps, optional event filters, and various metadata filters (path, referrer, os, browser, device, country, region, city, tag, hostname, distinctId, language, and UTM parameters). This change ensures the API documentation accurately reflects the actual request schema and authentication requirements (bearer-or-share) for this specific endpoint, improving developer experience for API consumers.

src/app/api/websites/\[websiteId\]/event-data/events · high confidence

Public API contract and route for listing team boards

The \/api/teams/{teamId}/boards\ endpoint is now exposed with a generated OpenAPI contract (\contract.generated.ts\) and a corresponding route handler (\route.ts\). This allows clients to retrieve a paginated, searchable, and sortable list of boards for a specific team, with access controlled by the \canViewTeam\ permission check. The API supports standard query parameters for pagination, search, and sorting (including order direction), and returns board details such as ID, name, type, and parameters.

src/app/api/teams/\[teamId\]/boards · high confidence

Behavioural changes

Added static assets and removed legacy tracking script

The public directory now includes standard web manifest files (site.webmanifest, browserconfig.xml) and a robots.txt file to support browser integration and search engine indexing. Additionally, the legacy umami.js tracking script has been removed from the public folder, while new data files for world maps (datamaps.world.json) and ISO-3166-2 subdivisions (iso-3166-2.json) have been added to support geographic data display.

public · high confidence

Added team website inclusion and explicit OpenAPI contracts for Me endpoints

The /api/me/websites endpoint now supports an optional includeTeams query parameter, allowing users to retrieve websites associated with teams they manage in addition to their personal sites. Both the /api/me/websites and /api/me/teams routes have been regenerated with explicit OpenAPI contracts, standardizing the API documentation and client generation for these account-related endpoints.

src/app/api/me/websites · high confidence

Admin teams API now supports sorting and pagination

The admin teams endpoint now accepts query parameters for pagination (page, pageSize, maxResults), search, and sorting (orderBy, sortDescending), allowing administrators to efficiently browse and filter teams. The response includes team details along with counts for active websites and members, and requires internal audience authentication with bearer or share token.

src/app/api/admin/teams · high confidence

Admin websites endpoint now supports sorting and explicit OpenAPI contracts

The admin websites API route has been updated to support sorting via query parameters (orderBy, sortDescending) in addition to existing pagination and search capabilities, allowing administrators to order website lists. This change also introduces a generated OpenAPI contract file that explicitly documents the endpoint's schema, parameters, and response structure, replacing any previous implicit or autogenerated descriptions.

src/app/api/admin/websites · high confidence

Authenticated logout now invalidates the Redis session key

The /api/auth/logout endpoint now explicitly deletes the authenticated session key from Redis upon successful logout, ensuring the session is properly invalidated on the server side. If authentication fails, the endpoint returns a 401 error and does not attempt to delete any keys. This change is accompanied by a generated OpenAPI contract defining the POST operation and unit tests verifying the Redis deletion behavior.

src/app/api/auth/logout · high confidence

Batch API now returns cache data and enforces a 500-item payload limit

The /api/batch endpoint has been updated to include a 'cache' field in its success response, allowing clients to access cached data from processed items. Additionally, the endpoint now strictly limits request payloads to a maximum of 500 items to prevent excessive processing. The implementation also fixes a previous issue where request recreation failed due to private member access errors by properly cloning headers and body.

src/app/api/batch · high confidence

Boards API now supports explicit type binding and fixes missing description errors

The boards API endpoint now allows creating boards with specific types (website, pixel, link, or mixed) and binding them to external entities via parameters, while also generating explicit OpenAPI contracts for these operations. Additionally, a fix ensures that creating a board without a description no longer returns a 500 error by defaulting the description to an empty string.

src/app/api/boards · high confidence

Centralized icon library and standardized UI label definitions

The component layer now exports all icons from the \lucide-react\ library via a dedicated \icons.ts\ module, providing a unified source for UI icons. Additionally, a comprehensive \messages.ts\ file has been introduced to centralize and standardize UI text labels (such as actions, roles, and navigation items) as string keys, replacing scattered or inconsistent text usage across the application.

src/components · high confidence

Centralized share token handling with permission-based section filtering and auto-redirect

The share feature now uses a new ShareProvider component to manage share token state and enforce access controls. This provider validates the share token, filters available dashboard sections based on the share parameters (allowing only sections where the parameter is true), and automatically redirects users to the first allowed section if only one is permitted and they land on the overview or root path. It also handles cleanup by clearing share data when the component unmounts, ensuring that shared views respect the specific permissions granted by the share link.

src/app/share · high confidence

ClickHouse schema overhaul for attribution, performance, and session replay

The ClickHouse database schema has been significantly restructured to support new analytics capabilities. The \website\_event\ table now includes columns for UTM parameters (source, medium, campaign, content, term) and click IDs (gclid, fbclid, msclid, ttclid, li\_fat\_id, twclid) to enable detailed attribution tracking. Web Vitals performance metrics (LCP, INP, CLS, FCP, TTFB) are now stored directly on events, and the hourly stats view has been updated to exclude performance events from view counts. A new \session\_replay\ table stores replay chunks, while \session\_data\ and \event\_data\_pivot\ tables provide optimized storage and projections for session-level property filtering. Additionally, the schema introduces \heatmap\_event\ for click/scroll data, \session\_link\ for identity stitching, and renames \subdivision1\ to \region\ for clearer geographic reporting.

db/clickhouse/migrations · high confidence

Database schema overhaul with new tracking, security, and collaboration features

The database schema has been significantly expanded to support new product capabilities. Session replay and click heatmaps are now stored in dedicated tables, with performance metrics (LCP, INP, CLS, FCP, TTFB) added to event records. User security is enhanced with two-factor authentication (2FA) tables and API key management. Collaboration features include a redesigned team structure (replacing the previous team-website join table) and new shareable links. Additional tracking includes UTM parameters, marketing click IDs, and website annotations. The schema also introduces segments, revenue tracking, and boards, while normalizing event and session data structures.

