Follow visits as they happen
See live visitors, pageviews, sessions, pages per visit, session duration and bounce rate. The WordPress Overview tab shows key metrics; live counts describe aggregate traffic without identifying WordPress user accounts.
DevDome Analytics tracks visitors, traffic sources and outbound clicks, with known bots reported separately from human traffic. Connect a free DevDome account to see key metrics inside WordPress and detailed reports in your hosted dashboard.
Free and GPL licensed, reviewed by the WordPress.org plugin team.
Review visitors, pages, traffic sources and outbound clicks, with detected crawlers counted separately. Key metrics appear inside WordPress, while your DevDome account holds the detailed reports.
See live visitors, pageviews, sessions, pages per visit, session duration and bounce rate. The WordPress Overview tab shows key metrics; live counts describe aggregate traffic without identifying WordPress user accounts.
Review visits, visitors, pageviews, referrers and outbound clicks for individual pages and posts. These counters belong to your private analytics reports; the plugin does not provide a public counter widget.
See known bots and AI crawlers separately from human visitors, including GPTBot, ClaudeBot and Googlebot. Unknown, new or deliberately disguised bots may escape detection. The plugin reports detected crawlers but does not block them.
Review traffic sources and referrers to see how visitors reach your pages. With Track AI Referrals enabled, visits from supported assistants, including ChatGPT and Perplexity, are identified separately from other sources.
Track outbound clicks on affiliate links, partner websites and social profiles, with optional relay through your WordPress server. While Track Clicks is on, site searches are also recorded, with terms limited to 200 characters.
General analytics are cookieless by default, with Track Returning Visitors disabled by default. Enabling it uses cookies and browser storage and may need visitor consent. Exclude WordPress roles and respect Do Not Track.
Analytics events are processed by the hosted DevDome service, with a free account required. Your WordPress database holds settings and temporary caches, but no custom analytics tables or stored analytics events.
First-Party Delivery serves the script from your domain and relays events through your WordPress server on supported DevDome plans. It can reduce losses from ad blockers, but cannot guarantee that every visit is counted.
Install the plugin, connect your free DevDome account and choose your tracking settings. No visitor data is collected until your site is connected.
Install DevDome Analytics from WordPress.org through Plugins > Add New, then activate it and open DevDome > Analytics.
Select Connect Via DevDome Account and approve the connection on devdome.com. A free DevDome account is required to process analytics events and generate reports.
Review the Settings tab and enable only the tracking features you want. View key metrics in Overview and detailed reports in your DevDome account.
Yes, a free DevDome account is required. The plugin connects WordPress to the hosted DevDome Analytics service, which processes events and displays full reports. A free plan is available. First-Party Delivery is available on supported plans.
No visitor data is sent, and the tracking script is not added. Opening the plugin screen can send your domain and secret token for a connection-status check. The DevDome Dashboard requests the plugin catalog with only the bundled core version. Error reports are sent only when you press Report this error.
General analytics are cookieless by default. Enabling Track Returning Visitors stores random identifiers in a cookie, localStorage and sessionStorage, and may need visitor consent. With it off, outbound-click identifiers stay in memory for the current page. Upgrading sites retain their previous returning-visitor setting.
No. Known bots and AI crawlers are reported separately from human visitors, but unknown, new or deliberately disguised bots may escape detection. The plugin reports detected crawlers; it does not block them.
Yes. Do Not Track Admins excludes logged-in administrators by default, and new installations also exclude the Editor role. You can exclude additional WordPress roles. Respect Do Not Track is on by default and honours the browser signal.
The tracking script loads asynchronously without blocking page rendering, and the plugin does not store analytics events in your WordPress database. The tracking snippet is the same for every visitor, so it works with full-page caching. Connecting or disconnecting clears common page caches.
Events include page URLs, titles, referrers, browser and device details, country and click destinations. Site search terms are sent while tracking and Track Clicks are enabled. Visitor IP addresses reach DevDome for location and visitor counts. The plugin does not collect post content, WordPress user accounts, customer data, order data or wp-admin activity.
Disconnecting stops tracking and outbound-click relaying. To delete collected data, press Reset Analytics or select Also delete my data on DevDome while disconnecting. Otherwise, DevDome deletes it after 90 days of inactivity. The plugin stores no analytics events locally.
Everything you need before you install, with no account required.
Install DevDome Analytics from WordPress.org (Plugins, Add New, search for DevDome Analytics) or upload the ZIP, then activate it.
A free DevDome account is required to process analytics events and generate hosted reports. No visitor data is collected until you connect the site.
Open DevDome > Analytics in the WordPress admin menu. Select Connect Via DevDome Account and approve the connection on devdome.com. The Overview tab shows key metrics, including live visitors; your DevDome account provides the full reports.
Review the Settings tab and enable only the features you want. Enable Tracking is the master switch. Track Clicks, Track Outbound Links, Track AI Referrals and Track Bot Visits can each be switched off independently. Administrators and editors are excluded on new installations, additional roles can be excluded, and Respect Do Not Track is on by default.
General analytics are cookieless by default on new installations. Track Returning Visitors is initially off; enabling it stores a random visitor ID in a first-party cookie and localStorage, plus a session ID in sessionStorage, and may require visitor consent. Sites upgrading from an earlier version keep returning-visitor tracking on until you change it.
