{"id":361489,"date":"2026-09-07T14:47:49","date_gmt":"2026-09-07T14:47:49","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/convertdash-analytics\/"},"modified":"2026-09-11T19:44:29","modified_gmt":"2026-09-11T19:44:29","slug":"convertnow-analytics","status":"publish","type":"plugin","link":"https:\/\/uk.wordpress.org\/plugins\/convertnow-analytics\/","author":23273719,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"1.3.0","stable_tag":"1.3.0","tested":"7.1","requires":"6.2","requires_php":"7.4","requires_plugins":null,"header_name":"ConvertNow Analytics","header_author":"Prateek Zare","header_description":"Analytics built for people who publish. See which authors, posts and content types earn traffic, computed entirely on your own database. Cookieless, self hosted, no external services, no paywall.","assets_banners_color":"cedff5","last_updated":"2026-09-11 19:44:29","external_support_url":"","external_repository_url":"","donate_link":"https:\/\/paypal.me\/prateekzare16","header_plugin_uri":"https:\/\/convertnow.tools\/convertnow-analytics\/","header_author_uri":"https:\/\/profiles.wordpress.org\/prateekzare\/","rating":0,"author_block_rating":0,"active_installs":0,"downloads":353,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"1.0.0":{"tag":"1.0.0","author":"prateekzare","date":"2026-09-07 16:36:31","revision":3685285},"1.1.0":{"tag":"1.1.0","author":"prateekzare","date":"2026-09-07 21:04:52","revision":3685597},"1.1.1":{"tag":"1.1.1","author":"prateekzare","date":"2026-09-08 09:02:31","revision":3686249},"1.2.0":{"tag":"1.2.0","author":"prateekzare","date":"2026-09-09 20:08:24","revision":3688952},"1.2.1":{"tag":"1.2.1","author":"prateekzare","date":"2026-09-10 00:48:35","revision":3689155},"1.2.2":{"tag":"1.2.2","author":"prateekzare","date":"2026-09-10 19:27:48","revision":3690398},"1.2.3":{"tag":"1.2.3","author":"prateekzare","date":"2026-09-11 09:24:47","revision":3691116},"1.3.0":{"tag":"1.3.0","author":"prateekzare","date":"2026-09-11 19:44:29","revision":3692024}},"upgrade_notice":{"1.2.2":"<p>Adds an optional anonymous usage report, off by default, which sends your site address, install date, 30 day totals and version numbers to the plugin author once a month if you agree to it. You are asked once, shown the exact payload first, and never asked again. Nothing about your visitors is ever included.<\/p>","1.2.1":"<p>Adds an on demand insights screen under Data that reports what actually moved in the selected period, with the figure and the confidence behind each finding, exportable as CSV or JSON. Also adds an optional longer visitor recognition window for counting returning readers, off by default.<\/p>","1.2.0":"<p>Counts readers without JavaScript, survives a blocked REST route, and no longer drops Do Not Track readers on new installs, so figures line up with what other tools report. A page read now costs one request instead of two, with nothing lost: the reading travels inside the next pageview. The beacon also backs off when your host returns 429, and will not send more than sixty times in a visit. Recommended for anyone seeing rate limiting.<\/p>","1.1.1":"<p>Deleting the plugin now keeps your settings, shared link and history by default, so updating by hand no longer wipes them. The AI screens are scoped to assistant traffic only, and authors, content types, assistants and campaigns can now be filtered on.<\/p>","1.1.0":"<p>Adds AI assistant traffic as its own channel and its own reports, and fixes Gemini and Copilot being counted as organic search. Daily summaries are rebuilt once on upgrade so past days are reclassified too. Also adds optional trend, average, anomaly and forecast layers to the chart, all off until you switch them on.<\/p>","1.0.0":"<p>First public release.