← Back to all sparks
C

Countly

ANALYTICS
Velocity5.0

Product analytics platform for web and mobile, self-hosted or cloud

Countly is running two release lines on autopilot while quietly hardening its self-hosted core.

product analyticsself-hostedsecurity hardeninglicensingjourneyslts
◆Current state
Countly ships paired patch releases on its 24.05 and 25.03 branches every one to three weeks, and most of them are fixes: data-manager transformations, event keys with special characters, chart tooltips. The substantive work of the last quarter was security: sanitized HTML sinks, scoped event hooks, a slimmer Docker image, and a sandbox swap for custom hook code. New capability is concentrated in the enterprise journey engine and a rebuilt license system.
◆Where it's heading
The product is in a maintenance-and-hardening phase rather than a feature push, with the LTS branch absorbing the security work and enterprise customers getting the few new features. The License v2 entitlements and slot model, plus tracker-side license lifecycle reporting, suggest Countly is tightening how it meters and enforces paid self-hosted installs. Journey engine is the one surface that keeps gaining capability release after release.
◆Prediction
Expect License v2 to reach the LTS branch and further journey-engine additions in the next 25.03.x release; the entries give no signal of a new major line yet.

◆Recent moves

  1. 1d ago

    24.05.54: data-manager merge and logging fixes

    A two-line enterprise patch on the older 24.05 branch fixing event deletion after merges and removing a noisy log. It confirms 24.05 is still maintained, but nothing here changes what users can do.

    View source ↗
  2. 9d ago

    25.03.54: License v2 entitlements and journey charts

    The most substantive release of the quarter: License v2 brings entitlements, slots, renewal and an offline policy, and the tracker gains license lifecycle reporting. Around that sit journey-engine chart improvements and a long list of funnel, formula and dashboard fixes. It points to Countly formalizing how enterprise self-hosted installs are metered.

    View source ↗
  3. 28d ago

    25.03.53-LTS: security patches for sinks, OIDC and surveys

    An LTS backport bundle: HTML-sink sanitization, OIDC session handling, survey parameter filtering, and removal of stored credentials from A/B experiments. Self-hosters should apply it, but it is patch work on an existing surface.

    View source ↗
  4. 28d ago

    24.05.53: tooltip escaping and OIDC security fixes

    The 24.05 counterpart to the same-day LTS patch, carrying the tooltip-escaping, prototype-key and OIDC fixes back to the older branch. It is the dual-branch maintenance pattern at its most routine.

    View source ↗
  5. 1mo ago

    25.03.52-LTS: isolated-vm hook sandbox and slimmer images

    The hardening release with real consequences: Docker images move to multi-stage Debian 13 and Node 24 builds, and hook custom code moves from v8-sandbox to isolated-vm. That swap breaks code relying on timers, async completion or the base64 helpers. The A/B testing stack also drops end-of-life Python 3.8 for compiled Stan models.

    View source ↗
  6. 1mo ago

    24.05.52: fixes for event keys with special characters

    Fixes for event descriptions and duplicate rows when event keys contain special characters, backported to 24.05. Routine branch maintenance.

    View source ↗