Your WordPress database holds settings, service addresses, site and account identifiers, the site secret token, account email and connection timestamp. First-Party Delivery also stores generated path and file names and, on sites set up by DevDome, a relay credential. Temporary caches hold connection, bot-count, plan and rate-limit information; rate-limit counters use a hash of the visitor's IP address. There are no custom analytics tables or locally stored analytics events. First-Party Delivery copies the bundled tracking script and bot detector into your uploads folder.
analytics.devdome.com provides the tracking script and receives analytics events once the site is connected and tracking is enabled. Browser events carry the Site ID, Account ID, page URL and path, page title, referring URL, browser, operating system, device type, user agent, browser language, screen size, time zone, country, click target URL, browser automation flag and bot-detector verdict. Click targets on your own site omit the query string. Events include the AI-referrer flag while Track AI Referrals is on, visitor and session IDs when the browser stores them, and site-search terms of up to 200 characters while tracking and click tracking are enabled. Direct browser requests expose the visitor's IP address to the service.
Outbound clicks relayed through /dd-e add the visitor's country code and IP address. With First-Party Delivery enabled, the scripts are served from your domain and tracking events pass through a randomized local path to analytics.devdome.com, authenticated with the site secret token; the relay also adds the visitor's country code and IP address. Known-crawler events sent by your server while Track Bot Visits is on contain the crawler user agent, bot name and type, requested URL and path, Site ID and timestamp.
analytics.devdome.com also handles connection, report and data-management requests. The connection handshake sends the Site ID, secret token, Account ID, site URL and name, administrator email, WordPress, PHP and plugin versions, active theme name, timezone, site language and multisite status. Opening the plugin screen can send a shorter status check with only the Site ID and secret token, at most once every 15 minutes, including before connection. Pressing Connect Via DevDome Account sends the domain, secret token and return admin address to obtain a short-lived link; returning from approval exchanges that link for the Account ID. Stats requests send the Site ID, token and selected day range. First-Party Delivery eligibility checks send the Site ID and token on connected sites. Reset Analytics, or disconnecting with "Also delete my data on DevDome" selected, sends the Site ID and token to the purge endpoint.
api.devdome.com provides account checks and disconnection. Account checks send the domain and secret token and return the Account ID and account email; they begin only after you start or complete a connection or save an Account ID. Connecting through the DevDome Tools dashboard card that discloses plugin sharing also enables transmission of active DevDome plugin slugs and versions, the bundled library version, and WordPress and PHP versions. Existing connections and connections through buttons without that disclosure do not send the plugin list. Disconnecting sends the domain and secret token and stops plugin-list sharing. The bundled bot-protection signature feeds and self-hosted update endpoints are not contacted by this build.
devdome.com serves the DevDome Dashboard plugin catalog, requested at most once every 12 hours with only the bundled core version. Pressing "Report this error" sends the error text, plugin, WordPress and PHP versions, current screen, connection flags and timestamps with secrets masked, site address and administrator email to devdome.com. The browser also visits devdome.com/connect/ when you follow the connection link to sign in and approve access.
With Track Returning Visitors off, outbound-link identifiers remain in memory for the current page. With it on, identifiers use browser storage and up to 50 events interrupted by network failures can be queued in localStorage for the next page load. DevDome uses visitor IP addresses for geolocation and visitor counts; readable visitor IP addresses are not stored on your site. Passwords, WordPress content, registered-user lists, customer, order and payment data are not sent. Visitor form values are not collected except for the site-search terms described above.
Updates come from WordPress.org like any other directory plugin; the bundled library's self-hosted update endpoint is disabled in this build.
Uninstalling removes the scheduled refresh event and generated First-Party Delivery JavaScript files. The relay credential is removed when Delete data on uninstall is enabled. A hidden old plugin folder left by a folder-ownership repair and its fingerprint option can remain; your server administrator can remove the folder. Deleting the plugin does not itself purge hosted analytics: use Reset Analytics or select "Also delete my data on DevDome" when disconnecting. Otherwise, hosted data is deleted after 90 days of inactivity.
Your own visits may be excluded: Do Not Track Admins is on by default, new installations exclude administrators and editors, and Respect Do Not Track honours the browser signal. Check these settings and the excluded roles when reviewing missing visits.
Bots can still appear in visitor reports if they are unknown, new or deliberately disguised. The plugin separates detected bots and AI crawlers from human traffic, but it reports crawlers without blocking them.
A returning visitor can count as new the next day while Track Returning Visitors is off because the service uses an identifier that changes daily. Enabling the setting recognises visitors across days using browser storage and may require consent.
On multisite, connect each site from its own Analytics screen. Subdomain and mapped-domain sites have separate Site IDs and reports. Subdirectory sites share the main domain, Site ID, secret token and report; connecting or disconnecting there requires a network administrator.
Still stuck? Ask on the WordPress.org support forum or use the DevDome contact form. For a security problem, use the Report a security issue tab instead.
Read from the live release feed, so it always describes the version you can download today. The two latest versions are shown here; the full history is on WordPress.org.
Please tell us before telling anyone else, and we will fix it and credit you if you want the credit. Use the contact form and say it is a security report, so it gets read first.
We are a small team, so we will not pretend to a 24/7 security desk or a guaranteed response time. We will read it, reply, and tell you honestly what we are doing about it.
Install DevDome Analytics from WordPress.org, connect a free DevDome account and choose the tracking features you want.