← Back to search

umami-compass

GitHub Actions Scanned 5d ago

A secure, read-only MCP server for Umami Analytics 3.2+ — Cloud and self-hosted

npm
C
74.8 / 100

Versions

0.5.1latest
Jul 21, 2026
0.5.0
Jul 20, 2026
0.4.1
Jul 16, 2026
0.4.0
Jul 16, 2026
0.3.1
Jul 13, 2026
+ show 6 moreshow less
0.3.0
Jul 13, 2026
0.2.0
Jul 13, 2026
0.1.3
Jul 13, 2026
0.1.2
Jul 13, 2026
0.1.1
Jul 13, 2026
0.1.0
Jul 13, 2026
PermissionsTool SafetyAuthAnnotationsCode QualityStabilitySpecVuln HistoryAuthorTransparencyCommunity

Tools 42

get_saved_report
annotations: none low

Get one saved report definition. The website ID is required to enforce the local allowlist and is verified against the response.

list_replays
annotations: none low

List Umami 3.2 session replay metadata. Successful responses state whether data is available and why an authorized result is empty. Raw rrweb event payloads are intentionally excluded.

search string
resolve_website
annotations: none low

Resolve a website UUID from a UUID, domain, URL, or website name. Ambiguous matches return bounded candidates instead of guessing.

query string candidateLimit number
get_portfolio_overview
annotations: none low

Summarize bounded aggregate traffic across visible websites, including period changes, growth and decline leaders, stale tracking, failures, and suspicious jumps.

staleAfterHours number anomalyMinimumPageviews number anomalyThresholdPercent number
analyze_performance_portfolio
annotations: none low

Compare Core Web Vitals across a bounded website portfolio with compact-by-default output, metric-specific drill-down selection, confidence, event/pageview ratios, and precise section truncation metadata.

comparisonMode enum detailRowLimit number excludeDomains array detailSiteLimit number excludeWebsiteIds array minimumEventCount number
explain_traffic_change
annotations: none low

Compare traffic with a previous, year-over-year, or custom period and rank observed changes across pages, referrers, countries, devices, channels, and events. Results describe association, not causation.

limit number comparisonMode enum
compare_traffic_series
annotations: none low

Return aligned current and comparison traffic buckets to locate the exact day or hour when traffic changed.

unit enum comparisonMode enum
analyze_release_impact
annotations: none low

Compare equal pre- and post-release windows across traffic breakdowns and Core Web Vitals. Returns a compact executive summary by default; request full detail for drill-down evidence. Recent releases use a partial post window and an equally shortened pre window.

limit number windowDays number detailLevel enum otherReleases array includePerformance boolean
tracking_health_check
annotations: none low

Audit visible websites for stale or missing traffic, traffic drops, domain mismatches, referral-spam patterns, custom-event availability, recorder configuration, and section permission failures. Disabled optional features are warnings only when marked as expected.

expectEvents boolean expectReplay boolean expectHeatmap boolean lookbackHours number staleAfterHours number minimumPageviews number dropThresholdPercent number
list_segments
annotations: none low

List reusable website segments or cohorts from Umami's paged response with explicit context limits.

type enum limit number search string
get_heatmap
annotations: none low

Get Umami 3.2 click or scroll heatmap data. Successful responses state whether data is available and why an authorized result is empty. Omit urlPath to list pages; provide it for bounded detail.

mode enum urlPath string maxPages number maxPoints number maxBuckets number
list_sessions
annotations: none low

List and search visitor sessions for a website and time range.

search string
get_session_stats
annotations: none low

Get aggregate session metrics for a website and time range.

get_session
annotations: none low

Get metadata for one Umami visitor session.

get_session_activity
annotations: none low

Get a bounded list of pageviews and events that occurred during one session and time range.

maxItems number
get_web_vitals
annotations: none low

Get normalized Umami 3.2 LCP, INP, CLS, FCP and TTFB summaries plus a bounded series for one metric. Empty data, partial buckets, filter scope and unavailable upstream sample counts are explicit.

maxPoints number
get_performance_breakdown
annotations: none low

Rank Web Vital percentiles by page, page title, device or browser. Rows default to 20 performance events and report the upstream limitation that per-metric non-null counts are unavailable.

limit number minimumSampleCount number
compare_web_vitals
annotations: none low

Compare all five Web Vital p75 summaries against a previous, year-over-year or custom period with ratings, materiality, event-count readiness and explicit filter scope.

compare_performance_breakdown
annotations: none low

Align page, page-title, device or browser rows across two periods. Comparable rows come first; undersized rows are excluded by default and missing capped candidates remain unknown rather than being treated as zero.