<\/p>"},"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3685592,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3685592,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3685592,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3685592,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{"blueprint.json":{"filename":"blueprint.json","revision":3692025,"resolution":false,"location":"assets","locale":"","contents":"{\"$schema\":\"https:\\\/\\\/playground.wordpress.net\\\/blueprint-schema.json\",\"landingPage\":\"\\\/wp-admin\\\/admin.php?page=convertnow-analytics\",\"preferredVersions\":{\"php\":\"8.2\",\"wp\":\"latest\"},\"phpExtensionBundles\":[\"kitchen-sink\"],\"features\":{\"networking\":false},\"steps\":[{\"step\":\"login\",\"username\":\"admin\",\"password\":\"password\"},{\"step\":\"installPlugin\",\"pluginData\":{\"resource\":\"wordpress.org\\\/plugins\",\"slug\":\"convertnow-analytics\"},\"options\":{\"activate\":true}},{\"step\":\"runPHP\",\"code\":\"<?php require_once '\\\/wordpress\\\/wp-load.php'; global $wpdb; $t = $wpdb->prefix . 'cnwa_hits'; $pages = array('\\\/', '\\\/about', '\\\/blog\\\/why-self-hosted-analytics', '\\\/blog\\\/ai-referrals-explained', '\\\/tools\\\/pdf-merge', '\\\/tools\\\/csv-to-json', '\\\/pricing', '\\\/contact'); $titles = array('Home', 'About', 'Why self hosted analytics', 'AI referrals explained', 'Merge PDFs', 'CSV to JSON', 'Pricing', 'Contact'); $refs = array(null, 'google.com', 'chatgpt.com', 'perplexity.ai', 'news.ycombinator.com', 'x.com', 'duckduckgo.com', 'claude.ai'); $brow = array('Chrome', 'Safari', 'Firefox', 'Edge'); $vers = array('126', '17', '127', '126'); $oses = array('Windows 10\\\/11', 'macOS', 'iOS', 'Android 14'); $devs = array('desktop', 'mobile', 'desktop', 'mobile'); $ctry = array('DE', 'US', 'IN', 'GB', 'FR', 'NL', 'CA', 'ES'); $langs = array('de-de', 'en-gb', 'en-us', 'fr-fr', 'nl-nl'); $rows = 0; for ($d = 45; $d >= 0; $d--) { $per = (int) round(38 + 26 * sin($d \\\/ 6.0) + ($d < 8 ? (8 - $d) * 5 : 0)); for ($i = 0; $i < $per; $i++) { $when = time() - $d * 86400 - random_int(0, 86399); $p = random_int(0, 7); $hash = substr(md5('cnwa-demo-' . $d . '-' . intdiv($i, 3)), 0, 32); $sess = substr(md5('cnwa-sess-' . $d . '-' . intdiv($i, 3)), 0, 16); $b = random_int(0, 3); $r = $refs[random_int(0, 7)]; $utm = (0 === $i % 13) ? 'newsletter' : null; $wpdb->insert($t, array('view_id' => substr(bin2hex(random_bytes(8)), 0, 16), 'session_id' => $sess, 'visitor_hash' => $hash, 'url_path' => $pages[$p], 'page_title' => $titles[$p], 'referrer_domain' => $r, 'referrer_path' => null, 'utm_source' => $utm, 'utm_medium' => $utm ? 'email' : null, 'utm_campaign' => $utm ? 'spring-launch' : null, 'browser' => $brow[$b], 'browser_version' => $vers[$b], 'os' => $oses[$b], 'device' => $devs[$b], 'screen' => $devs[$b] === 'mobile' ? '390x844' : '1920x1080', 'lang' => $langs[random_int(0, 4)], 'country' => $ctry[random_int(0, 7)], 'content_type' => $p >= 2 && $p <= 3 ? 'post' : 'page', 'author_id' => 1, 'duration' => random_int(0, 420), 'scroll' => random_int(5, 100), 'created_at' => gmdate('Y-m-d H:i:s', $when))); $rows++; } } if (class_exists('CNWA_Rollup')) { CNWA_Rollup::run(60); } echo 'Seeded ' . $rows . ' demo pageviews.';\"}]}"}},"all_blocks":[],"tagged_versions":["1.0.0","1.1.0","1.1.1","1.2.0","1.2.1","1.2.2","1.2.3","1.3.0"],"block_files":[],"assets_screenshots":{"screenshot-1.png":{"filename":"screenshot-1.png","revision":3686254,"resolution":"1","location":"assets","locale":"","width":1418,"height":1076},"screenshot-2.png":{"filename":"screenshot-2.png","revision":3686254,"resolution":"2","location":"assets","locale":"","width":1409,"height":1665},"screenshot-3.png":{"filename":"screenshot-3.png","revision":3686254,"resolution":"3","location":"assets","locale":"","width":1422,"height":1659},"screenshot-4.png":{"filename":"screenshot-4.png","revision":3686254,"resolution":"4","location":"assets","locale":"","width":1412,"height":1274},"screenshot-5.png":{"filename":"screenshot-5.png","revision":3686254,"resolution":"5","location":"assets","locale":"","width":1413,"height":1669},"screenshot-6.png":{"filename":"screenshot-6.png","revision":3686254,"resolution":"6","location":"assets","locale":"","width":1416,"height":1188},"screenshot-7.png":{"filename":"screenshot-7.png","revision":3686254,"resolution":"7","location":"assets","locale":"","width":1412,"height":1070},"screenshot-8.png":{"filename":"screenshot-8.png","revision":3686254,"resolution":"8","location":"assets","locale":"","width":1420,"height":1067},"screenshot-9.png":{"filename":"screenshot-9.png","revision":3685592,"resolution":"9","location":"assets","locale":"","width":1600,"height":1889}},"screenshots":{"1":"The