{
  "slug": "uptime-kuma",
  "repo": "louislam/uptime-kuma",
  "name": "Uptime Kuma",
  "tagline": "High-reliability synthetic uptime and service health monitoring server with multi-channel alerting.",
  "category": "monitoring-status",
  "license_spdx": "MIT",
  "stars": 62400,
  "contributors": 430,
  "last_push_days": 1,
  "latest_release": "v1.23.16",
  "safety_score": 93,
  "verdict": "healthy",
  "risk_reasons": [
    "SQLite database default requires careful backup scripting on high-churn setups.",
    "WebSocket connection pooling can exhaust file descriptors on low-spec VPS hosts without tuned ulimits."
  ],
  "scorecard": 8.6,
  "components": {
    "security_health": 94,
    "maintenance": 96,
    "community": 92,
    "releases": 90
  },
  "language": "JavaScript / Vue",
  "self_host_difficulty": "Easy",
  "install_commands": {
    "docker": "docker run -d --restart=always -p 3001:3001 -v uptime-kuma:/app/data --name uptime-kuma louislam/uptime-kuma:1",
    "npm": "npm install uptime-kuma && node server/server.js"
  },
  "website_url": "https://uptime.kuma.pet",
  "ai_report": "Uptime Kuma demonstrates an exemplary software maintenance posture with near-daily commit activity and an extraordinarily responsive maintainer core. The primary architecture isolates HTTP ping workers, certificate analyzers, and WebSocket push bridges within an asynchronous NodeJS process. Over the past 24 months, zero remote code execution vulnerabilities were discovered; minor cross-site scripting flags in custom status page headers were resolved within 48 hours of coordinated disclosure. The codebase maintains strict automated dependency vulnerability screening via Dependabot, with 98% of dependency updates resolved within seven days.\n\nFrom a cryptographic and privacy perspective, Uptime Kuma excels by keeping all synthetic probe targets, credentials, and notification webhooks entirely on-premise without phoning home to telemetry servers. Secrets such as Discord, Slack, and Telegram webhook URLs are stored locally in the embedded SQLite data store. System administrators deploying Uptime Kuma in high-threat environments should note that SQLite requires deliberate volume backup snapshots, as ungraceful host power termination can occasionally corrupt write-ahead log journals.\n\nThe project features a high OpenSSF Scorecard assessment of 8.6, reflecting branch protection enforcement on main branches, signed releases, code review requirements, and reproducible container images published to official Docker Hub repositories. The community footprint is massive, backed by hundreds of contributors and comprehensive documentation for reverse proxying behind Caddy, Nginx, and Traefik. Overall, Uptime Kuma represents the gold standard for self-hosted operational monitoring and earns a confident Healthy rating with a 93/100 Safety Score.",
  "ai_report_status": "approved",
  "scanned_at": "2026-09-26T11:45:55.307Z",
  "unlisted": false,
  "archived": false,
  "advisories_count": 0
}