prisma/migrations · high confidence

Link and pixel editing interfaces have been moved to their own dedicated routes (\/links/\[linkId\]/edit\ and \/pixels/\[pixelId\]/edit\). These new pages provide a structured layout that separates the main edit form from the share settings, each wrapped in its respective provider context, and include a back-navigation link to the detail view.

src/app/(main)/links/\[linkId\]/edit, src/app/(main)/pixels/\[pixelId\]/edit · high confidence

Docker proxy now handles request routing and security headers via Next.js middleware

The Docker deployment now uses a new Next.js middleware (proxy.ts) to manage incoming requests instead of a static configuration. This middleware dynamically rewrites paths for the tracker script, recorder, and API collection endpoints based on environment variables (such as COLLECT\_API\_ENDPOINT and TRACKER\_SCRIPT\_NAME), allows disabling the login page via DISABLE\_LOGIN, and applies Content Security Policy headers at runtime to support dynamic ALLOWED\_FRAME\_URLS. It also sets CORS headers for API requests and cache headers for static scripts.

docker · high confidence

Creating or updating pixels and links now requires slugs to be at least 8 characters long. This validation is enforced in the API routes for both resources, ensuring consistency between creation and editing, and is supported by new unit tests that verify the schema rejects shorter slugs.

src/app/api/pixels · high confidence

Enforced team role hierarchy for user updates and removals

The team user management API now enforces a strict role hierarchy: only users with a higher rank than the target can modify their role or remove them from the team, and team owners are protected from being removed by non-admins (including self-removal) to prevent orphaning the team. This change is implemented in the GET, POST, and DELETE route handlers for the team user endpoint, supported by new permission checks and corresponding unit tests.

src/app/api/teams/\[teamId\]/users/\[userId\] · high confidence

Event stats API now supports period-over-period comparison

The website event statistics endpoint now returns comparison data alongside the primary metrics. By passing a \compare\ query parameter (set to \prev\ for previous period or \yoy\ for year-over-year), users can retrieve a \comparison\ object in the response that contains the same metrics for the calculated prior date range, enabling direct performance analysis without making additional API calls.

src/app/api/websites/\[websiteId\]/events/stats · high confidence

The links API now enforces explicit OpenAPI contracts and granular permission checks for viewing, updating, and deleting links. Users will see standardized error responses (e.g., 'That slug is already taken' for validation conflicts) instead of raw database errors, and access is strictly controlled via \canViewLink\, \canUpdateLink\, and \canDeleteLink\ checks before any operation proceeds.

src/app/api/links/\[linkId\] · high confidence

Explicit OpenAPI contracts and refactored user creation endpoint

The /api/users endpoint now enforces case-insensitive usernames by lowercasing input before storage and returns explicit OpenAPI contracts (contract.generated.ts) that document the API schema, including required fields (username, password, role) and error responses. The user creation logic has been refactored to use a new parseRequest method for validation, integrates with Prisma queries, and ensures that only authorized users can create new accounts.

src/app/api/users · high confidence

Explicit OpenAPI contracts and refined board update validation

The board API now includes generated OpenAPI contracts (contract.generated.ts) that explicitly define the GET, POST, and DELETE endpoints, including the new 'bearer-or-share' authentication option for viewing boards. Additionally, the board update (POST) logic has been hardened to validate that the board's type and parameters contain accessible entities and valid saved reports before allowing changes, preventing updates that would result in inaccessible or invalid states.

src/app/api/boards/\[boardId\] · high confidence

Explicit OpenAPI contracts and standardized query handling for Teams endpoints

The Teams API endpoints for links and websites now include generated OpenAPI contract files (contract.generated.ts) that explicitly define the API schema, including pagination, search, and sorting parameters. The route handlers have been refactored to use a shared request parsing library (parseRequest) and standardized schema definitions (pagingParams, searchParams, sortingParams), ensuring consistent input validation and query filtering across these endpoints. This change improves API documentation accuracy and enforces uniform query parameter handling for team resources.

src/app/api/teams/\[teamId\]/websites · high confidence

Goals page now uses saved definitions and mobile-friendly UI

The Goals page has been refactored to use the new saved definition routes and the react-zen UI library, resulting in a mobile-friendly interface for creating and editing goals. The edit form now adapts its layout for smaller screens, and the board preview correctly handles disconnected or unavailable goals. Additionally, add and edit buttons are hidden on share pages to prevent unauthorized modifications.

src/app/(main)/websites/\[websiteId\]/(reports)/goals · high confidence

Introduce per-visit session replays with filtering and gating

The Replays page now displays replays organized by individual visits rather than long-lived sessions, allowing users to filter the replay list by minimum duration and view saved replays in a dedicated tab. Access to this feature is gated behind the Business plan in cloud mode, and replays are played back in a modal that adapts to portrait or landscape orientation.

src/app/(main)/websites/\[websiteId\]/replays · high confidence

Legacy report APIs routed through compatibility handlers

New compatibility route handlers have been added under src/app/(compat)/compat/api/reports/ to serve legacy report API requests. These handlers cover report management (create, read, update, delete) and specific report types including attribution, breakdown, funnel, goal, heatmap, journey, performance, retention, revenue, and UTM. A key behavioral change is that the websiteId field is intentionally ignored when updating reports, preventing reports from being relocated to another website. All endpoints enforce existing permission checks and query filters, ensuring legacy clients continue to function while the underlying report logic remains unchanged.