Overview: visitors, visits, views, bounce rate and time on page, with the chart's optional trend, average, unusual-day and forecast layers switched on","2":"AI at a Glance: which assistants send people, what they were sent to, and how AI compares with every other channel","3":"AI Assistants, ranked, with each one's share over time and how deeply its readers read","4":"Pages at a Glance: what gets read, where visits begin and where they end","5":"Referrers at a Glance: channels, search engines and social networks together","6":"Campaigns at a Glance: UTM sources, mediums and campaigns in one place","7":"Geographic at a Glance: countries and languages, with a world map","8":"Goals, with the builder open: each rule reads back in a sentence and says how many of your pages it matches","9":"Settings: the switches for the chart insights, data retention, and the weekly summary email"}},"plugin_section":[262246],"plugin_tags":[239387,232,20315,396,521],"plugin_category":[36,54],"plugin_contributors":[279589],"plugin_business_model":[],"class_list":["post-361489","plugin","type-plugin","status-publish","hentry","plugin_section-dashboard-widgets","plugin_tags-ai-analytics","plugin_tags-analytics","plugin_tags-cookieless","plugin_tags-privacy","plugin_tags-statistics","plugin_category-analytics","plugin_category-security-and-spam-protection","plugin_contributors-prateekzare","plugin_committers-prateekzare"],"banners":{"banner":"https:\/\/ps.w.org\/convertnow-analytics\/assets\/banner-772x250.png?rev=3685592","banner_2x":"https:\/\/ps.w.org\/convertnow-analytics\/assets\/banner-1544x500.png?rev=3685592","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/convertnow-analytics\/assets\/icon-128x128.png?rev=3685592","icon_2x":"https:\/\/ps.w.org\/convertnow-analytics\/assets\/icon-256x256.png?rev=3685592","generated":false},"screenshots":[{"src":"https:\/\/ps.w.org\/convertnow-analytics\/assets\/screenshot-1.png?rev=3686254","caption":"The Overview: visitors, visits, views, bounce rate and time on page, with the chart's optional trend, average, unusual-day and forecast layers switched on"},{"src":"https:\/\/ps.w.org\/convertnow-analytics\/assets\/screenshot-2.png?rev=3686254","caption":"AI at a Glance: which assistants send people, what they were sent to, and how AI compares with every other channel"},{"src":"https:\/\/ps.w.org\/convertnow-analytics\/assets\/screenshot-3.png?rev=3686254","caption":"AI Assistants, ranked, with each one's share over time and how deeply its readers read"},{"src":"https:\/\/ps.w.org\/convertnow-analytics\/assets\/screenshot-4.png?rev=3686254","caption":"Pages at a Glance: what gets read, where visits begin and where they end"},{"src":"https:\/\/ps.w.org\/convertnow-analytics\/assets\/screenshot-5.png?rev=3686254","caption":"Referrers at a Glance: channels, search engines and social networks together"},{"src":"https:\/\/ps.w.org\/convertnow-analytics\/assets\/screenshot-6.png?rev=3686254","caption":"Campaigns at a Glance: UTM sources, mediums and campaigns in one place"},{"src":"https:\/\/ps.w.org\/convertnow-analytics\/assets\/screenshot-7.png?rev=3686254","caption":"Geographic at a Glance: countries and languages, with a world map"},{"src":"https:\/\/ps.w.org\/convertnow-analytics\/assets\/screenshot-8.png?rev=3686254","caption":"Goals, with the builder open: each rule reads back in a sentence and says how many of your pages it matches"},{"src":"https:\/\/ps.w.org\/convertnow-analytics\/assets\/screenshot-9.png?rev=3685592","caption":"Settings: the switches for the chart insights, data retention, and the weekly summary email"}],"raw_content":"<!