scanned 1d ago·osv · gitleaks · opengrep · picklescan + heuristics·full breakdown in the Security tab ↓
Umami
Umami is a simple, fast, privacy-focused open-source web analytics tool and a lightweight alternative to Google Analytics. It gives marketers and site owners the essential metrics — page views, visitors, referrers, campaigns (UTM), and events — without using cookies or collecting personal data, which simplifies GDPR/PECR compliance and avoids consent-banner friction.
Key features
Cookie-free, privacy-first tracking that does not collect personal information
UTM campaign and referrer tracking for marketing attribution
Custom event tracking and per-URL/goal reporting
Self-hostable (Docker) on your own domain with unlimited websites and users
Umami runs on Node.js with PostgreSQL or MySQL and installs in minutes. A single script tag starts collecting data, and the tracker is only a couple of kilobytes, so it has negligible impact on page performance. With tens of thousands of GitHub stars, it is one of the most popular open web-analytics projects and a common choice for teams that want marketing insight while keeping full ownership of their visitor data.
Curated mirror of the open-source Umami (MIT). Get it from the source.
! Security: Review · 7575/100 · grade Bscanned 1d ago
✓ no compromise signals11 risk-surface · 6/20 OWASP controls flagged
Compromise signals — malicious or tampered code (leaked secrets, backdoors, a dropped executable) — reduce the score, and known dependency CVEs carry a bounded penalty (they warrant review but never QUARANTINE — update the dependency to clear). Other dangerous-by-capability traits are risk surface, expected for some capabilities. Every finding is mapped to its OWASP control below.
What this capability can do · med confidence (static)
Findings mapped to the OWASP Top 10 for LLM Applications (2025) and the OWASP Machine Learning Security Top 10. Expand any flagged control for the exact findings — compromise reduces the score; expected/risk-surface do not, except a known CVE, which carries a small bounded penalty (high/critical → Review).
OWASP Top 10 for LLM Applications
⚠LLM03Supply Chaincritical
Vulnerable/compromised dependencies, models or archives in the artifact.