src/app/(compat) · high confidence

MCP server authentication and routing logic

The embedded MCP server now authenticates requests using self-hosted API keys instead of OAuth, enforcing this via the new \authenticateMcpRequest\ function which validates keys and rejects them in Cloud mode. Additionally, the server's internal dispatch table (\MCP\_DISPATCH\_ROUTES\) explicitly defines which API endpoints are accessible to MCP clients, restricting access to specific GET routes for websites, sessions, funnels, goals, segments, annotations, and performance metrics while blocking other methods and paths.

src/lib/mcp · high confidence

Major database schema overhaul and Prisma client migration

The database schema has been completely redesigned, replacing the previous simple event, pageview, and session models with a comprehensive structure supporting users, teams, API keys, heatmaps, session replays, and detailed website analytics. This change introduces new entities such as User, ApiKey, SessionReplay, HeatmapEvent, and Board, along with extensive indexing for performance. Additionally, the Prisma generator has been updated to use the new 'prisma-client' provider with the 'client' engine type, and the database datasource now explicitly sets relationMode to 'prisma'.

prisma · high confidence

Migrate UTM parameters and populate revenue data

This change introduces two new data migrations for the PostgreSQL database. The first migration extracts and normalizes UTM and click-ID parameters (such as fbclid, gclid, utm\_source, etc.) from the url\_query column into dedicated columns on the website\_event table, truncating values to 255 characters. The second migration populates the new revenue table by joining event\_data with website\_event to capture revenue amounts and associated currency information for relevant events.

db/postgresql · high confidence

Migrate input components to react-zen and introduce new filtering controls

The input components in src/components/input have been rewritten to use the @umami/react-zen UI library, replacing previous implementations with new primitives like Select, Dialog, and Tabs. This migration introduces several new controls: ActionSelect, BoardSelect, LinkSelect, and PixelSelect for entity selection; DateFilter and MonthFilter for time-range selection; and a comprehensive FieldFilters and FilterEditForm system for managing complex property, segment, and cohort filters. Additionally, new utility components such as DialogButton, DownloadButton, ExportButton, and MenuButton have been added to support these interactions.

src/components/input · high confidence

Migrate to Next.js App Router and react-zen design system

The application has migrated its frontend architecture to the Next.js App Router, introducing a new root layout (\src/app/layout.tsx\) and providers structure (\src/app/Providers.tsx\) that integrates \@umami/react-zen\ for UI components and styling. This change replaces the previous global CSS and context-based providers with a token-driven design system, updating the root HTML structure to use \next/font/google\ for the Inter font and configuring \next-intl\ for internationalization. The migration also includes a new 404 page (\src/app/not-found.tsx\) using Zen components, a root page (\src/app/page.tsx\) that handles team-based routing via \router.replace\, and global style adjustments in \src/app/global.css\ to support the new theme tokens, autofill fixes, and mobile-friendly session replay controls.

src/app · high confidence

Migrated common UI components to react-zen and introduced new layout primitives

The shared component library in src/components/common has been rebuilt using the react-zen design system, replacing previous implementations with standardized primitives like Column, Row, and Grid. This migration introduces new layout and utility components including DataGrid (supporting table and card views), Panel (with fullscreen toggle), NavMenu, and Badge, while updating core elements such as Link (with cloud-mode prefetch defaults), ComboBox, and MultiSelect. Existing functionality is preserved through new wrappers and components like ControlledDialog, FilterRecord, and OtpInput, ensuring consistent styling and behavior across the application.

src/components/common · high confidence

Mobile-friendly event data pivot table with property filtering

The event data view now renders a pivot table that adapts to the device: on mobile it displays rows as cards, while on desktop it uses a horizontal-scrolling table. The table dynamically includes columns for each event property, supports pagination, and allows filtering by specific event properties via URL parameters.

src/app/(main)/websites/\[websiteId\]/event-data · high confidence

New SQL query implementations for revenue analytics and UTM tracking

This change introduces new SQL query files for revenue analytics (charts, metrics, sessions, and stats) and UTM tracking. The revenue queries now filter sessions based on specific criteria before aggregating revenue data, ensuring that only relevant sessions contribute to revenue metrics. The UTM query provides a breakdown of page views by UTM parameters. These changes improve the accuracy and granularity of revenue and marketing attribution analytics.

src/queries/sql/revenue, src/queries/sql/utm · high confidence

New dashboard editing and viewing interface

The dashboard location now features a dedicated edit flow, allowing users to design and save dashboard layouts via a new edit page (/dashboard/edit) with a save/cancel header, while the main view displays the configured board or an empty state. This change introduces new components (DashboardEditHeader, DashboardEditPage, DashboardProvider, DashboardViewHeader, DashboardViewPage) that handle the board context, data fetching, and UI rendering specifically for the dashboard area, replacing the previous implementation.

src/app/(main)/dashboard · high confidence

New dedicated route for team settings

A new page route at /settings/teams/\[teamId\] has been added, serving as the entry point for team-specific configuration. This route renders the TeamSettingsPage component, which wraps the existing TeamSettings UI within a TeamProvider to ensure the necessary team context is available for the settings interface.

src/app/(main)/settings/teams/\[teamId\] · high confidence

New generated API client replaces the legacy hand-written client

The \@umami/api-client\ package has been replaced by a new client generated from the OpenAPI contract, introducing breaking changes to the public API. Instantiation now uses \new UmamiClient()\ with \baseUrl\, \apiKey\, or \token\ options instead of the previous \getClient()\ function. Methods now accept a single configuration object (e.g., \{ websiteId, ...params }\) rather than positional arguments, and error handling has shifted from returning \{ ok, data, status, error }\ objects to throwing \UmamiApiError\ on non-2xx responses. While many methods retain deprecated aliases for backward compatibility, the old \userId\ and \secret\ parameters for client-side token minting have been removed.

