Actual
actualbudget.orgA local-first personal finance app
- Homepage:actualbudget.org
- GitHub:github.com/actualbudget/actual
- Discord:8JfAXSgfRf
- Web info:web-check.xyz/check/actualbudget.org
Actual Source Code
Author
Description
A local-first personal finance app
Homepage
https://actualbudget.orgRepository
- LicenseMIT
- Created29 Apr 22
- Primary languageTypeScript
- Size601,733 KB
- Stars29,113
- Forks3,011
- Watchers29,113
Top Contributors
@MatissJanis (1092)
@matt-fidd (434)
@joel-jeremy (369)
@j-f1 (312)
@MikesGlitch (260)
@youngcw (190)
@jfdoming (165)
@TomAFrench (161)
@carkom (127)
@dependabot[bot] (115)
@shall0pass (114)
@rich-howell (89)
@lelemm (87)
@jlongster (80)
@psybers (76)
@bpaulien (66)
@Juulz (53)
@alecbakholdin (42)
@UnderKoen (42)
@twk3 (41)
@RubenOlsen (37)
@StephenBrown2 (36)
@PartyLich (29)
@trevdor (28)
@Shazib (23)
@kyrias (22)
@tim-smart (18)
@Copilot (17)
@misu-dev (16)
@github-actions[bot] (16)
@emiltb (13)
@pogman-code (13)
@milanalexandre (13)
@wdpk (12)
@aleetsaiya (12)
@Kidglove57 (12)
@Jackenmen (12)
@albertogasparin (11)
@Kovah (11)
@mnil (11)
@qedi-r (10)
@samaluk (10)
@shaankhosla (10)
@tabedzki (10)
@tcrasset (9)
@MattFaz (9)
@JSkinnerUK (9)
@jonner (8)
@Marethyu1 (8)
@jonathan-fang (8)
@Crazypkr (8)
@gsumpster (7)
@julianwachholz (7)
@tostasmistas (7)
@pa4uslf (7)
@sjones512 (7)
@Kennedy242 (6)
@rodriguestiago0 (6)
@ftbboy2115 (6)
@tlesicka (6)
@SamBobBarnes (6)
@rgoldfinger (6)
@HansiWursti (6)
@davidkaufman (6)
@JukeboxRhino (6)
@totallynotjon (5)
@winklevos (5)
@Jod929 (5)
@csenel (5)
@passabilities (5)
@Wizmaster (5)
@sreetamdas (5)
@migillett (5)
@karimkodera (5)
@Cldfire (5)
@Miodec (5)
@a-gradina (5)
@sinistersnare (4)
@biohzrddd (4)
@deathblade666 (4)
@joel-rich (4)
@sys044 (4)
@tempiz (4)
@duplaja (4)
@Dreptschar (4)
@mannkind (4)
@olets (4)
@OlivierKamers (4)
@skliaruk (4)
@kymckay (4)
@MatthiasBenaets (4)
@NikxDa (4)
@nikhilweee (4)
@hostyn (4)
@aujkb (4)
@zachwhelchel (4)
@YusefOuda (4)
@ShayanAraghi (4)
@tjex (4)
@tmchow (4)
Recent Commits
Matt Fiddaman(23 Sept 26)
sidebar: trigger group balance updates on sync (#8994) * trigger group balance updates on sync * note * coderabbit
Baris Ari(23 Sept 26)
[AI] Migrate create-folders migration to TypeScript (#8851) * [AI] Migrate create-folders migration to TypeScript * [AI] Add release note for create-folders migration * [AI] Preserve migration titles after TypeScript conversion * [AI] Reject duplicate normalized migration titles --------- Co-authored-by: Baris Arı <[email protected]> Co-authored-by: Baris Ari <[email protected]>
flafleur(22 Sept 26)
[AI] Detect CSV file encoding and add a per-account encoding selector (#8924) * [AI] Detect CSV file encoding and add a per-account encoding selector Read CSV/TSV files as raw bytes and decode them based on the detected encoding instead of always assuming UTF-8: the byte order mark, BOM-less UTF-16 (NUL byte analysis), strict UTF-8 validation, and a windows-1252 fallback that also decodes ISO-8859-1 content. A mostly-valid UTF-8 file with a few corrupted bytes still decodes as UTF-8 with replacement characters instead of falling back to windows-1252. Add an encoding selector to the CSV import options, persisted per account like the delimiter, for files in encodings that cannot be detected automatically (e.g. windows-1250, ISO-8859-2). Adds fixtures and tests for UTF-16 (with and without BOM), UTF-8 with BOM, corrupted UTF-8, NUL-padded UTF-8, and windows-1252 content. Fixes #6327 * Update VRT screenshots Auto-generated by VRT workflow PR: #8924 * Update VRT screenshots Auto-generated by VRT workflow PR: #8924 * [AI] Address