Firefly III

firefly-iii.org
Firefly III

A free and open source personal finance manager. Firefly III features a clean and clear UI, is easy to set up and use, and is backed by a strong community. Regular updates bring new features, improvements, and fixes. There's also a hass.io addon, and compatibility with Home Assistant. Ensure your server is securely configured.

Open Source

Firefly III Source Code

Author

firefly-iii

Description

Firefly III: a personal finances manager

#accounting#budget#budgeting#budgets#cash-flow#cashflow#credit-card#docker#expenses#finance#finances#financial#linux#money#paycheck#personal-finance#php#php7

Homepage

https://firefly-iii.org/

Repository

  • LicenseAGPL-3.0
  • Created28 Jun 14
  • Primary languagePHP
  • Size318,779 KB
  • Stars24,347
  • Forks2,254
  • Watchers24,347

Language Usage

Language Usage

Project Health

  • Last commit3 days ago
  • Open issues163
  • Latest releasev6.6.6

Recent Commits

  • James Cole(10 Aug 26)

    No longer build v1, remove some old code.

  • James Cole(09 Aug 26)

    Fix sponsorship

  • James Cole(07 Aug 26)

    Rename workflow from 'Create new release' to 'Run CI' Signed-off-by: James Cole <[email protected]>

  • James Cole(07 Aug 26)

    Create run-ci.yml Signed-off-by: James Cole <[email protected]>

  • James Cole(07 Aug 26)

    Delete .github/workflows/psalm.yml Signed-off-by: James Cole <[email protected]>

  • James Cole(07 Aug 26)

    Delete .github/workflows/sonarcloud.yml Signed-off-by: James Cole <[email protected]>

  • James Cole(07 Aug 26)

    Update Psalm Security Scan action version Signed-off-by: James Cole <[email protected]>

  • James Cole(07 Aug 26)

    Update sonarcloud.yml Signed-off-by: James Cole <[email protected]>

  • James Cole(07 Aug 26)

    Merge pull request #12585 from firefly-iii/dependabot/composer/composer-252f2de36c Bump league/commonmark from 2.8.2 to 2.9.0 in the composer group across 1 directory

  • dependabot[bot](07 Aug 26)

    Bump league/commonmark in the composer group across 1 directory Bumps the composer group with 1 update in the / directory: [league/commonmark](https://github.com/thephpleague/commonmark). Updates `league/commonmark` from 2.8.2 to 2.9.0 - [Release notes](https://github.com/thephpleague/commonmark/releases) - [Changelog](https://github.com/thephpleague/commonmark/blob/2.9/CHANGELOG.md) - [Commits](https://github.com/thephpleague/commonmark/compare/2.8.2...2.9.0) --- updated-dependencies: - dependency-name: league/commonmark dependency-version: 2.9.0 dependency-type: direct:production dependency-group: composer ... Signed-off-by: dependabot[bot] <[email protected]>

  • James Cole(07 Aug 26)

    Update SonarCloud action to use sonarqube-scan-action Signed-off-by: James Cole <[email protected]>

  • James Cole(06 Aug 26)

    Modify SonarCloud analysis workflow configuration Updated SonarCloud workflow to specify project key and organization. Signed-off-by: James Cole <[email protected]>

  • James Cole(04 Aug 26)

    Merge pull request #12573 from firefly-iii/dependabot/npm_and_yarn/npm_and_yarn-84557ebc70 Bump brace-expansion from 1.1.15 to 1.1.18 in the npm_and_yarn group across 1 directory

  • dependabot[bot](04 Aug 26)

    Bump brace-expansion in the npm_and_yarn group across 1 directory Bumps the npm_and_yarn group with 1 update in the / directory: [brace-expansion](https://github.com/juliangruber/brace-expansion). Updates `brace-expansion` from 1.1.15 to 1.1.18 - [Release notes](https://github.com/juliangruber/brace-expansion/releases) - [Commits](https://github.com/juliangruber/brace-expansion/compare/v1.1.15...v1.1.18) --- updated-dependencies: - dependency-name: brace-expansion dependency-version: 1.1.18 dependency-type: indirect dependency-group: npm_and_yarn ... Signed-off-by: dependabot[bot] <[email protected]>

  • James Cole(04 Aug 26)