limit number
get_performance_cross_tab
annotations: none low

Derive a bounded two-dimensional performance breakdown through explicit fan-out. Candidate source, request count, sample limitations and truncation are reported so the result is not mistaken for a native exhaustive pivot.

candidateLimit number rowsPerCandidate number candidateDimension enum
get_route_group_performance
annotations: none low

Measure caller-defined route templates with exact regex-filtered performance queries instead of attempting to merge non-composable percentiles from individual URLs.

get_server_info
annotations: none low

Get the local package version, enabled toolsets, safety limits, and supported analysis capabilities without exposing credentials.

list_websites
annotations: none low

List websites visible directly or through any team membership of the configured Umami identity. If UMAMI_WEBSITE_IDS is set, returns only that exact allowlist.

search string
get_website
annotations: none low

Get metadata for one website.

get_website_stats
annotations: none low

Get visits, visitors, pageviews, bounces, visit duration and Umami's comparison values for a time range.

get_pageviews
annotations: none low

Get Umami 3.2 pageview and session time series. Both arrays are preserved in the response.

get_metrics
annotations: none low

Get a ranked aggregate Umami metric breakdown such as paths, referrers, countries, devices, events, channels or URLs. Visitor identifiers are excluded from the core toolset.

limit number offset number search string
get_active_visitors
annotations: none low

Get the current number of active visitors for a website.

get_website_date_range
annotations: none low

Get the earliest and latest analytics timestamps available for a website.

get_revenue_stats
annotations: none low

Get Umami 3.2 revenue totals and comparison values in a chosen currency.

get_revenue_metrics
annotations: none low

Break down Umami 3.2 revenue by country, region, referrer or channel.

type enum limit number
list_events
annotations: none low

List and search custom events for a website and time range.

search string
get_event_stats
annotations: none low

Get aggregate custom-event statistics and comparison values.

get_event_series
annotations: none low

Get custom-event counts over time, optionally filtered to a named event.

limit number
list_saved_reports
annotations: none low

List saved report definitions for one website without modifying them.

run_goal_report
annotations: none low

Calculate an Umami conversion goal for a path or custom event.

type enum value string
run_funnel_report
annotations: none low

Calculate a 2–8 step Umami funnel. windowMinutes controls the allowed time between consecutive steps.

steps number endStep string eventType number startStep string
run_journey_report
annotations: none low

Calculate the most common 2–7 step user journeys and return a bounded ranking.

steps number endStep string eventType number startStep string
run_retention_report
annotations: none low

Calculate daily Umami cohort retention and return a bounded result set.

limit number
run_utm_report
annotations: none low

Calculate Umami source, medium, campaign, term and content performance with bounded category arrays.

run_attribution_report
annotations: none low

Calculate first-click or last-click attribution for a conversion path or event with bounded channel arrays.

step string type enum model enum
run_breakdown_report
annotations: none low

Cross-tabulate up to three Umami dimensions, including derived channel combinations, and return the highest-ranked bounded rows.

limit number

Permissions 3

network medium
Server uses network capabilities via: fetch()
shell high
Server uses shell capabilities via: child_process
env_vars low
Server uses env_vars capabilities via: process.env