review: require dominant NUL parity and translate encoding labels Require one parity to clearly dominate (>= 90% of NUL bytes) before detecting BOM-less UTF-16, so a UTF-8 file with dense contiguous NUL padding (even split across parities) is no longer misdetected as UTF-16. Adds a fixture with padding above the 10% density threshold. Wrap the encoding selector labels in t() per the repository's translated user-facing text requirement. * [AI] Drop iso-8859-1 from the CSV encoding selector TextDecoder resolves the iso-8859-1 label to the windows-1252 decoder per the WHATWG encoding spec, so the option was redundant and could mislead users into expecting true ISO-8859-1 decoding. windows-1252 already covers ISO-8859-1 content; keep the alias accepted in decodeCsvBytes with a clarifying comment and an alias test. * [AI] Make the iso-8859-1 alias test distinguish Windows-1252 The alias test now uses a fixture containing the 0x80 byte, which windows-1252 decodes as the euro sign while a true ISO-8859-1 decoder would produce a C1 control character, so the assertion actually verifies the windows-1252 alias semantics. * [AI] Simplify CSV encoding detection to BOM and explicit selection Follow the review suggestion: the byte order mark selects UTF-16 LE/BE and everything else decodes as UTF-8; other encodings are handled by the manual per-account selector this PR adds. Drop the speculative BOM-less UTF-16, windows-1252 fallback, and corrupted UTF-8 heuristics along with their fixtures and tests. --------- Co-authored-by: François Lafleur <[email protected]> Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
John Costa(21 Sept 26)
[AI] Fix YNAB4 import dropping the parent payee on split children (#8973) * fix YNAB4 import dropping the parent payee on split children YNAB4 stores the payee on the parent transaction only, but the importer spread a `payee: undefined` key onto every non-transfer sub transaction. `makeChild` treats a present key as explicit, so the children never fell back to the parent's payee and showed up with no payee at all. Only emit the key when a payee was actually resolved; transfer children are unchanged. Fixes #3561 * Update packages/loot-core/src/server/importers/ynab4.ts --------- Co-authored-by: Tim <[email protected]>
Michael Clark(21 Sept 26)
:bar_chart: Monte carlo performance improvement (#8988) * improve performance of monte carlo * release notes
John Costa(21 Sept 26)
fix(import): accept "Sept" as a month abbreviation in CSV dates (#8957) The month rewrite in parseDate matched "Sep", "Sep." and "September" but not the four-letter "Sept" that some bank exports use. The word boundary after "sep" failed on the trailing "t", so the month was never converted to a number and every September row was rejected as an invalid date. Extend the regex to also accept "Sept" and "Sept." and cover the DD MMM YY, DD MMM YYYY and MMM DD, YYYY forms in the parseDate table. Closes #8888
Julian Dominguez-Schatz(21 Sept 26)
Retry Weblate repository lock conflicts (#8979) * [AI] Retry Weblate repository lock conflicts * [AI] Add release note for translation retries
Matt Fiddaman(20 Sept 26)
⬆️ better-sqlite3 v13 (#8736) * better-sqlite3 v13 * note * fix build * engine update * fix yarn warning and arm32 docker builds
Michael Clark(20 Sept 26)
:chart_with_upwards_trend: Monte carlo -Warn when contribution is too large (#8971) * warn when monte carlo contribution is too large * feedback
Matt Fiddaman(19 Sept 26)
add account hover card (#8969) * add account hover card * add context menus * note * generalise touch helper * coderabbit
Matt Fiddaman(19 Sept 26)