packages/api-client · high confidence

New login page with two-factor authentication support and password manager compatibility

The login interface has been rebuilt to support a two-factor authentication flow, redirecting users to a dedicated step when a partial token is received, and includes fixes for password manager autofill by setting correct autocomplete attributes on the username and password fields.

src/app/login · high confidence

New main application layout with responsive navigation and 2FA enforcement

The main application shell has been restructured into a new layout under src/app/(main) using the react-zen UI library. This introduces a responsive design with a collapsible SideNav for desktop and a MobileNav sheet for smaller screens, while the TopNav now includes selectors for teams, websites, links, pixels, and boards. The layout enforces two-factor authentication by blocking interaction with the main content until setup is complete, restricts update notices and telemetry scripts to production environments, and handles team validation by redirecting users if the current team is invalid.

src/app/(main) · high confidence

Password update API now enforces minimum length and explicit validation

The /api/me/password endpoint now strictly requires the new password to be at least 8 characters long, enforced via Zod schema validation in the route handler and reflected in the generated OpenAPI contract. This change ensures that invalid requests are rejected early with a 400 Bad Request error before any database operations occur, improving both security posture and API reliability for users updating their credentials.

src/app/api/me/password · high confidence

Pixel management API with explicit permissions and validation

The pixel API endpoints now enforce explicit permission checks (view, update, delete) before executing database operations, ensuring users can only access or modify pixels they are authorized to manage. The update endpoint validates input fields (name and slug) using Zod schemas and provides specific error handling for unique constraint violations on slugs. Additionally, a generated OpenAPI contract has been added to document the API structure, including request/response schemas and authentication requirements.

src/app/api/pixels/\[pixelId\] · high confidence

Pixel tracking route now supports caching and handles missing pixels

The pixel tracking endpoint at /p/\[slug\] now checks Redis for cached pixel data before querying the database, improving performance for repeated requests. It also properly handles cases where a pixel is not found by returning a 404 response. The route continues to forward request headers to the POST handler and returns a 1x1 GIF image with cache-control headers set to prevent caching.

src/app/(collect)/p · high confidence

Pixels management interface rebuilt with new UI components and sparkline charts

The Pixels page has been completely rewritten to use the new \@umami/react-zen\ component library, replacing the previous implementation. This update introduces a modern data table that includes 7-day visitor sparkline charts for each pixel, alongside sortable columns for name, URL, and creation date. The interface now supports distinct add and delete actions via dialog-based forms, while edit actions navigate to a dedicated page. Access to these actions is correctly restricted for view-only users, and the layout utilizes the new \PageBody\ and \Panel\ wrappers for consistent styling.

src/app/(main)/pixels · high confidence

Real-time dashboard rebuilt with new component architecture

The Real-time analytics page has been completely refactored to use a new modular component structure and the @umami/react-zen UI library. The layout now consists of distinct components for the active users count, metrics bar, real-time chart, activity log, paths, referrers, and countries. The activity log now supports filtering by event type (pageview, session, event) and includes a search field. Links in the paths and referrers sections now render using the hostname instead of the domain. The page also integrates a WorldMap component for geographic visualization and uses a unified loading state pattern across all metrics.

src/app/(main)/websites/\[websiteId\]/realtime · high confidence

Realtime API route refactored with explicit schema validation and SQL-based data retrieval

The realtime endpoint for a specific website has been updated to use a new Zod-based validation schema for query parameters (including timezone, unit, and various filters) and now retrieves data via a dedicated SQL query function instead of the previous implementation. Additionally, an explicit OpenAPI contract file has been generated for this route to document the API interface, ensuring consistent parameter definitions and operation metadata.

src/app/api/realtime · high confidence

Redefined ClickHouse schema for events, session data, and hourly stats

The ClickHouse database schema has been restructured to support new analytics capabilities. The \website\_event\ table now includes \visit\_id\ and \job\_id\ columns, with an updated primary key and order by clause to optimize hourly aggregations. A new \event\_data\ table stores granular event properties (string, number, date) keyed by \data\_key\, while a new \session\_data\ table uses \ReplacingMergeTree\ to store session-level properties with deduplication settings and a materialized projection for efficient property filtering. Additionally, the \website\_event\_stats\_hourly\ table and its associated materialized view have been redefined to aggregate data by hour, utilizing \AggregatingMergeTree\ functions for metrics like views, entry/exit URLs, and UTM parameters.

db/clickhouse · high confidence

Redesigned attribution report with refined filtering and display

The attribution report page has been rebuilt to offer a more structured user experience. Users can now filter results by attribution model (first-click or last-click), type (viewed page or triggered event), and a specific conversion step via a new WebsiteValueComboBox. The report view itself has been updated to display metrics using a standardized list table format with label, count, and percent columns, and the layout has been adjusted for better responsiveness across devices.

src/app/(main)/websites/\[websiteId\]/(reports)/attribution · high confidence

Redesigned board layout editor and view with component-based architecture

The board editing and viewing experience has been rebuilt using a new component-based structure located in the board detail route. The editor now supports a resizable, row-and-column grid layout (BoardEditBody, BoardEditRow, BoardEditColumn) where users can add, remove, and rearrange rows and columns, with each column hosting a configurable board component via a new selector (BoardComponentSelect) and renderer (BoardComponentRenderer). The view mode (BoardViewPage) renders these components in a read-only layout, optionally showing entity badges. Additionally, a new sharing management interface (BoardShareDialog, BoardShareCreateForm, BoardSharesTable) allows users to create and manage board share links with options for filtering and theme enforcement.