--section=description-->\n<p>A complete analytics dashboard that runs entirely on your own database. No account, no key, no tier held back, nothing to upgrade to.<\/p>\n\n<p>Visitors, visits, views, real bounce rate and real time on page. Top pages, entry and exit pages. Referrers, channels, campaigns, countries, languages, browsers, devices. Goals, funnels, journeys, retention, segments and cohorts. Read depth per page, a live counter, a heatmap, a weekly email and a shareable read only dashboard.<\/p>\n\n<p><strong>AI traffic, counted properly<\/strong><\/p>\n\n<p>Someone asks ChatGPT a question, the answer cites your page, they click through. That is a reader, not a crawler. Most plugins file them under referral, and some do worse: Gemini answers from a google.com address and Copilot from microsoft.com, so a plain search rule buries both inside organic search.<\/p>\n\n<p>ConvertNow gives AI assistants a channel and four screens of their own. ChatGPT, Perplexity, Claude, Gemini, Copilot, Grok, DeepSeek, Meta AI and Le Chat are recognised by name. Crawlers are refused before a row is written, so GPTBot and the rest never appear as traffic.<\/p>\n\n<p><strong>Revenue, when there is any<\/strong><\/p>\n\n<p>WooCommerce and Easy Digital Downloads orders are read from the shop and attached to the visit behind them, so you see which channel, campaign, page and author earned. Other checkouts can report a sale from the page. No shop, no menu.<\/p>\n\n<p><strong>Editorial reporting<\/strong><\/p>\n\n<p>The author is recorded on every pageview, so the byline is a dimension like any other: traffic by author, fastest growing authors, blog posts separated from pages and archives, and read depth per post.<\/p>\n\n<p><strong>Fast by design<\/strong><\/p>\n\n<p>The tracker inlines into the footer: no extra request, about 1.5 KB. Raw hits roll up into daily tables hourly, so a twelve month report costs the same queries as a one day one. Every chart is plain SVG, so there is no charting library to load.<\/p>\n\n<p><strong>Privacy<\/strong><\/p>\n\n<p>No cookies, no localStorage, no persistent identifier. Visitors are counted with a one way SHA256 hash of IP, user agent and a salt that rotates daily, so the same person cannot be followed from one day to the next. Raw IP addresses are never stored, and nothing about your visitors leaves your server.<\/p>\n\n<p><strong>Links<\/strong><\/p>\n\n<ul>\n<li><a href=\"https:\/\/convertnow.tools\/convertnow-analytics\/\">convertnow.tools\/convertnow-analytics<\/a> for docs and screenshots<\/li>\n<li><a href=\"https:\/\/convertnow.tools\">convertnow.tools<\/a> for everything else I build<\/li>\n<li><a href=\"mailto:contact@convertnow.tools\">contact@convertnow.tools<\/a> or <a href=\"mailto:prateekzare@gmail.com\">prateekzare@gmail.com<\/a>, both reach me<\/li>\n<\/ul>\n\n<h3>External services<\/h3>\n\n<p>ConvertNow uses no external service for anything it does. There is one optional service, off by default, described in full below.<\/p>\n\n<p>Tracking, reporting, goals, funnels, journeys, retention, segments, cohorts, insights, country lookups and exports all run on your own server against your own database. There is no activation call, no licence check and no key. Nothing about your visitors ever leaves your site under any setting.<\/p>\n\n<p><strong>Optional: anonymous usage reporting (off by default)<\/strong><\/p>\n\n<p>If, and only if, you switch this on, the plugin sends one report a month to convertnow.tools, the author's site, at <code>https:\/\/convertnow.tools\/wp-json\/cnwa-hub\/v1\/report<\/code>. It exists so the author can see which versions are in use and how the plugin is actually being used, and it is used for nothing else.<\/p>\n\n<p>It is off on every install. You are asked once, on the plugin's own screen, with the exact payload from your site shown to you before you decide. Declining is remembered permanently. If you never answer, nothing is ever sent. You can switch it on or off at any time in Settings \u2192 Data retention \u2192 Anonymous usage report, and switching it off removes the scheduled event immediately.