sidebar pt. 5: account search (#8914) * filter helper * add search * note * review improvements
Spaghettio73(19 Sept 26)
docs: add receipt2actual and actual2ics to Community Projects (#8945)
Michael Clark(18 Sept 26)
:bug: Monte carlo cashflow chart underfunding fix (#8964) * fix underfunded gap amount when using withdrawal rules and min spending amount * release notes
Terry Lockett(18 Sept 26)
fix ToBudget actions not showing in firefox (#8958)
Michael Clark(18 Sept 26)
:hedgehog: Speeding up large budgets by only running rules when needed (#8946) * optimise transactions edits/deletes by making the running balance query find applicable rules first, and only run if required * balance now fetched at most once and only for a rule whos conditions matched
Michael Clark(18 Sept 26)
:chart_with_upwards_trend: Monte Carlo income streams (#8955) * monte carlo income streams * simplify release note * enhancement * fix withdrawal rule floor when income is specified * update screenshots * suplus pot and images * way better description in the run details * covering case where income is all thats setup and spending is the same as the income * feedback * screenshots and rename of minimum withdrawal to min spending * additional docs
Stephen Brown II(18 Sept 26)
[AI] Show a progress bar while importing a YNAB budget (#8956) * [AI] Show a progress bar while importing a YNAB budget * [AI] Name the account in transaction import progress * [AI] Defer scheduled import progress until rule updates finish Change-Id: rnuttktwqnkslztsvklpqxvnwnvqvopy * [AI] Prevent dismissing an import while it is running Change-Id: tnwzlovsmtsqwtkxorqnymtxvwuyrsvk * [AI] Subscribe to import progress before importing Change-Id: kwnmmmslpoxpxrmpzltnwsrqvuryzous
Michael Clark(17 Sept 26)
:hedgehog: Make saving transaction edits slightly faster on big budgets (#8944) * increasing cache size, wrap updatetransactions in one transaction to reduce number * rabbit feedback
J-LCRX(16 Sept 26)
[AI] Rank exact payee matches above tied substring matches (#8811) * [AI] Rank exact payee matches above tied substring matches fzf's tiebreakers default to none, so when two suggestions tie on match score (e.g. querying 'Amazon' against both 'Amazon' and 'Amazon Prime'), the ranking falls back to original array order instead of favoring the exact match. useTags.ts already fixes this for tag filtering via tiebreakers: [byLengthAsc, byStartAsc]; this applies the same fix to payee autocomplete matching. Split out from the combined payee/category fix on fix/exact-match-tiebreak-scoring — the category half is intentionally not carried over, since category suggestions are meant to stay ordered the way they appear within the budget arrangement. * [AI] Use alphabetically-ordered payee names in exact-match tiebreak test 'Amazon Prime'/'Amazon' needed to be listed out of alpha order to demonstrate the bug, which doesn't match how the payee list is naturally sorted. 'AAA Google'/'Google' demonstrates the same fix while staying in alpha order like the rest of the suite. Co-Authored-By: Claude Sonnet 5 <[email protected]> --------- Co-authored-by: Claude Sonnet 5 <[email protected]>
Stephen Brown II(15 Sept 26)
[AI] fix(sync): receive only the latest timestamp to stop counter overflow (#8706) * [AI] fix(sync): receive only the latest timestamp to stop counter overflow Timestamp.recv was called once per incoming message. Each call burns one tick of the 16-bit HLC counter whenever the logical clock does not advance, and the counter only resets when Date.now() moves forward. Browsers that coarsen Date.now() (LibreWolf, or Firefox with resistFingerprinting, which rounds it to 100ms) give the loop enough time to pass 65535 messages in a single tick, so a large sync throws OverflowError and the budget never opens. Receive only the highest incoming timestamp instead. The clock lands in the same place, the drift check still sees the furthest-ahead message, and the counter advances once per batch. * [AI] fix(sync): address timestamp review feedback Change-Id: oowtnqoxrmltvupuxowqqnnynnqwkxqx
