Self-hosted web analytics: which tool to pick

Eight open-source analytics tools run on your own server, but they don't answer the same need. GoAccess reads web server logs and puts no script on the page. PostHog measures how people use an application more than who visits a site, and its vendor points you to its cloud beyond about 100,000 events a month. The other six load a script in the page: Umami gets by with Node.js and PostgreSQL, Matomo can also import server logs, and Plausible, Rybbit and Swetrix run on a ClickHouse database.

Script, logs or product analytics: three ways to measure

A script-based tool loads a JavaScript file that counts page views, traffic sources and the events you pick. Plausible, Umami, Matomo, Rybbit, Swetrix and Open Web Analytics all work this way. Umami's docs spell out the limit they share: a visitor whose ad blocker filters the script isn't counted.

Log analysis starts on the server. GoAccess reads access logs from Apache, Nginx or a CDN such as CloudFront: it sees the requests that blockers hide from scripts, but nothing that happens in the browser without a request to the server. Its manual defines a unique visitor as an IP address, a date and a user agent, bots included by default. Matomo bridges the two: its import_logs.py script loads Apache, Nginx, IIS, HAProxy or CloudFront logs, without screen resolution, page titles or events.

Product analytics follows users through an application: funnels, session replay, feature flags, A/B tests. PostHog is the example here. Its own README puts the limit of a self-hosted instance at about 100,000 events a month.

What each tool needs to run

Read from the repositories and documentation on 5 October 2026.

ToolLicenceWhat you runCollectionCookie by defaultLatest release
MatomoGPL 3.0 or laterPHP, MySQL or MariaDBscript, log importyes, can be turned off5.14.1, 4 Oct 2026
UmamiMITNode.js 22, PostgreSQLscriptno3.4.0, 17 Sep 2026
Plausible, Community EditionAGPL 3.0 or laterPostgreSQL, ClickHouse, 2 GB of RAMscriptno3.2.1, 15 May 2026
RybbitAGPL 3.0ClickHouse, PostgreSQL, Redis, 2 GB of RAM, an HTTPS domainscriptno2.9.0, 12 Sep 2026
Swetrix, Community EditionAGPL 3.0ClickHouse, Redis, 2 GB of RAMscriptno5.4.1, 4 Aug 2026
Open Web AnalyticsGPL 2.0 or laterPHP 8.2, MySQL, a cron job every minutescriptyes, 364 days1.14.0, 21 Sep 2026
PostHogMIT, except the ee/ directory38 Docker services, 4 vCPU and 16 GB of RAM advisedscriptyes, 365 daysnone: continuous delivery from master
GoAccessMITno database, RAM caps the volumeserver logsnot applicable1.12, 16 Sep 2026

The three tools built on ClickHouse recommend 2 GB of RAM. Matomo advises 2 CPUs and 2 GB of RAM for up to 100,000 page views a month, and Open Web Analytics has needed a cron job every minute since version 1.11.

On releases, Open Web Analytics shipped nothing between January 2023 and June 2025, then ten versions between July and September 2026, with a database schema change in each of the last four. PostHog publishes no versions at all and takes no support tickets from self-hosted instances. Plausible's Community Edition ships twice a year.

Four vendors keep part of the product for their paid plan. Matomo sells funnels, heatmaps and session recordings as separate plugins under a proprietary licence. PostHog's docs keep every paid-plan feature on its cloud. Swetrix's Community Edition records JavaScript errors but sends no alerts, and Plausible's has no funnels, no revenue goals and no SSO.

What "cookieless" doesn't settle

A "cookieless" label says nothing about the conditions under which the CNIL, France's data protection regulator, lets a site measure its audience without asking for consent. Its page on audience measurement tools ties them to how the data is used: measurement done only for the site owner, anonymous statistics, no cross-referencing with other processing and no tracking from one site to the next. The CNIL also recommends telling visitors, keeping trackers for thirteen months at most and the data for twenty-five. It forbids vendors from presenting a tool as "certified" or "approved by the CNIL".

Matomo sets cookies by default, but its "Enforce compliance" option, added in version 5.9, masks part of the IP address, fixes the retention period and turns off the visits log, visitor profiles, heatmaps and A/B tests. GoAccess sets no script and no cookie, yet the logs it reads hold the full IP address, and its anonymisation option only masks it in the report.

Without cookies, visitors are also counted differently. Umami builds its visitor ID with a salt that rotates every month, so a visitor who comes back the following month counts as new.

Adding an analytics script under a strict CSP

A Content Security Policy without 'unsafe-inline' blocks scripts written into the page. Plausible's install snippet is one of them: move it into a file served by the site, then allow the analytics instance's origin in script-src for the loader and in connect-src for sending events. GoAccess's HTML report raises the problem the other way round: its FAQ says it requires 'unsafe-inline' and 'unsafe-eval' on the page that serves it.

Contact clicks are easy to lose. Plausible's outbound link tracking compares the link's host with the page's, and a mailto: link has no host, so clicks on an email address only show up through a custom event. Umami counts no click at all unless the element carries a data-umami-event attribute.