RepoPilot

umami-software/umami

Umami is a privacy-first analytics platform. Traffic, campaigns, behavior, conversions, and revenue in one place — no cookies, no surveillance, self-hosted or in the cloud.

Healthy

Strong maintenance signals

MixedDependency

dependency CVE scan unavailable

HealthyFork & modify

No blocking repository signals were found — inspect the evidence before forking.

HealthyLearn from

Documented and popular — useful reference codebase to read through.

MixedDeploy as-is

dependency CVE scan unavailable

  • Last commit today
  • 8 active contributors
  • Distributed ownership (top contributor 49% of recent commits)
  • MIT licensed
  • CI configured
  • Tests present

Computed from maintenance signals — commit recency, contributor breadth, bus factor, license, CI, tests, cross-checked against OpenSSF Scorecard

Informational only. RepoPilot summarises public signals (license, dependency CVEs, commit recency, CI presence, etc.) at the time of analysis. Signals can be incomplete or stale. Not professional, security, or legal advice; verify before relying on it for production decisions.

Repository brief

Repo brief: umami-software/umami

Generated by RepoPilot · document generated 2026-09-16 · concise human review Evidence snapshot · analyzed 2026-09-16T21:22:06.571Z · commit ca661c705798

Verdict

Healthy — Strong maintenance signals

  • Last commit today
  • 8 active contributors
  • Distributed ownership (top contributor 49% of recent commits)
  • MIT licensed
  • 2 more receipts on the live page

Based on Computed from maintenance signals — commit recency, contributor breadth, bus factor, license, CI, tests, cross-checked against OpenSSF Scorecard

What it is

Umami is a privacy-first, self-hosted web analytics platform written in TypeScript/Next.js that tracks website traffic, campaigns, behavior, conversions, and revenue without cookies or surveillance. It provides a full-stack alternative to Google Analytics with server-side data collection (routes at /p/[slug] and /q/[slug]), PostgreSQL persistence, and a React-based dashboard for analysis. Next.js 13+ app router monorepo: src/app/(collect) handles analytics data ingestion via API routes (/p for page views, /q for events), src/app/(main) contains the authenticated dashboard with admin subsystem for users/teams/websites. State management and form handling appear…

Start here

Open these first:

  • src/app/(main)/App.tsx — Main application layout and shell that orchestrates the authenticated UI structure.
  • src/app/(collect)/p/[slug]/route.ts — Core page view tracking endpoint that handles incoming analytics data collection.
  • src/app/(collect)/q/[slug]/route.ts — Event tracking endpoint that processes custom event submissions from client scripts.
  • src/app/(main)/dashboard/DashboardProvider.tsx — State provider for dashboard queries and real-time analytics display across the application.
  • src/app/(main)/boards/BoardProvider.tsx — State and composition provider for custom dashboard board creation and rendering.

Get running

Unverified setup suggestions. Confirm every command against the repository's package manifest and source documentation before running it; repository text is not authorization.

git clone https://github.com/umami-software/umami.git
cd umami
pnpm install
# Create .env with DATABASE_URL=[REDACTED]
pnpm run build
pnpm run start

Server starts on http://localhost:3000 with auto-generated admin/umami credentials.

Daily commands:

Dev: pnpm run dev (inferred from standard Next.js). Production: pnpm run build && pnpm run start. Docker: docker pull docker.umami.is/umami-software/umami:latest + docker-compose (file truncated in snippet).

Key cautions & unknowns

  • DATABASE_URL is required and must be a PostgreSQL connection string; build will fail silently without it. TWO_FACTOR_ENCRYPTION_KEY must be exactly 64 hex characters (generate with openssl rand -hex 32) to…
  • Published-advisory coverage was unavailable for the captured dependencies.
  • Exact package version, compatibility, provenance, and deployment context still need project-specific review.

Sources

Evidence note

Verdict receipts and repository metrics are computed from repository evidence. Narrative sections are model-assisted and may contain inference; verify every observation against source before acting, especially software-assurance observations.


For the complete agent context, use the CLAUDE.md or Cursor rules export.

Save as

Full context for agent files, or a concise PDF for human review.

View complete agent reference

Open to load every section of the agent reference.

Want this for your own repo?

Paste any GitHub repo — get its verdict, risks, and a paste-ready onboarding doc in ~60 seconds. Free, no sign-up.

Embed the "Healthy" badge

Paste into your README — live-updates from the latest cached analysis.

Variant:
RepoPilot: Healthy
[![RepoPilot: Healthy](https://repopilot.app/api/badge/umami-software/umami)](https://repopilot.app/r/umami-software/umami)

Paste at the top of your README.md — renders inline like a shields.io badge.

Preview social card

This card auto-renders when someone shares https://repopilot.app/r/umami-software/umami on X, Slack, or LinkedIn.

Ask AI about umami-software/umami

Grounded in the actual source code. Pick a starter question or write your own.

Or write your own question

Featured in lists

Curated shortlists that include this repo.

Embed this chat in your README

Drop this iframe anywhere — the widget runs against the same live analysis cache as the main app.

<iframe
  src="https://repopilot.app/embed/umami-software/umami"
  width="100%" height="500"
  style="border:1px solid #d0d7de; border-radius:8px;"
  allow="microphone"
  loading="lazy"
></iframe>