    Merge pull request #12571 from firefly-iii/dependabot/composer/composer-c0cb037752 Bump guzzlehttp/guzzle from 7.15.1 to 7.15.2 in the composer group across 1 directory

  • dependabot[bot](04 Aug 26)

    Bump guzzlehttp/guzzle in the composer group across 1 directory Bumps the composer group with 1 update in the / directory: [guzzlehttp/guzzle](https://github.com/guzzle/guzzle). Updates `guzzlehttp/guzzle` from 7.15.1 to 7.15.2 - [Release notes](https://github.com/guzzle/guzzle/releases) - [Changelog](https://github.com/guzzle/guzzle/blob/7.15.2/CHANGELOG.md) - [Commits](https://github.com/guzzle/guzzle/compare/7.15.1...7.15.2) --- updated-dependencies: - dependency-name: guzzlehttp/guzzle dependency-version: 7.15.2 dependency-type: direct:production dependency-group: composer ... Signed-off-by: dependabot[bot] <[email protected]>

  • James Cole(03 Aug 26)

    Merge pull request #12565 from firefly-iii/dependabot/github_actions/actions/stale-11 Bump actions/stale from 10 to 11

  • dependabot[bot](03 Aug 26)

    Bump actions/stale from 10 to 11 Bumps [actions/stale](https://github.com/actions/stale) from 10 to 11. - [Release notes](https://github.com/actions/stale/releases) - [Changelog](https://github.com/actions/stale/blob/main/CHANGELOG.md) - [Commits](https://github.com/actions/stale/compare/v10...v11) --- updated-dependencies: - dependency-name: actions/stale dependency-version: '11' dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <[email protected]>

  • James Cole(30 Jul 26)

    Set timezone to Europe/Amsterdam in release workflow Signed-off-by: James Cole <[email protected]>

  • James Cole(27 Jul 26)

    Merge pull request #12533 from firefly-iii/dependabot/npm_and_yarn/npm_and_yarn-ca68f6365a Bump svgo from 2.8.2 to 2.8.3 in the npm_and_yarn group across 1 directory

  • dependabot[bot](27 Jul 26)

    Bump svgo in the npm_and_yarn group across 1 directory Bumps the npm_and_yarn group with 1 update in the / directory: [svgo](https://github.com/svg/svgo). Updates `svgo` from 2.8.2 to 2.8.3 - [Release notes](https://github.com/svg/svgo/releases) - [Commits](https://github.com/svg/svgo/compare/v2.8.2...v2.8.3) --- updated-dependencies: - dependency-name: svgo dependency-version: 2.8.3 dependency-type: indirect dependency-group: npm_and_yarn ... Signed-off-by: dependabot[bot] <[email protected]>

  • James Cole(27 Jul 26)

    Merge pull request #12525 from firefly-iii/dependabot/npm_and_yarn/npm_and_yarn-c2e2e76f30 Bump the npm_and_yarn group across 1 directory with 2 updates

  • dependabot[bot](25 Jul 26)

    Bump the npm_and_yarn group across 1 directory with 2 updates Bumps the npm_and_yarn group with 2 updates in the / directory: [postcss](https://github.com/postcss/postcss) and [fast-uri](https://github.com/fastify/fast-uri). Updates `postcss` from 8.5.16 to 8.5.23 - [Release notes](https://github.com/postcss/postcss/releases) - [Changelog](https://github.com/postcss/postcss/blob/main/CHANGELOG.md) - [Commits](https://github.com/postcss/postcss/compare/8.5.16...8.5.23) Updates `fast-uri` from 3.1.3 to 3.1.4 - [Release notes](https://github.com/fastify/fast-uri/releases) - [Commits](https://github.com/fastify/fast-uri/compare/v3.1.3...v3.1.4) --- updated-dependencies: - dependency-name: postcss dependency-version: 8.5.23 dependency-type: direct:development dependency-group: npm_and_yarn - dependency-name: fast-uri dependency-version: 3.1.4 dependency-type: indirect dependency-group: npm_and_yarn ... Signed-off-by: dependabot[bot] <[email protected]>

  • James Cole(21 Jul 26)

    Merge pull request #12517 from firefly-iii/dependabot/composer/composer-a2cf776ffc Bump guzzlehttp/guzzle from 7.13.1 to 7.15.1 in the composer group across 1 directory

