Umami · Vulnerability Disclosure

Umami Vulnerability Disclosure

Vulnerability disclosure

Umami publishes a responsible vulnerability disclosure policy on its security page, with a dedicated reporting address, a report-quality checklist and rules of engagement for researchers. It is a policy, not a bounty.

Umami runs a coordinated vulnerability disclosure program on Hackerone.

Cookieless TrackingOpen-SourcePrivacyWeb AnalyticsWebsite AnalyticsProduct AnalyticsEvent TrackingSelf-HostedGDPRSession ReplayHeatmapsMarketing Attribution
Program: Hackerone

Disclosure Policy

Policy
Policy
Policy
Policy
Policy
Policy
Policy
Policy
Policy

Security Contact

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-08-13'
method: searched
source: https://umami.is/security
provider: Umami
providerId: umami
description: >-
  Umami publishes a responsible vulnerability disclosure policy on its security
  page, with a dedicated reporting address, a report-quality checklist and rules
  of engagement for researchers. It is a policy, not a bounty.
policy:
  published: true
  url: https://umami.is/security
  section: Responsible vulnerability disclosure
  contact: security@umami.is
  contact_kind: email
  scope: >-
    Umami and Umami Cloud. Explicitly OUT of scope: customer-controlled
    self-hosted installations, which must not be tested without the operator's
    permission.
  statement: >-
    "We welcome reports from security researchers and customers who believe they
    have discovered a vulnerability in Umami or Umami Cloud."
  response_commitment: >-
    "We will review good-faith reports and keep the reporter informed as the
    issue is investigated." No numeric acknowledgement or remediation SLA is
    published.
  safe_harbor: not_stated
bug_bounty:
  operates: false
  statement: >-
    "Umami does not currently operate a guaranteed paid bug-bounty program."
  platforms_checked: [HackerOne, Bugcrowd, Intigriti]
  platforms_found: []
report_should_include:
  - The affected product, URL, API endpoint, or software version
  - A description of the vulnerability and its potential impact
  - Reproduction steps or a proof of concept
  - Any relevant logs, screenshots, or request details
  - Preferred contact information
rules_of_engagement:
  - Do not access, modify, download, or delete customer data
  - Do not disrupt Umami Cloud or degrade service availability
  - Do not perform denial-of-service, spam, or social-engineering attacks
  - Do not test against customer-controlled self-hosted installations without permission
  - Use accounts and data that you own whenever possible
  - Give Umami a reasonable opportunity to investigate and remediate before public disclosure
advisories:
  channel: GitHub Security Advisories
  url: https://github.com/umami-software/umami/security/advisories
  note: >-
    The security page states Umami investigates "reported vulnerabilities and
    GitHub security advisories" as part of its SDLC. Because Umami is open
    source under MIT, GitHub advisories are the practical disclosure channel for
    the self-hosted product.
gaps:
  - >-
    No /.well-known/security.txt on any Umami host (umami.is, api.umami.is,
    cloud.umami.is, docs.umami.is all miss — see well-known/umami-well-known.yml).
    The policy exists and the contact exists; only the RFC 9116 machine-readable
    form is missing. This is the cheapest available fix on this artifact.
  - No published acknowledgement or remediation timeline.
  - No safe-harbor language.
evidence:
  - url: https://umami.is/security
    status: 200
  - url: https://umami.is/.well-known/security.txt
    status: 404
  - url: https://api.umami.is/.well-known/security.txt
    status: 405
maintainers:
  - FN: Kin Lane
    email: kin@apievangelist.com

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/umami-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.