<\/p>\n\n<p>This is the complete payload, and there is nothing else in it:<\/p>\n\n<ul>\n<li>Your site address and site name<\/li>\n<li>The date this plugin was first activated on your site<\/li>\n<li>Your total pageviews and total visitors for the last 30 days, as two numbers<\/li>\n<li>The ConvertNow, WordPress and PHP versions, and your site locale<\/li>\n<\/ul>\n\n<p>It contains nothing about your visitors: no page paths, no referrers, no IP addresses, no visitor hashes, no user accounts, no email addresses, no post or page titles. The request is sent once every 30 days, non blocking, and a failure is silent.<\/p>\n\n<p>Terms of service: <a href=\"https:\/\/convertnow.tools\/terms\/\">convertnow.tools\/terms<\/a>. Privacy policy: <a href=\"https:\/\/convertnow.tools\/privacy\/\">convertnow.tools\/privacy<\/a>.<\/p>\n\n<p>The country lookup tables ship inside the plugin as plain text files and are read from disk. There is nothing to download and nothing to import.<strong>Links<\/strong><\/p>\n\n<ul>\n<li>Plugin home page: <a href=\"https:\/\/convertnow.tools\/convertnow-analytics\/\">convertnow.tools\/convertnow-analytics<\/a><\/li>\n<li>Support by email: <a href=\"mailto:contact@convertnow.tools\">contact@convertnow.tools<\/a><\/li>\n<li>The author directly: <a href=\"mailto:prateekzare@gmail.com\">prateekzare@gmail.com<\/a><\/li>\n<li>Support forum: <a href=\"https:\/\/wordpress.org\/support\/plugin\/convertnow-analytics\/\">wordpress.org\/support\/plugin\/convertnow-analytics<\/a><\/li>\n<li>Leave a review: <a href=\"https:\/\/wordpress.org\/support\/plugin\/convertnow-analytics\/reviews\/\">wordpress.org\/support\/plugin\/convertnow-analytics\/reviews<\/a><\/li>\n<\/ul>\n\n<p>Both addresses reach the same inbox. Email is usually the faster of the two; the forum is the better place for anything another user might hit as well.<\/p>\n\n<p><strong>Bundled data<\/strong><\/p>\n\n<p>IP Geolocation by <a href=\"https:\/\/db-ip.com\">DB-IP<\/a>, used under <a href=\"https:\/\/creativecommons.org\/licenses\/by\/4.0\/\">CC BY 4.0<\/a>.<\/p>\n\n<p>Country lookups read two plain text tables built from the DB-IP IP to Country Lite database: <code>assets\/data\/geo-ipv4.csv<\/code> and <code>assets\/data\/geo-ipv6.csv<\/code>. Every line is one boundary, written as an uppercase hex address prefix and an ISO 3166-1 alpha-2 country code, so both files can be opened and read in any text editor. The world map outlines are plain JSON path data at <code>assets\/data\/world.json<\/code>. Nothing in the plugin is compiled, minified or obfuscated.<\/p>\n\n<!--section=installation-->\n<p>From your dashboard:<\/p>\n\n<ol>\n<li>Go to <strong>Plugins \u2192 Add New<\/strong> and search for <strong>ConvertNow Analytics<\/strong>.<\/li>\n<li>Click Install Now, then Activate.<\/li>\n<li>Open <strong>ConvertNow<\/strong> in the admin menu. Data starts appearing immediately.<\/li>\n<\/ol>\n\n<p>Or by hand:<\/p>\n\n<ol>\n<li>Upload the <code>convertnow-analytics<\/code> folder to <code>\/wp-content\/plugins\/<\/code>.<\/li>\n<li>Activate it from the Plugins screen.<\/li>\n<li>Open <strong>ConvertNow<\/strong> in the admin menu.<\/li>\n<\/ol>\n\n<p>Either way that is it. No key, no account, no configuration. Country data is built in, so the map and the Countries panel fill in on their own. Your own visits are not counted while you are logged in as an administrator or editor, which is why the numbers stay at zero until real traffic arrives.<\/p>\n\n<!--section=faq-->\n<dl>\n<dt id=\"do%20i%20need%20an%20account%20or%20a%20licence%20key%3F\"><h3>Do I need an account or a licence key?<\/h3><\/dt>\n<dd><p>No, and there is nowhere to put one. There is no account, no key, no activation and no paid tier. The plugin contains no code that makes an outbound request, so there is nothing to opt out of either.