Softwr

Cybersecurity · head to head

Trivy vs Umami

Trivy logo

Trivy

Cybersecurity

Open-source vulnerability and misconfiguration scanner

From
Free
Rated
-
Umami logo

Umami

Marketing

Open source, cookie-free web analytics you can self-host for the cost of a database

From
Free
Rated
-

The short version

  • Each has a real cost: Trivy reports what public advisory databases know, so coverage varies by ecosystem and unfixed CVEs create noise; Umami there is no cohort analysis, retention curve, session replay or multi-touch attribution, so a marketing team that needs to justify channel spend will still buy a second tool and Umami becomes a supplementary dashboard.
  • They diverge on capability: Trivy covers Multi-target scanning, Umami covers Cookie-free tracking.
  • Prices and features above were last checked on 31 August 2026.

Where they differ

Only the attributes on which Trivy and Umami actually diverge.

Attributes where Trivy and Umami differ
AttributeTrivyUmami
Pricing modelOpen source, no licence feePer month by event count
PlatformsLinux, macOS, Windows, Docker, KubernetesWeb, Linux
CategoryCybersecurityMarketing

Identical on both: starting price (Free), free tier (Yes), user rating (Not yet rated).

What each one covers

Drawn from each product's published feature list. An absence here means we hold no record of it - not that the product lacks it.

Only in Trivy

  • Multi-target scanning
  • Vulnerability detection
  • Misconfiguration checks
  • Secret detection

Only in Umami

  • Cookie-free tracking
  • Self-hosting
  • Small tracking script
  • Custom events
  • Funnels and goals
  • Multi-site and teams
  • Public dashboards
  • API access

What people use each for

The jobs each tool is most often brought in to do.

Trivy

  • Failing a pull request when a container image introduces a known CVEnot Umami
  • Scanning Terraform and Kubernetes manifests for misconfiguration before applynot Umami
  • Catching committed secrets as part of an existing CI stepnot Umami

Umami

  • A developer who wants traffic numbers on a personal or client site without adding a consent bannernot Trivy
  • An organisation whose legal or procurement team has ruled out sending visitor data to a US advertising companynot Trivy
  • A high-traffic site where hosted analytics priced by pageview band has become expensive and self-hosting removes the ceiling entirelynot Trivy
  • A team that wants analytics data in a database they already control so they can query and join it themselvesnot Trivy

Where each one falls short

Documented limitations, not opinions. Every one is a constraint you would hit in normal use.

Trivy

  • Reports what public advisory databases know, so coverage varies by ecosystem and unfixed CVEs create noise
  • No built-in triage or exception workflow, so suppressing accepted risk is managed in config files
  • Findings are point-in-time from CI, with no continuous runtime monitoring unless you add the commercial platform

Umami

  • There is no cohort analysis, retention curve, session replay or multi-touch attribution, so a marketing team that needs to justify channel spend will still buy a second tool and Umami becomes a supplementary dashboard.
  • Self-hosting is only free in licence terms; you own the database, the upgrades, the backups and the query performance at scale, and a busy site's events table grows quickly enough to need real attention.
  • Because it stores no persistent identifier, it cannot follow a user across devices or sessions in any meaningful way, which makes returning-visitor and lifetime-value questions unanswerable by design rather than by omission.
  • Cloud overage is billed per event beyond the plan allowance, so a traffic spike or a badly instrumented custom event can produce a bill materially above the $20 or $200 headline before anyone notices.
  • It is maintained by a small team, so the pace of new capability is modest and enterprise expectations such as SSO, granular role permissions and formal support agreements are limited compared with commercial analytics vendors.

Pricing, plan by plan

Trivy

Free
  • TrivyFree
    • Full scanner
    • Unlimited scans
    • Community support

Umami

Free
  • Self-hostedFree
    • MIT licensed, no licence fee
    • No event limit imposed by the software
    • Unlimited websites and users
  • Cloud HobbyFree
    • Up to 100,000 events per month
    • 3 websites
    • 6 months data retention
  • Cloud Pro$20/month
    • Up to 1,000,000 events per month
    • Unlimited websites
    • Unlimited team members
  • Cloud Business$200/month
    • Up to 10,000,000 events per month
    • All Pro features
    • Higher volume overage rate

Which should you pick?

Choose Trivy if

  • You need multi-target scanning.
  • You want to start without paying.
  • You work on Linux, macOS, Windows, Docker, Kubernetes.
  • You also want vulnerability detection.

Choose Umami if

  • You need cookie-free tracking.
  • You want to start without paying.
  • You work on Web, Linux.
  • You also want self-hosting.

Questions people ask

Is Trivy or Umami better?
Neither clearly leads. Trivy starts at Free and Umami at Free, and user ratings are close enough to be indistinguishable. Choose on capability and platform support.
Which is cheaper, Trivy or Umami?
Trivy starts at Free and Umami at Free.
Does Trivy or Umami run on more platforms?
Trivy runs on Linux, macOS, Windows, Docker, Kubernetes. Umami runs on Web, Linux.
Can I use Trivy for free?
Both have a free tier, so you can try either at no cost before committing.
What is Trivy best used for?
Trivy is most often used for failing a pull request when a container image introduces a known cve, scanning terraform and kubernetes manifests for misconfiguration before apply, catching committed secrets as part of an existing ci step. Of those, failing a pull request when a container image introduces a known cve and scanning terraform and kubernetes manifests for misconfiguration before apply are not what Umami is typically brought in for.
What can Trivy do that Umami cannot?
Trivy covers Multi-target scanning, Vulnerability detection, Misconfiguration checks, Secret detection. Umami covers Cookie-free tracking, Self-hosting, Small tracking script, Custom events.

Answered from the vendors’ own pages

Trivy: Is Trivy free?

Yes, open source from Aqua Security with no licence fee. Aqua sells a commercial platform around it.

Umami: Is Umami really free?

Self-hosted, yes; it is MIT licensed with no event cap. You pay for the server and database. Umami Cloud has a free tier at 100,000 events a month and paid tiers from $20.

Trivy: What can Trivy scan?

Container images, filesystems, Git repositories, Kubernetes clusters and infrastructure-as-code, for vulnerabilities, misconfigurations, secrets and licences.

Umami: Do I need a cookie consent banner?

For Umami analytics specifically, generally no, because it sets no cookies and stores no personal data. Other tags on your site may still require one.

Trivy: Does Trivy need a server?

No. It is a single binary, which is a large part of why it became a default in CI.

Umami: Can it replace Google Analytics?

For traffic, referrers and event counts, yes. For attribution modelling, audiences and advertising integration, no.

Umami: What does it need to run?

A container and a PostgreSQL or MySQL database. Most people deploy it on infrastructure they already pay for.

Share

Related pages

Other head to heads