21855 stars · GPL-3.0 — read from /blob/master/LICENSE, plain unmodified FSF text; the only project words are inside the standard fill-in-the-blank appendix · 5.14.0 — GitHub dates it 2026-09-21, Packagist dates the same version 2026-09-16, a five-day disagreement with both in 2026; version 6 is in beta, 6.0.0-b4 published 2026-09-30, the morning of the run · Track this in Scout
Website visitor reporting that runs on your own hosting, with the data in your own database.
▶Repo detailsthe review · specs · pros & cons · install
What it is
A large PHP application at 21,855 stars, created in March 2011, that collects and reports on website and application traffic. Version 5.14.0 is the current stable release, dated 21 September 2026, and version 6 is in testing right now: a test build was published on the morning this edition was written.
What it is good for. Anyone who must keep visitor data on their own machines, which is usually a legal or a client-confidentiality requirement rather than a preference. It is also the right choice when reports have to be as detailed as the well-known free service, because the simpler counters cover far less ground.
- GPL-3.0, read from the licence file and the plain unmodified text. The only project-specific words in it are inside the standard fill-in-the-blank example at the end.
- It publishes honest sizing figures, which almost nothing else here does. Up to 100,000 page views a month wants 2 processor cores, 2 GB of memory and a 50 GB disk; up to 1 million wants 4 cores, 8 GB and 250 GB; up to 10 million wants 8 cores, 16 GB and 100 to 400 GB; up to 100 million wants 16 or more cores, 32 GB or more and a 1 TB disk.
- Very active. Five versions, including test builds of the next major version, were published in the fortnight before this edition.
- The honest cost is the paid add-ons, not the licence. There are twenty of them, and they cover features many people assume are included: A/B testing, funnels, heat maps and session recording, user flows, custom reports, form reporting, media reporting, crash reporting, multi-channel attribution, roll-up reporting, search-engine keyword performance, activity logs, single sign-on and white labelling. The price is a subscription counted by user seats with a thirty-day trial, and no figure is shown without going through the trial or contacting sales, so we are not quoting one.
- Installing it is real system administration: a web server, PHP, a MySQL or MariaDB database, and a database user granted a long list of permissions including file access.
- Do not install it by copying the repository. The release page states that the source download is meant for developers and will need extra work; the archive attached to the release, or the download on the project's own site, is the way in.
- 2,500 open issues, the largest backlog on this page. Version 6 raises the floor to PHP 8.1 and MySQL 8.0 or MariaDB 10.6, which will leave older hosting behind.
umami-software/umamiA far smaller and simpler self-hosted visitor counter that installs in an evening instead of a weekend and answers correspondingly fewer questions.
Track this in Scout
plausible/community-editionThe same idea of a privacy-respecting counter you host, packaged for self-hosting by the company behind the paid service, with a deliberately small set of reports.
Track this in Scout
rybbit-io/rybbitVisitor and product reporting together, including funnels and session replay which are paid add-ons in Matomo; it needs 2 GB of memory and two databases.
Track this in Scout
sudo apt-get install php php-curl php-gd php-cli mysql-server php-mysql php-xml php-mbstring
