We’re excited to share with you our latest (and epic!) 3.6.0 release, continuing the great work done this year. Because we have greatly improved security and fixed a possible issue, this release is rated critical so please upgrade as soon as possible.

What’s new?

255 tickets have been closed by more than 26 contributors. Read more about the most important changes:

Users management re-designed

Users Management has been completely re-designed with efficiency and usability in mind. Check out the updated ‘Manage users’ guide to see how powerful and easy it now is to manage users and permissions, even across hundreds of websites and users.

New ‘write’ permission and ‘admin’ can now create users

We’re also slightly changing what ‘admin’ permission means, and we introduce a new ‘write’ permission for more flexibility. Users with ‘admin’ permissions have more power starting in Matomo 3.6.0: they can now directly create new users and give these users permissions to access the website’s data.

Improvements in reporting and dashboards

In terms of reporting: you can now build more awesome and precise dashboards by including only the metric(s) you need in your dashboard (Try the new widget “Generic > Metric” to display your KPI chosen amongst all of the dozens KPIs available in Matomo). In Referrers reports, “Social network” is now its own Referrer type along Search Engines, Websites, Campaigns and Direct entries. In all email reports, users will now find an “Unsubscribe” link that will let them unsubscribe from the email report. When you segment data in a report and the data is not processed yet, a notification will now explain why and clarify what to do next.

Administration and security improvements

In terms of Admin features: You can now define a Privacy policy page, and/or a Terms and conditions page for your Matomo that will be displayed at the bottom of certain pages, such as the Login screen. CORS hostnames can also now be configured in the User Interface directly (no more need to edit the config file). So far when you deleted a website, Matomo did not delete RAW data in your database. But starting in 3.6.0 a scheduled task will run to delete all data for websites that were deleted.

This release also brings dozens of other improvements and fixes. For example the Matomo Glossary has been redesigned and improved. MySQL 5.7.17+ compatibility with support for group replication. And we introduce several security improvements, please learn more about security in the section below.

New Tag Manager product now available for free in Matomo!

And our new and awesome Tag Manager is available for free from the Marketplace. It is a complete open source alternative to Google Tag Manager. Check it out! Soon we will include it in Matomo by default.

After You Update

  • Use the forums if you have any question or feedback (free support),
    or contact the Business Support Team to make the most of your Matomo Analytics and get professional support (paid support).
  • Please help us spread the word about Matomo! Maybe you can write about the project on your blog, website, twitter, talk about Matomo Analytics at conferences, or let your friends and colleagues know what is Matomo. Already 1,000,000+ websites have liberated their web analytics, and with your help we can grow the community!
  • To improve Matomo in your language consider contributing to translations.
  • Support our efforts by donating to the project.

Security release

This release is rated critical and it is highly recommend to upgrade to Matomo 3.6.0 as soon as possible.

Matomo authentication security was reviewed and improved in this release: no token_auth stored in cookies, after a password change all sessions are invalidated across all devices, all cookies are now set with the Secure flag over HTTPS, also now the session is kept active on a computer only when both the IP address and user agent are still matching (preventing re-use of the session cookie on another device).

You’ll also benefit from other security improvements: a potential XSS issue was fixed (responsibly reported as part of our bug bounty program by K. Górnicz), a new system check will warn you if you haven’t forced SSL only yet, and a new config setting is available to completely disable all features using the Internet or connecting to external servers..

Our security bug bounty program welcomes & rewards researchers who discover and responsibly report to us any security issues found in Matomo or any of the plugins created by Matomo/InnoCraft.

Database upgrade

This release does not contain any major database upgrade.

Platform Changes

Matomo is an open analytics platform. In an effort to help Matomo developers learn about improvements and changes in the core APIs, we document the changes since the last release.

In this 3.6.0 release there are breaking API changes, New features, New APIs, New config.ini.php settings. Read more in Platform Changelog for Developers to see all changes to the platform and APIs.

Note: the Marketplace showcases more than 75 plugins already compatible with Matomo 3 and this is just the beginning. Matomo is your universal data analytics platform!

New and updated SDKs (Tracking API Clients)

The Matomo team offers official SDKs (Tracking API Clients) for measuring your mobile apps and any other kind of apps.

Congratulations to the SDK maintainers and contributors for these great releases!

New and updated guides and FAQs

New:

Updated:

New plugins

By the Matomo team and InnoCraft:

By third party developers:

Need help upgrading Matomo?

Read the Updating Matomo user guide or for more help contact the Matomo experts.

Development Services

If you are missing some functionality in Matomo or need a bug fixed, or if you need a new custom feature developed especially for you, you can sponsor the development of it. Fill in this form to get started.

Features and bug fixes that were sponsored in this new release are marked below with “Sponsored by”. Thank you to these organisations for sponsoring improvements in Matomo!

List of 255 tickets closed in Matomo 3.6.0

We are together creating the best open analytics platform in the world. You can help make Matomo even more awesome by getting involved in Matomo!