src/app/(main)/boards/\[boardId\] · high confidence

Redesigned events page with persistent tabs and property analysis

The events page has been restructured into a tabbed interface featuring three distinct views: a chart view displaying event trends and a top-50 metrics table, an activity view showing a paginated list of individual events with session and location details, and a new properties view for analyzing event attributes. The properties view allows users to select specific events and properties to visualize via charts, supporting string, boolean, number, date, and array data types. The selected tab state is now persisted in local storage, ensuring the user's view preference is maintained across page reloads.

src/app/(main)/websites/\[websiteId\]/events · high confidence

Redesigned funnel creation and reporting interface

The funnels section has been rebuilt to support per-step event data filtering and a mobile-friendly layout. Users can now add specific property filters to individual funnel steps when defining or editing them, and the UI components (such as the funnel overview and edit forms) have been updated to adapt to smaller screens. The interface also includes improved validation and error handling for funnel definitions.

src/app/(main)/websites/\[websiteId\]/(reports)/funnels · high confidence

The link detail view has been restructured into a new layout featuring a dedicated header with edit and view actions, a control bar for filtering and exporting, and a metrics bar displaying visitors, visits, and pageviews. The main content area now includes a chart and organized panels for referrers, channels, environment data, and location metrics, alongside a new interface for managing link shares.

src/app/(main)/links/\[linkId\] · high confidence

Redesigned pixel detail page with new layout and sharing controls

The pixel detail view has been completely restructured into a new layout featuring a dedicated header with edit/view actions, a control bar for filtering and exporting, and a metrics bar displaying visitors, visits, and pageviews. The main content area now presents detailed analytics through tabbed panels for sources (referrers, channels), environment (browsers, OS, devices), and location (world map, countries, regions, cities). Additionally, a new sharing interface allows users to create and manage share links directly from the pixel page.

src/app/(main)/pixels/\[pixelId\] · high confidence

Redesigned share management with theme and filter controls

The share management interface has been rebuilt using the new React Zen component library, introducing a modernized table layout for viewing shared links alongside dedicated forms for creating and editing shares. Users can now configure specific sharing options, including enabling or disabling session property filters and selecting a display theme (such as system, light, or dark) for the shared view. The update also improves the user experience with responsive mobile layouts, inline URL copying, and consistent styling across the share creation and editing workflows.

src/components/share · high confidence

Redesigned website overview with expanded metrics and new navigation

The website overview page has been completely redesigned to feature a new layout structure, including a dedicated header with active user counts, a metrics bar displaying visitors, visits, pageviews, bounce rate, and visit duration, and a main chart panel with annotation support. The interface now includes a new navigation menu (WebsiteNav) and an expanded view modal for detailed metrics breakdowns. Additionally, the controls area has been updated with a new filter bar, date range selector, and export options, while the panels section now organizes metrics into tabs for pages, sources, environment, and location data.

src/app/(main)/websites/\[websiteId\] · high confidence

Refactored analytics send endpoint with explicit OpenAPI contract and Web Vitals support

The /api/send route has been refactored to include a generated OpenAPI contract (contract.generated.ts) that explicitly documents the API schema, and now accepts Web Vitals performance metrics (LCP, INP, CLS, FCP, TTFB) in the payload. The endpoint enforces stricter validation, requiring exactly one of website, link, or pixel identifiers, and introduces a new 'performance' event type alongside existing 'event' and 'identify' types. Session ID generation has been updated to use a distinct ID for identified users, and the route now includes comprehensive unit tests (route.test.ts) covering parsing, validation, and bot-checking logic.

src/app/api/send · high confidence

Refactored event-data API routes to fix event\_name filtering and add explicit OpenAPI contracts

The event-data API endpoints (fields, properties, and values) have been refactored to resolve a parameter collision where the \event\ query string (used for filter expressions like \eq.revenue-demo\) was incorrectly treated as the specific event name. The routes now explicitly accept and pass an \eventName\ parameter to distinguish between filtering by event type and selecting a specific event, ensuring that filter expressions are not misinterpreted as exact event names. Additionally, explicit OpenAPI contracts have been generated for these endpoints to standardize the API documentation and client generation.

src/app/api/websites/\[websiteId\]/event-data/values · high confidence

Refactored login API with 2FA support and team population

The login API route has been rewritten to support a two-step authentication flow: users with 2FA enabled receive a short-lived partial token instead of a full session token, and the system now returns a 503 error if 2FA is enabled but the encryption key is missing. Additionally, the login response now includes the user's associated teams, and session tokens are bound to the current password hash to ensure invalidation upon password changes.

src/app/api/auth/login · high confidence

Refactored permissions logic into modular, testable modules

The permission checks for boards, entities, links, pixels, reports, shares, teams, users, and websites have been reorganized into dedicated, isolated modules under src/permissions. This change introduces comprehensive unit tests for all permission functions, ensuring that access control for viewing, updating, and deleting resources is now more robust, explicit, and easier to maintain. Users benefit from more consistent and secure handling of share tokens and team-based access across all product features.

src/permissions · high confidence

Refactored team user management API with explicit OpenAPI contracts

The team user endpoints have been rewritten to use a new request parsing and permission system, introducing explicit OpenAPI contracts for the GET and POST routes. The GET /api/teams/{teamId}/users route now supports pagination, search, and filtering, returning team member details along with associated user profiles, while enforcing view permissions. The POST /api/teams/{teamId}/users route handles adding members with specific roles, enforcing update permissions and preventing duplicate memberships. A generated contract file defines the API schema, including operation IDs, authentication requirements, and response structures for both success and error cases.

src/app/api/teams/\[teamId\]/users · high confidence

Refactored website API routes with OpenAPI contracts and stricter access controls

