← Back to all sparks
Umami logo

Umami

ANALYTICS
Velocity0.0

Open-source, privacy-focused web analytics

Umami spent late 2025 patching Next.js CVEs, then shipped Boards and Session Replay in v3.1.0.

web analyticssession replaydashboardssecurity patchesself-hosted
Current state
The window splits sharply. Four of six releases are December 2025 patches across the v2 and v3 lines, all responding to the same Next.js and React security advisories plus Docker build breakage — several shipped within days of each other because the first fix updated Next.js without the affected React versions. Then v3.1.0 in April 2026 delivered custom dashboards as Boards, Session Replay, Web Vitals performance tracking, a redesigned share page, and a large batch of fixes.
Where it's heading
The security cluster is a framework dependency showing its cost — an analytics tool inheriting its release schedule from Next.js advisories. v3.1.0 is where product work resumes, and its content is telling: Session Replay and Web Vitals move Umami past pageview counting into behaviour and performance, which is the territory occupied by heavier commercial analytics rather than the lightweight privacy-first tools it grew up alongside.
Prediction
Expect the next releases to build on Boards and Session Replay rather than return to the counting core, since both are new surfaces that arrived with a single release and no follow-up yet.

Recent moves

  1. 3mo ago

    v3.1.0: Boards, Session Replay and Web Vitals

    ⚡ SPARK

    Boards and Session Replay in one release take Umami past aggregate counting into per-session behaviour and Core Web Vitals — a different product category from the privacy-first pageview counter it started as.

    View source ↗
  2. 8mo ago

    v3.0.3: Next.js security patch

    A patch release for a Next.js security advisory with no other content. Framework dependency maintenance.

    View source ↗
  3. 8mo ago

    v2.20.2: Next.js security patch for the v2 line

    The same Next.js security patch applied to the v2 line. Parallel maintenance across supported branches.

    View source ↗
  4. 8mo ago

    v2.20.1: React version fix and Docker build repairs

    A follow-up patch updating the affected React versions the previous release missed, plus Docker build fixes. Corrective maintenance on an incomplete security fix.

    View source ↗
  5. 8mo ago

    v2.20.0: Next.js CVE fix for the v2 line

    A release existing solely to address the Next.js CVE on the v2 line. Security maintenance with no product content.

    View source ↗
  6. 8mo ago

    v3.0.2: Next.js RSC vulnerability patch and UI fixes

    A patch addressing the Next.js/RSC vulnerability plus fixes to chart legends, date-range arrows and dashboard prefetching. Security work with incidental bug fixes.

    View source ↗