Michael Clark(15 Sept 26)
:electron: When data folder is unavailable show a friendly message (#8928) * when data folder is unavailable due to permissions etc, show a friendly prompt * feedback from rabbit
danielcovill(15 Sept 26)
Tips tricks docs fix (#8940) * Update tips-tricks.md Correct out of date documentation. * Add release notes * Clearer writing, filename fix for release notes
Matiss Janis Aboltins(13 Sept 26)
[AI] Warn API users about deferred sync messages and fix stale docs row (#8925) Co-authored-by: Claude Fable 5.1 <[email protected]>
Albert Bendicho(13 Sept 26)
Update enable-banking.md Clarify needed steps (#8821) * Clarify enable-banking.md steps It seems to be a common problem people face that they skip the `Link the accounts you want in the Enable Banking interface` https://github.com/actualbudget/actual/issues/7799#issuecomment-4433943297 https://github.com/actualbudget/actual/issues/7799#issuecomment-4629194825 https://github.com/actualbudget/actual/issues/7799#issuecomment-4641704020 https://github.com/actualbudget/actual/issues/7799#issuecomment-4477748895 https://github.com/actualbudget/actual/issues/7799#issuecomment-4488926240 https://github.com/actualbudget/actual/issues/7799#issuecomment-4511171800 https://github.com/actualbudget/actual/issues/7799#issuecomment-4641704020 * [autofix.ci] apply automated fixes * coderabbitai requested improvements * [autofix.ci] apply automated fixes --------- Co-authored-by: autofix-ci[bot] <114827586+autofix-ci[bot]@users.noreply.github.com>
Amy Hawkins(13 Sept 26)
[AI] Fix missing vite-plugin-peggy workspace in sync-server.Dockerfile (#8798) * [AI] Fix missing vite-plugin-peggy workspace in sync-server.Dockerfile The deps stage copies each workspace's package.json individually for Docker layer caching, but packages/vite-plugin-peggy/package.json was never added to that list even though loot-core and api both depend on it via workspace:*, so yarn install fails resolution with Workspace not found. Add the missing COPY line. Co-Authored-By: Claude Sonnet 5 <[email protected]> * release note --------- Co-authored-by: Amy Hawkins <[email protected]> Co-authored-by: Claude Sonnet 5 <[email protected]>
Sreetam Das(13 Sept 26)
[AI] Add Karma to the custom theme catalog (#8930) * [AI] Add Karma to the custom theme catalog Karma is a dark theme for Actual Budget. The CSS is hosted at sreetamdas/karma/actual.css and every --color-* token is mapped from the canonical Karma palette, so the theme stays in step with the Karma ports for VS Code, Zed and iTerm. Colors are the six representative hues for the catalog swatch: the near-black background, the purple primary accent, and the green/pink/orange/cyan accents. * [AI] Add release note for the Karma theme
Krzysztof Wójt(13 Sept 26)
[AI] Expose parent transaction fields to split rule formulas (#8898) * [AI] Expose parent transaction text to split rule formulas * [AI] Categorize split parent context as an enhancement
dependabot[bot](12 Sept 26)