The website management endpoints have been restructured to use explicit OpenAPI operation contracts (in \contract.ts\ and \active/contract.ts\) and dedicated route handlers. This change introduces stricter, section-based permission checks (e.g., \canViewWebsiteSection\ for active visitors) and integrates share ID management into the website update flow, allowing users to create or clear share links when editing a website's name or domain. The API now also exposes a new endpoint to retrieve the current number of active visitors for a website.

src/app/api/websites/\[websiteId\] · high confidence

Refined access controls and validation for individual website segments

The API endpoints for managing individual website segments now enforce stricter permission checks and input validation. Retrieving a segment requires the user to have view access to shared website filters, while updating a segment now requires explicit update permissions on the website itself. Additionally, the update endpoint validates that session property filters are not applied to cohort-type segments, returning a clear error if this constraint is violated.

src/app/api/websites/\[websiteId\]/segments/\[segmentId\] · high confidence

Refined board share authorization and white-labeling support

The share API endpoint now enforces stricter authorization when sharing boards, filtering website, pixel, and link IDs based on whether the board is owned by a user or a team and verifying individual entity permissions before inclusion in the response. Additionally, the endpoint now retrieves and includes white-label configuration data for the account associated with the shared entity, allowing shared views to reflect custom branding settings.

src/app/api/share/\[slug\] · high confidence

Removal of legacy React-based UI components

The application has removed the previous React-based layout structure, specifically deleting the \Header\, \Footer\, and \Layout\ components. This eliminates the client-side rendering of the site shell, including the page title handling, favicon, Google Fonts import, and the embedded Umami analytics script that were previously managed by the \Layout\ component.

components · high confidence

Removed legacy Bootstrap grid and global style definitions

The \styles/bootstrap-grid.css\ file containing the Bootstrap Grid v4.5.0 layout system has been deleted, removing the framework's container, row, and column CSS classes from the application. Additionally, the \styles/index.css\ file, which previously defined global resets and base typography for the root elements, has been removed, indicating a shift away from these specific global style definitions.

styles · high confidence

Removed legacy pages directory structure

The legacy Next.js pages directory structure has been removed, specifically deleting the custom 404 error page, the main application entry point (\_app.js), and the home page (index.js). This indicates a migration away from the traditional pages router, likely towards an app router or a different rendering architecture, eliminating the previous static page definitions and global layout wrapper.

pages · high confidence

Revenue data is now served via dedicated API endpoints for charts, metrics, sessions, and stats

The revenue screen now fetches data from four new, specialized API routes—\/revenue/chart\, \/revenue/metrics\, \/revenue/sessions\, and \/revenue/stats\—replacing the previous monolithic approach. Each endpoint handles a specific aspect of revenue analytics (time-series charts, breakdown metrics, session lists, and aggregate stats) and enforces section-level access control via \canViewWebsiteSection\. This separation allows for more targeted queries and improved performance, while the generated OpenAPI contracts ensure consistent parameter handling (such as date ranges, currency, and filters) across all revenue data requests.

src/app/api/websites/\[websiteId\]/revenue · high confidence

Revenue report page redesign with new metrics and chart modes

The Revenue report page has been rebuilt to include Average Order Value (AOV) and Average Revenue Per User (ARPU) alongside total revenue and orders, and the revenue chart now supports a cumulative display mode in addition to the standard period view. The page also introduces a default currency setting that persists across sessions, and the metrics tables for sources and locations have been updated to display data with label, count, and percent columns.

src/app/(main)/websites/\[websiteId\]/(reports)/revenue · high confidence

Separate board creation and design flows into distinct routes

The board creation and design experiences are now handled by separate page components. Visiting the board creation URL immediately redirects users to the main boards list, while the board design interface is now accessible via a dedicated /design route within each board's context, allowing for a clearer separation between setting up a board and editing its design.

src/app/(main)/boards/\[boardId\]/design, src/app/(main)/boards/create · high confidence

Session activity now stitches linked sessions for unified activity views

The session activity API endpoint now automatically widens the query scope to include linked sessions when a distinct ID is provided. If a user is identified by a specific distinct ID, the system fetches all sessions associated with that identity and expands the date range to cover the full lifespan of those linked sessions, ensuring that activity history is not truncated at the boundaries of the single requested session. This change improves the continuity of user activity data in the UI by presenting a complete timeline across identity-linked sessions, while keeping the view scoped to the original session when no distinct ID is specified.

src/app/api/websites/\[websiteId\]/sessions/\[sessionId\]/activity · high confidence

Session management API with deletion and identity stitching

The API for individual website sessions now supports deletion (restricted to relational storage backends) and enhanced GET responses that include \canDelete\ flags, \distinctIds\, and \stitchedSessionCount\ to reflect linked identities. A new endpoint retrieves session properties, and explicit OpenAPI contracts are generated for these operations.

src/app/api/websites/\[websiteId\]/sessions/\[sessionId\] · high confidence

Session replays are now scoped to individual visits

The session replay system has been refactored to store and retrieve recordings on a per-visit basis rather than per session. This change improves data quality by ensuring that replay chunks are tied to specific user visits, addressing issues where sessions persisted too long and resulted in low-quality recordings. The SQL query layer in \src/queries/sql/replays\ now supports both relational and ClickHouse backends for fetching replay chunks and summaries, filtering by visit ID, and saving new recording data (which is sent to Kafka when available).

src/app/api/websites/\[websiteId\]/sessions/\[sessionId\]/replays, src/queries/sql/replays · medium confidence