<\/p><\/dd>\n<dt id=\"my%20host%20says%20i%20am%20making%20too%20many%20requests.%20is%20it%20this%20plugin%3F\"><h3>My host says I am making too many requests. Is it this plugin?<\/h3><\/dt>\n<dd><p>Partly, possibly. A page read sends one small request to your own site, and the last page of a visit sends a second. Those cannot be page cached, so on a site that serves cached HTML they may be most of what actually reaches PHP.<\/p>\n\n<p>As of 1.2.0 there is far less of it. The reading of a page now travels inside the next pageview rather than costing a request of its own, so a five page visit sends six requests where it used to send ten, and no figure is lost doing it. The beacon also obeys a 429 or 503 from your server: it reads <code>Retry-After<\/code> and stops entirely until that has passed, so it can no longer add to a rate limit once one starts. And it will not send more than sixty times in one visit however badly a theme misbehaves.<\/p>\n\n<p>What it is not: the plugin makes no outbound requests of any kind, so it cannot be the source of automated traffic from Meta, AWS or Microsoft, and it contacts no third party. It also adds no cron work beyond one hourly summary job.<\/p><\/dd>\n<dt id=\"why%20are%20my%20numbers%20lower%20than%20jetpack%2C%20google%20analytics%20or%20my%20host%27s%20stats%3F\"><h3>Why are my numbers lower than Jetpack, Google Analytics or my host's stats?<\/h3><\/dt>\n<dd><p>Four ordinary reasons, in the order they usually matter.<\/p>\n\n<ol>\n<li><strong>You installed it partway through the period.<\/strong> Days before the install are empty because nothing was recorded then, not because they were quiet.<\/li>\n<li><strong>Administrators and editors are not counted<\/strong>, by default. Your own visits, and your team's, are missing on purpose. Settings \u2192 Tracking changes it.<\/li>\n<li><strong>Do Not Track.<\/strong> If that setting is on, those readers are dropped entirely, and most other tools ignore the signal. New installs default to off; a site upgrading from an earlier version keeps it on until changed.<\/li>\n<li><strong>Bots.<\/strong> ConvertNow refuses crawlers, monitors, previewers and AI training bots before a row is written. Some tools count a share of them, which raises their numbers rather than lowering yours.<\/li>\n<\/ol>\n\n<p>If the gap still looks wrong after that, the usual cause is the beacon being blocked: a security plugin that hardens <code>\/wp-json\/<\/code>, or a firewall rule. Since 1.2.0 the plugin retries on a front end URL when that happens, and counts readers with no JavaScript at all.<\/p><\/dd>\n<dt id=\"how%20do%20you%20tell%20an%20ai%20visitor%20from%20an%20ai%20crawler%3F\"><h3>How do you tell an AI visitor from an AI crawler?<\/h3><\/dt>\n<dd><p>They arrive by completely different routes and are handled at different points. A crawler identifies itself in the user agent, and GPTBot, ClaudeBot, CCBot, PerplexityBot, Bytespider, Applebot and Amazonbot are all refused by the collector before a row is written, so they never become traffic. A visitor is a browser carrying a referrer from an assistant's own domain. Only the second one reaches the AI screens, which is why every figure there is a person who read an answer and followed the citation.<\/p><\/dd>\n<dt id=\"why%20did%20my%20gemini%20traffic%20used%20to%20show%20up%20as%20google%3F\"><h3>Why did my Gemini traffic used to show up as Google?<\/h3><\/dt>\n<dd><p>Because Gemini is served from gemini.google.com, and a rule that looks for \"google\" in the referrer catches it. Copilot has the same problem on microsoft.com. ConvertNow checks the assistants first, so a visit from Gemini is counted as an assistant and a visit from Google Search is counted as search. Existing summaries are rebuilt on upgrade, so past days are reclassified too.<\/p><\/dd>\n<dt id=\"an%20assistant%20is%20missing.%20can%20i%20add%20it%3F\"><h3>An assistant is missing. Can I add it?