Bump @vitest/mocker from 4.1.10 to 5.0.0 in the npm_and_yarn group across 0 directory (#8923) * Bump @vitest/mocker in the npm_and_yarn group across 0 directory Updates `@vitest/mocker` from 4.1.10 to 5.0.0 - [Release notes](https://github.com/vitest-dev/vitest/releases) - [Changelog](https://github.com/vitest-dev/vitest/blob/main/docs/releases.md) - [Commits](https://github.com/vitest-dev/vitest/commits/v5.0.0/packages/mocker) --- updated-dependencies: - dependency-name: "@vitest/mocker" dependency-version: 5.0.0 dependency-type: indirect dependency-group: npm_and_yarn ... Signed-off-by: dependabot[bot] <[email protected]> * [AI] Fix typecheck failures under vitest 5 Vitest 5 changed two things that broke the typecheck/build jobs: - `vi.fn()`'s inferred type now references `Procedure` from an internal vitest chunk that cannot be named from outside, so the hoisted mocks in `cloud-storage.test.ts` tripped TS2883. Annotate them as `Mock`. - The `expect` package was inlined and the global `jest.Matchers` declaration dropped, so `@testing-library/jest-dom`'s default entry no longer augments vitest's `Assertion`. Use the `/vitest` entry point instead. Co-Authored-By: Claude Opus 5 <[email protected]> Claude-Session: https://claude.ai/code/session_01Bvwt76cXUoLwfHiy1jhToc * [AI] Bump @actual-app/crdt to 3.1.3 The dependency bump touches packages/crdt/package.json, so the CRDT version bump check requires a new version. Matches how the previous dependabot group bump (#8921) was handled. Co-Authored-By: Claude Opus 5 <[email protected]> Claude-Session: https://claude.ai/code/session_01Bvwt76cXUoLwfHiy1jhToc * [AI] Add release note for the vitest bump Co-Authored-By: Claude Opus 5 <[email protected]> Claude-Session: https://claude.ai/code/session_01Bvwt76cXUoLwfHiy1jhToc --------- Signed-off-by: dependabot[bot] <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: MatissJanis <[email protected]> Co-authored-by: Claude Opus 5 <[email protected]>
Fabian Markert(12 Sept 26)
[AI] Fix character encoding corruption when importing CAMT files (#8912) (#8913)
Tim(11 Sept 26)
[AI] Fix theme colour ordering and custom theme refresh (#8922) * [AI] Fix theme colour ordering and custom theme refresh * Apply suggestion from @tim-smart
Actual Security
Security Advisories (14)
- lowPatched
CVE-2026-57449CORS Proxy GitHub API Allowlist Prefix Bypass Leaks Private Repositories Through the Server GitHub Token
- highPatchedCVSS 8.3
CVE-2026-49229Disabled OpenID users keep access through existing session tokens
- mediumPatchedCVSS 4.2
CVE-2026-50179CSV Formula Injection in Transaction Export via Imported Payee/Notes Fields
- mediumPatchedCVSS 4.3
CVE-2026-46700Missing authorization on GET /secret/:name allows non-admin OpenID users to enumerate admin-configured bank-sync secrets
- mediumPatchedCVSS 4.6
CVE-2026-46672CSV Formula Injection in `@actual-app/cli` `--format csv` Output via Custom `escapeCsv` Helper
- mediumPatched
CVE-2026-42890Electron Run As Node in actual
- highPatched
CVE-2026-42604OpenID `client_secret` Disclosure via Broken Authorization Guard in `/openid/config`
- highPatched
CVE-2026-50007Shared users can perform owner-only file management actions
- mediumPatched
CVE-2026-43872Path traversal vulnerability in actual-server
- highPatchedCVSS 8.8
CVE-2026-33318Privilege Escalation via 'change-password' Endpoint on OpenID-Migrated Servers
- mediumPatched
CVE-2026-3089Actual Sync Server 26.2.1 - Authenticated Path Traversal
- criticalPatched
CVE-2026-27584Missing Authentication for SimpleFIN and Pluggy AI bank sync endpoints
- highPatched
CVE-2026-27638Missing authorization in sync endpoints allows cross-user budget file access in multi-user mode
- mediumPatchedCVSS 4.2
GHSA-xvp7-8vm8-xfxxGocardless service is logging sensitive data including bearer tokens, account numbers, etc...