Share API routes now require authentication and enforce entity permissions

The API endpoints for managing individual shares (GET, POST, DELETE) at \/api/share/id/{shareId}\ now strictly require authentication via bearer token and enforce entity-level permissions. The GET endpoint checks \canViewEntity\, POST checks \canUpdateEntity\, and DELETE checks \canDeleteEntity\ before allowing access. Additionally, the POST endpoint now validates that the request body contains a \name\ (max 200 chars), \slug\ (max 100 chars), and \parameters\ object, ensuring shares can be updated with specific metadata. A generated OpenAPI contract (\contract.generated.ts\) has also been added to document these operations.

src/app/api/share/id · high confidence

Share pages now support white-label branding and collapsible navigation

The share page layout has been restructured to include a collapsible sidebar navigation (ShareNav) and a footer (ShareFooter) that display the white-labeled branding—such as custom logos, display names, and domain links—when configured. The navigation menu dynamically filters its sections (traffic, behavior, growth) based on the share parameters, and the layout adapts to mobile with a full-width menu and desktop with a fixed, collapsible sidebar. This change also introduces a new ShareBranding component to handle the visual identity of the shared report.

src/app/share/\[slug\] · high confidence

Standardized analytics query hooks with unified parameter handling

The \src/components/hooks/queries\ directory has been refactored to use a new, standardized \useAnalyticsQuery\ hook for fetching analytics data. This change introduces a consistent pattern for handling date ranges, timezones, and filter parameters across all analytics endpoints (such as attribution, funnels, goals, heatmaps, journeys, performance, and retention). The new hooks automatically serialize these parameters and integrate with the \useModified\ hook to ensure data freshness. Additionally, specific hooks for event and session data properties now support property filtering and distinct event selection, while resource-specific hooks (like boards, links, pixels, and replays) have been updated to use the \usePagedQuery\ hook for consistent pagination and modification tracking.

src/components/hooks/queries · high confidence

Teams API refactored with explicit OpenAPI contracts and cloud mode limits

The Teams API routes have been rewritten to use a new request parsing and permission system, and explicit OpenAPI contracts are now generated for the endpoints. For users in cloud mode, creating a team now enforces a per-plan team limit, preventing creation once the quota is reached. Additionally, team ownership can now be assigned to a specific user during creation, but this is restricted to admin users only. The API also caches team metadata in Redis upon creation in cloud mode to support entitlement checks.

src/app/api/teams · high confidence

Teams API routes now use explicit permission checks and generated OpenAPI contracts

The team management endpoints (GET, POST, DELETE) have been refactored to enforce granular permissions via dedicated checks (canViewTeam, canUpdateTeam, canDeleteTeam) and to expose explicit OpenAPI contracts. The GET endpoint now returns detailed team metadata including twoFactorRequired and accessCode, while POST validates input using Zod and restricts updates to owners or managers. A new generated contract file (contract.generated.ts) documents these operations, ensuring client code and documentation stay in sync with the API schema.

src/app/api/teams/\[teamId\] · high confidence

Teams join endpoint now excludes deleted teams and generates explicit API contracts

The /api/teams/join route has been updated to prevent users from joining teams that have been soft-deleted (where deletedAt is not null), ensuring that join codes for removed teams are effectively invalidated. Additionally, an explicit OpenAPI contract (contract.generated.ts) is now generated for this endpoint, defining the POST operation, its bearer authentication requirement, and the expected request/response schemas for users.

src/app/api/teams/join · high confidence

Unified property data visualization and filtering for sessions and events

The property data components have been refactored to support both session and event data through a shared set of UI components. This introduces a new PropertyFilterBar and PropertyFilterEditForm for managing property filters, alongside dedicated chart components (PropertyChart, PropertyDateChart, PropertyNumericChart) that visualize property data using the updated react-zen UI library. The filtering logic now handles duplicate property names by selecting the dominant data type, and the date charts automatically adjust their time granularity (day, week, month, year) based on the data range.

src/components/property-data · high confidence

Websites API now enforces cloud subscription limits and supports team-scoped creation

The websites API (\/api/websites\) has been updated to enforce website creation limits based on the user's subscription tier when running in cloud mode, returning an error if the limit is reached. Additionally, the POST endpoint now accepts an optional \teamId\ parameter, allowing users to create websites associated with a specific team rather than just their personal account, with appropriate permission checks for team management.

src/app/api/websites · high confidence

Websites API now supports fetching websites from associated teams

The GET /api/users/{userId}/websites endpoint now accepts an includeTeams query parameter. When this parameter is provided, the API returns websites associated with the user's teams in addition to their direct websites, enabling users to view a comprehensive list of websites they have access to through team memberships.

src/app/api/users/\[userId\]/websites · high confidence

Websites list page redesigned with sparklines and punycode support

The Websites list page has been rebuilt using a new DataGrid-based layout. Key improvements include the addition of 7-day visitor sparklines in the table, support for displaying internationalized domain names (punycode decoding), and a refined add-website workflow that shows a tracking code step in cloud mode. The table now supports sorting and respects view-only user permissions by hiding action buttons when appropriate.

src/app/(main)/websites · high confidence

Test coverage

Establishes Vitest test infrastructure and utilities; New API integration test suite with Playwright, Vitest, and coverage tracking; New test coverage for analytics query serialization, schema validation, and API routing.

Dependencies

Introduce API client and MCP server packages; migrate to pnpm

This change introduces two new workspace packages: \@umami/api-client\, a TypeScript client generated from the OpenAPI contract, and \@umami/mcp\, a Model Context Protocol server that depends on the API client. It also migrates the project from Yarn to pnpm, replacing \yarn.lock\ with \pnpm-lock.yaml\ and updating the root \package.json\ to use pnpm-specific scripts and configuration. The migration includes significant dependency updates, such as upgrading Next.js to 16.3.4, React to 19.3.0, and Prisma to 7.10.0, while removing legacy tooling like Husky and lint-staged in favor of Biome.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Score

  • CAI 33 → 46 (+13.1)
  • Rubric changed (rubric-2026.08.15 → rubric-2026.09.16) — scores are not directly comparable.