<\/h3><\/dt>\n<dd><p>Yes, with the <code>cnwa_ai_sources<\/code> filter. Each entry is a pattern matched against the referrer host and the name to show. The list is checked in order, so a narrow host goes above a broad one.<\/p><\/dd>\n<dt id=\"do%20the%20trend%20line%20and%20forecast%20use%20ai%3F\"><h3>Do the trend line and forecast use AI?<\/h3><\/dt>\n<dd><p>No, and the plugin does not claim they do. They are a least squares fit and the standard deviation of the days around it, computed in your browser from the figures already on the screen. The forecast is that straight line continued, and the band around it is how much the measured days actually varied. Nothing is sent anywhere and no model runs. Every layer is off until you switch it on in Settings.<\/p><\/dd>\n<dt id=\"is%20the%20ai%20insights%20screen%20actually%20ai%3F\"><h3>Is the AI insights screen actually AI?<\/h3><\/dt>\n<dd><p>It is statistics, and the screen says so at the bottom of every run. Least squares fits for direction, median absolute deviation for outliers, share and concentration comparisons against the previous period of equal length. It runs on your server against your own rows, no model is called and nothing leaves the site. The name reflects what the screen is for, reading your numbers the way an analyst would, not a claim about how it works.<\/p><\/dd>\n<dt id=\"will%20generating%20insights%20slow%20my%20site%20down%3F\"><h3>Will generating insights slow my site down?<\/h3><\/dt>\n<dd><p>It cannot touch your front end, because it only runs from the dashboard when somebody presses the button. The run itself reads the selected period and the one before it across several dimensions, which on a large site takes a few seconds, and the result is cached for five minutes so a second press costs nothing. Nothing runs on opening the screen.<\/p><\/dd>\n<dt id=\"can%20i%20count%20returning%20visitors%3F\"><h3>Can I count returning visitors?<\/h3><\/dt>\n<dd><p>Yes, but it is off by default. Settings \u2192 Tracking \u2192 Visitor recognition widens the salt window from one day to 30, 90 or 365 days. Until you change it the salt rotates daily and a reader returning tomorrow is a new visitor, which is the honest default for a plugin that stores nothing on the reader's device. Widening it changes what you are doing with visitor data, so update your privacy disclosures before you do.<\/p><\/dd>\n<dt id=\"where%20do%20i%20set%20up%20a%20goal%20or%20a%20funnel%3F\"><h3>Where do I set up a goal or a funnel?<\/h3><\/dt>\n<dd><p>On the Goals or Funnels screen itself, under the report. Open the report, expand the editor below it, pick a page from your own site, save. Creating a definition needs the same capability as changing a setting, so a user who can view reports but not manage the site sees the report and no editor.<\/p><\/dd>\n<dt id=\"why%20does%20retention%20not%20show%20whether%20visitors%20came%20back%20next%20week%3F\"><h3>Why does Retention not show whether visitors came back next week?<\/h3><\/dt>\n<dd><p>Because ConvertNow cannot tell. A visitor is identified by a hash that is rebuilt nightly every day, on purpose, so the same person is unrecognisable tomorrow. Rather than print a number that looks like week on week retention and is not, the report answers what the data actually supports: how a page holds its traffic over the days after it lands, and how often a visit is a return within the same day.<\/p><\/dd>\n<dt id=\"how%20far%20back%20do%20the%20behaviour%20reports%20go%3F\"><h3>How far back do the behaviour reports go?<\/h3><\/dt>\n<dd><p>As far as your raw retention setting keeps pageviews, ninety days by default. Goals, funnels, journeys, retention and cohorts all need the shape of individual visits, and the daily summaries have already rolled that away. Each of those screens says the date it can see back to.<\/p><\/dd>\n<dt id=\"how%20does%20it%20know%20who%20wrote%20a%20post%3F\"><h3>How does it know who wrote a post?<\/h3><\/dt>\n<dd><p>WordPress already does. The tracker resolves each URL to the post behind it and stores the author ID with the pageview, then the report turns IDs back into display names when it draws. Nothing is sent anywhere to work that out.