Scan Findings 94

low
Tool 'list_replays' has no annotations annotation_checker · 100%
low
Tool 'resolve_website' has no annotations annotation_checker · 100%
low
Tool 'get_portfolio_overview' has no annotations annotation_checker · 100%
low
Tool 'analyze_performance_portfolio' has no annotations annotation_checker · 100%
low
Tool 'explain_traffic_change' has no annotations annotation_checker · 100%
low
Tool 'compare_traffic_series' has no annotations annotation_checker · 100%
low
Tool 'analyze_release_impact' has no annotations annotation_checker · 100%
low
Tool 'tracking_health_check' has no annotations annotation_checker · 100%
low
Tool 'get_heatmap' has no annotations annotation_checker · 100%
low
Tool 'list_sessions' has no annotations annotation_checker · 100%
low
Tool 'get_session_stats' has no annotations annotation_checker · 100%
low
Tool 'get_session' has no annotations annotation_checker · 100%
low
Tool 'get_session_activity' has no annotations annotation_checker · 100%
low
Tool 'get_web_vitals' has no annotations annotation_checker · 100%
low
Tool 'get_performance_breakdown' has no annotations annotation_checker · 100%
low
Tool 'compare_web_vitals' has no annotations annotation_checker · 100%
low
Tool 'compare_performance_breakdown' has no annotations annotation_checker · 100%
low
Tool 'get_performance_cross_tab' has no annotations annotation_checker · 100%
low
Tool 'get_route_group_performance' has no annotations annotation_checker · 100%
low
Tool 'get_server_info' has no annotations annotation_checker · 100%
low
Tool 'list_websites' has no annotations annotation_checker · 100%
low
Tool 'get_website' has no annotations annotation_checker · 100%
low
Tool 'get_website_stats' has no annotations annotation_checker · 100%
low
Tool 'get_pageviews' has no annotations annotation_checker · 100%
low
Tool 'get_metrics' has no annotations annotation_checker · 100%
low
Tool 'get_active_visitors' has no annotations annotation_checker · 100%
low
Tool 'get_website_date_range' has no annotations annotation_checker · 100%
low
Tool 'get_revenue_stats' has no annotations annotation_checker · 100%
low
Tool 'get_revenue_metrics' has no annotations annotation_checker · 100%
low
Tool 'list_events' has no annotations annotation_checker · 100%
low
Tool 'get_event_stats' has no annotations annotation_checker · 100%
low
Tool 'get_event_series' has no annotations annotation_checker · 100%
low
Tool 'list_saved_reports' has no annotations annotation_checker · 100%
low
Tool 'get_saved_report' has no annotations annotation_checker · 100%
low
Tool 'list_segments' has no annotations annotation_checker · 100%
low
Tool 'run_goal_report' has no annotations annotation_checker · 100%
low
Tool 'run_funnel_report' has no annotations annotation_checker · 100%
low
Tool 'run_journey_report' has no annotations annotation_checker · 100%
low
Tool 'run_retention_report' has no annotations annotation_checker · 100%
low
Tool 'run_utm_report' has no annotations annotation_checker · 100%
low
Tool 'run_attribution_report' has no annotations annotation_checker · 100%
low
Tool 'run_breakdown_report' has no annotations annotation_checker · 100%
info
Sandbox failed to start for behavioral verification behavioral_verifier · 100%
info
package.json metadata manifest_parser · 100%
info
Tool: list_replays manifest_parser · 85%
info
Tool: resolve_website manifest_parser · 85%
info
Tool: get_portfolio_overview manifest_parser · 85%
info
Tool: analyze_performance_portfolio manifest_parser · 85%
info
Tool: explain_traffic_change manifest_parser · 85%
info
Tool: compare_traffic_series manifest_parser · 85%
info
Tool: analyze_release_impact manifest_parser · 85%
info
Tool: tracking_health_check manifest_parser · 85%
info
Tool: get_heatmap manifest_parser · 85%
info
Tool: list_sessions manifest_parser · 85%
info
Tool: get_session_stats manifest_parser · 85%
info
Tool: get_session manifest_parser · 85%
info
Tool: get_session_activity manifest_parser · 85%
info
Tool: get_web_vitals manifest_parser · 85%
info
Tool: get_performance_breakdown manifest_parser · 85%
info
Tool: compare_web_vitals manifest_parser · 85%
info
Tool: compare_performance_breakdown manifest_parser · 85%
info
Tool: get_performance_cross_tab manifest_parser · 85%
info
Tool: get_route_group_performance manifest_parser · 85%
info
Tool: get_server_info manifest_parser · 85%
info
Tool: list_websites manifest_parser · 85%
info
Tool: get_website manifest_parser · 85%
info
Tool: get_website_stats manifest_parser · 85%
info
Tool: get_pageviews manifest_parser · 85%
info
Tool: get_metrics manifest_parser · 85%
info
Tool: get_active_visitors manifest_parser · 85%
info
Tool: get_website_date_range manifest_parser · 85%
info
Tool: get_revenue_stats manifest_parser · 85%
info
Tool: get_revenue_metrics manifest_parser · 85%
info
Tool: list_events manifest_parser · 85%
info
Tool: get_event_stats manifest_parser · 85%
info
Tool: get_event_series manifest_parser · 85%
info
Tool: list_saved_reports manifest_parser · 85%
info
Tool: get_saved_report manifest_parser · 85%
info
Tool: list_segments manifest_parser · 85%
info
Tool: run_goal_report manifest_parser · 85%
info
Tool: run_funnel_report manifest_parser · 85%
info
Tool: run_journey_report manifest_parser · 85%
info
Tool: run_retention_report manifest_parser · 85%
info
Tool: run_utm_report manifest_parser · 85%
info
Tool: run_attribution_report manifest_parser · 85%
info
Tool: run_breakdown_report manifest_parser · 85%
info
Transport: stdio manifest_parser · 90%
info
Sandbox failed to start for output poisoning scan output_poisoning · 100%
medium
Permission: network access detected permission_analyzer · 70%
high
Permission: shell access detected permission_analyzer · 95%
low
Permission: env_vars access detected permission_analyzer · 90%
info
SBOM generated: 7 components sbom_generator · 100%
high
Generic API Key Assignment found in webcredo-umami-compass-18e9fcf/README.md secret_scanner · 75%
medium
No build provenance detected (SLSA L0) slsa_assessor · 90%