Lenses

  • Code Health 59 → 73 (+13.8)
  • Architecture 59 (new)
  • Maturity 54 → 63 (+8.8)
  • Readiness 13 → 43 (+30.4)
  • Security 51 → 57 (+5.8)
  • Accessibility 40 (new)
  • Performance 60 (new)

Resolved (71)

  • Critical CVE: [GHSA redacted] (pnpm-lock.yaml)
  • Critical CVE: [GHSA redacted] (pnpm-lock.yaml)
  • Dimension evaluation failed
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (pnpm-lock.yaml)
  • …and 51 more

New (313)

  • (anonymous) (cyclomatic 107) (src/recorder/index.js)
  • (anonymous)::sendReplayEvents (cognitive 21) (src/recorder/index.js)
  • App.App (cognitive 24) (src/app/(main)/App.tsx)
  • App.App (cyclomatic 27) (src/app/(main)/App.tsx)
  • Banned license: ua-parser-js
  • BoardComponentSelect.BoardComponentSelect (cognitive 71) (src/app/(main)/boards/[boardId]/BoardComponentSelect.tsx)
  • BoardComponentSelect.BoardComponentSelect (cyclomatic 78) (src/app/(main)/boards/[boardId]/BoardComponentSelect.tsx)
  • BoardEditBody.BoardEditBody (cognitive 16) (src/app/(main)/boards/[boardId]/BoardEditBody.tsx)
  • BoardEditBody.BoardEditBody (cyclomatic 16) (src/app/(main)/boards/[boardId]/BoardEditBody.tsx)
  • BoardEditColumn.BoardEditColumn (cyclomatic 23) (src/app/(main)/boards/[boardId]/BoardEditColumn.tsx)
  • BoardEditForm.BoardEditForm (cognitive 17) (src/app/(main)/boards/BoardEditForm.tsx)
  • BoardEditForm.BoardEditForm (cyclomatic 16) (src/app/(main)/boards/BoardEditForm.tsx)
  • Boundary-crossing change coupling: SessionActivity.tsx ↔ getSessionActivity.ts (src/app/(main)/websites/[websiteId]/sessions/SessionActivity.tsx)
  • Change coupling clique: useCountryNames.ts, useLanguageNames.ts, useLocale.ts (src/components/hooks/useCountryNames.ts)
  • Change coupling: EventsPage.tsx ↔ SessionsPage.tsx (src/app/(main)/websites/[websiteId]/events/EventsPage.tsx)
  • Change coupling: FilterRecord.tsx ↔ FilterBar.tsx (src/components/common/FilterRecord.tsx)
  • Change coupling: Funnel.tsx ↔ Goal.tsx (src/app/(main)/websites/[websiteId]/(reports)/funnels/Funnel.tsx)
  • Change coupling: TeamMembersDataTable.tsx ↔ TeamWebsitesDataTable.tsx (src/app/(main)/teams/[teamId]/TeamMembersDataTable.tsx)
  • Change coupling: TeamsTable.tsx ↔ WebsitesTable.tsx (src/app/(main)/teams/TeamsTable.tsx)
  • Change coupling: UserSettings.tsx ↔ TeamSettings.tsx (src/app/(main)/admin/users/[userId]/UserSettings.tsx)
  • …and 293 more

Changes since last survey

  • 130 commits — 93 feature/other, 37 fixes

By area

  • src/app — 37 commits
  • (repo) — 32 commits
  • (root) — 15 commits
  • src/components — 13 commits
  • src/lib — 9 commits
  • public/intl — 6 commits
  • src/queries — 4 commits
  • packages/mcp — 3 commits
  • src/openapi — 3 commits
  • tests/api — 3 commits
  • packages/api-client — 2 commits
  • prisma/migrations — 2 commits
  • .github/workflows — 1 commit

Notable commits

  • fix: Fix API client path parameter handling and release version 3.4.0
  • fix: Fix Goal/Funnel wildcard UI bug
  • fix: Fix MCP CLI packaging and update React UI dependencies
  • fix: Fix Postgresql/Clickhouse timezone inconsistencies. Closes #4541. Closes #3810.
  • fix: Fix mobile date filter fullscreen dropdown
  • fix: Fix page selector custom values
  • fix: Merge pull request #4434 from Yashh56/fix/funnel-val
  • fix: Merge pull request #4447 from tomazic89/fix/funnel-null-event-values
  • fix: Merge pull request #4450 from NoiceHax/fix/issue-4443
  • fix: Merge pull request #4451 from NoiceHax/fix/issue-4152
  • fix: Merge pull request #4465 from luca-seemann/fix/otp-mobile-paste
  • fix: Merge pull request #4469 from brantsrasmus/fix/board-create-description
  • fix: Merge pull request #4472 from JoeJoeflyn/fix/hide-sidenav-scrollbar-collapsed
  • fix: Merge pull request #4490 from justadityaraj/fix/page-selector-dev
  • fix: Merge pull request #4496 from justadityaraj/fix/4489-preserve-regex-commas
  • fix: Merge pull request #4502 from nicolas2601/fix/manage-teams-base-path
  • fix: Merge pull request #4533 from MontejoJorge/fix/show-title-full-path-metric-label
  • fix: fix event_name parameter collision. Closes #4461
  • fix: fix funnel step editor crash on null event values
  • fix: fix otp paste not filling all fields on mobile
  • …and 110 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

umami-software/umami was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 28 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit ec0ff50388c264ed8ce46f00967e92f7e71476ae — the exact code this score is about.
  • Scored under rubric-2026.09.16 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-24a00d372a4b.