  • dependabot[bot](21 Jul 26)

    Bump guzzlehttp/guzzle in the composer group across 1 directory Bumps the composer group with 1 update in the / directory: [guzzlehttp/guzzle](https://github.com/guzzle/guzzle). Updates `guzzlehttp/guzzle` from 7.13.1 to 7.15.1 - [Release notes](https://github.com/guzzle/guzzle/releases) - [Changelog](https://github.com/guzzle/guzzle/blob/8.0/CHANGELOG.md) - [Commits](https://github.com/guzzle/guzzle/compare/7.13.1...7.15.1) --- updated-dependencies: - dependency-name: guzzlehttp/guzzle dependency-version: 7.15.1 dependency-type: direct:production dependency-group: composer ... Signed-off-by: dependabot[bot] <[email protected]>

  • James Cole(16 Jul 26)

    Change workflow a little.

  • James Cole(11 Jul 26)

    Fix quick build.

  • James Cole(11 Jul 26)

    Fix more steps.

  • James Cole(11 Jul 26)

    Fix var

  • James Cole(11 Jul 26)

    Another attempt.

Firefly III Security

4.6/10

Repo Security Summary

Updated 27 Jul 26

  • Code-Review0/10
  • Maintained10/10
  • Token-PermissionsN/A
  • PackagingN/A
  • Dangerous-WorkflowN/A
  • CII-Best-Practices2/10
  • Security-Policy0/10
  • Binary-Artifacts10/10
  • License10/10
  • Pinned-DependenciesN/A
  • Branch-Protection3/10
  • Signed-Releases8/10
  • Fuzzing0/10
  • SAST0/10

Security Advisories (4)

  • mediumPatched

    GHSA-6jq6-x4cx-qvcmStored XSS in Audit Log Entry view via piggy bank name (ale.twig)

  • lowPatched

    GHSA-5q8v-j673-m5v4User API endpoints expose all users' information to any authenticated user (IDOR)

  • mediumPatched

    CVE-2024-37893MFA bypass in oauth flow

  • mediumPatchedCVSS 4

    GHSA-29w6-c52g-m8jcC5 Firefly III 6.1.6 CSV Injection.

Firefly III Website

Website

Firefly III - A free and open source personal finance manager

Firefly III

Redirects

Does not redirect

Security Checks

All 65 security checks passed

Server Details

  • IP Address172.67.137.142
  • LocationSan Francisco,California,United States of America,NA
  • ISPCloudFlare Inc.
  • ASNAS13335

Associated Countries

  • USUS
  • DEDE

Safety Score

Website marked as safe

100%

Blacklist Check

www.firefly-iii.org was found on 0 blacklists

  • AntiSocial Blacklist
  • Artists Against 419
  • Badbitcoin
  • Bambenek Consulting
  • CERT Polska
  • CoinBlockerLists
  • CRDF
  • CryptoScamDB
  • EtherAddressLookup
  • EtherScamDB
  • Fake Website Buster
  • MetaMask EthPhishing
  • NABP Not Recommended Sites
  • OpenPhish
  • PetScams
  • PhishFeed
  • PhishFort
  • Phishing.Database
  • PhishStats
  • PhishTank
  • Phishunt
  • RPiList Not Serious
  • Scam.Directory
  • SecureReload Phishing List
  • Spam404
  • StopGunScams
  • Suspicious Hosting IP
  • ThreatFox
  • ThreatLog
  • TweetFeed
  • URLhaus
  • ViriBack C2 Tracker

Website Preview

Website preview

Firefly III Reviews

More Secure Budgeting

About the Data: Firefly III

Edit Firefly III Data

You can edit Firefly III's entry in this section of awesome-privacy.yml by submitting a PR to our GitHub repo.
Note that some of the information shown above has been aggregated from external sources, a list of these can be found data documentation.

Origin Data

Modify Data

API

You can access Firefly III's data programmatically via our API. Simply make a GET request to:

https://api.awesome-privacy.xyz/v1/services/firefly-iii

The REST API is free, no-auth and CORS-enabled. To learn more, view the API Docs or read the API Usage Guide.

Share Firefly III

Help your friends compare Secure Budgeting, and pick privacy-respecting software and services.
Share Firefly III and Awesome Privacy with your network!