Actual Website
Website
Your Finances — made simple | Actual Budget
Actual Budget is a super fast and privacy-focused app for managing your finances. At its heart is the well proven and much loved Envelope Budgeting methodology.
Redirects
Does not redirect
Security Checks
All 65 security checks passed
Server Details
- IP Address98.84.224.111
- Hostnameec2-98-84-224-111.compute-1.amazonaws.com
- LocationAshburn,Virginia,United States of America,NA
- ISPAmazon Technologies Inc.
- ASNAS14618
Associated Countries
US
Safety Score
Website marked as safe
100%
Blacklist Check
actualbudget.org was found on 0 blacklists
- AntiSocial Blacklist
- Artists Against 419
- Badbitcoin
- Bambenek Consulting
- CERT Polska
- CoinBlockerLists
- CRDF
- CryptoScamDB
- EtherAddressLookup
- EtherScamDB
- Fake Website Buster
- MetaMask EthPhishing
- NABP Not Recommended Sites
- OpenPhish
- PetScams
- PhishFeed
- PhishFort
- Phishing.Database
- PhishStats
- PhishTank
- Phishunt
- RPiList Not Serious
- Scam.Directory
- SecureReload Phishing List
- Spam404
- StopGunScams
- Suspicious Hosting IP
- ThreatFox
- ThreatLog
- TweetFeed
- URLhaus
- ViriBack C2 Tracker
Website Preview
Actual Docker
Container Info
actual
Actual is a super fast privacy-focused app for managing your finances.
Run Command
docker run -d \
Compose File
version: 3.8
Actual Socials
Actual Reviews
More Secure Budgeting
Privacy-first cross-platform personal expense tracker (Android/iOS/Web) with offline-first design. Multi-cloud sync options — self-hosted BeeCount Cloud, iCloud, Supabase, WebDAV or S3 — keep data under user control.
A lightweight, self-hosted personal finance app for recording daily transactions and analyzing spending patterns. Self-hosted, with all data staying on your own server. Supports 2FA and OICD.
A free and open source personal finance manager. Firefly III features a clean and clear UI, is easy to set up and use, and is backed by a strong community. Regular updates bring new features, improvements, and fixes. There's also a hass.io addon, and compatibility with Home Assistant. Ensure your server is securely configured.
A full-featured cross-platform accounting application suitable for personal and small business finance. Stable and reliable, GnuCash offers a comprehensive suite of financial management tools. Available for Windows, Mac, Linux, and Android.
Utilizes plain text files and scriptable, command-line-friendly software for bookkeeping/accounting, offering full control over data. Popular tools include Ledger, hledger, and Beancount among others, providing a flexible and vendor-independent approach to accounting.
A self-hosted, opensource, privacy-first portfolio tracking and accounting tool for crypto and more. Support for all 3 major Operating systems and docker. The tool focus is on data self-sovereignty.
About the Data: Actual
Change History
- Added #364
Edit Actual Data
You can edit Actual's entry in this section of awesome-privacy.yml by submitting a PR to our GitHub repo.
Note that some of the information shown above has been aggregated from external
sources, a list of these can be found data documentation.
Origin Data
Modify Data
API
You can access Actual's data programmatically via our API. Simply make a GET request to:
https://api.awesome-privacy.xyz/v1/services/actualThe REST API is free, no-auth and CORS-enabled. To learn more, view the API Docs or read the API Usage Guide.
Share Actual
Help your friends compare Secure Budgeting, and pick privacy-respecting software and services.
Share Actual and Awesome Privacy with your network!