<\/p><\/dd>\n<dt id=\"will%20author%20reports%20cover%20posts%20published%20before%20i%20installed%20it%3F\"><h3>Will author reports cover posts published before I installed it?<\/h3><\/dt>\n<dd><p>Views recorded before you installed it do not exist, so no. Views recorded before version 2.0 carry no content type yet; Settings has a Classify button that resolves them in batches and backfills Authors, Blog Posts and Content Types for that history.<\/p><\/dd>\n<dt id=\"does%20it%20work%20with%20caching%20plugins%3F\"><h3>Does it work with caching plugins?<\/h3><\/dt>\n<dd><p>Yes. The beacon is client side and posts to a REST endpoint, so a cached HTML page still reports its own view.<\/p><\/dd>\n<dt id=\"does%20it%20work%20with%20a%20cdn%20or%20cloudflare%3F\"><h3>Does it work with a CDN or Cloudflare?<\/h3><\/dt>\n<dd><p>Yes. Set the visitor IP source in Settings so country lookups and visitor counts use the real client address instead of the proxy.<\/p><\/dd>\n<dt id=\"does%20it%20support%20ipv6%3F\"><h3>Does it support IPv6?<\/h3><\/dt>\n<dd><p>Yes. Country lookups cover IPv4 and IPv6.<\/p><\/dd>\n<dt id=\"does%20the%20country%20lookup%20add%20load%20to%20my%20server%3F\"><h3>Does the country lookup add load to my server?<\/h3><\/dt>\n<dd><p>Almost none. The table ships with the plugin, so there is no download and no import. A lookup reads one small block of a file, about three microseconds, with no database query and no network request. Results are reused within a request.<\/p><\/dd>\n<dt id=\"how%20accurate%20is%20the%20country%20data%3F\"><h3>How accurate is the country data?<\/h3><\/dt>\n<dd><p>It resolves IPv4 to \/24 and IPv6 to \/48, which is right for about 98% of addresses when checked against the full DB-IP dataset. That is a deliberate trade: a coarser table means a much smaller file and a much cheaper lookup, and it is more than enough to see where an audience is.<\/p><\/dd>\n<dt id=\"why%20do%20my%20visitor%20counts%20differ%20from%20other%20analytics%20tools%3F\"><h3>Why do my visitor counts differ from other analytics tools?<\/h3><\/dt>\n<dd><p>ConvertNow filters bots aggressively and counts a visitor as unique within a single day. Tools that use persistent cookies count differently. Neither number is wrong, they measure different things.<\/p><\/dd>\n<dt id=\"a%20content%20blocker%20is%20blocking%20the%20endpoint.\"><h3>A content blocker is blocking the endpoint.<\/h3><\/dt>\n<dd><p>Rename the endpoint in Settings. The tracker picks up the new name automatically.<\/p><\/dd>\n<dt id=\"can%20i%20track%20a%20static%20page%20hosted%20elsewhere%3F\"><h3>Can I track a static page hosted elsewhere?<\/h3><\/dt>\n<dd><p>Yes. Settings has a snippet. Add the other domain to the allowed domains list first.<\/p><\/dd>\n<dt id=\"can%20i%20filter%20the%20dashboard%3F\"><h3>Can I filter the dashboard?<\/h3><\/dt>\n<dd><p>Yes. Click any row label in a breakdown panel and everything recalculates against that value. Filters stack and combine with AND. Because the daily summaries store each dimension separately, a filtered view reads raw rows, so it reaches back as far as your raw retention setting allows. The filter bar tells you that date.<\/p><\/dd>\n<dt id=\"is%20the%20trend%20line%20a%20forecast%3F\"><h3>Is the trend line a forecast?<\/h3><\/dt>\n<dd><p>No. It is a least squares fit through the period you are viewing, continued a short way past the end. It knows nothing about seasonality, campaigns or what you publish next. Treat it as direction of travel.<\/p><\/dd>\n<dt id=\"does%20it%20track%20clicks%3F\"><h3>Does it track clicks?<\/h3><\/dt>\n<dd><p>No. ConvertNow deliberately records pageviews and engagement only, which keeps the database small and the dashboard readable.<\/p><\/dd>\n<dt id=\"where%20is%20my%20data%20stored%3F\"><h3>Where is my data stored?<\/h3><\/dt>\n<dd><p>In your own WordPress database, in four tables prefixed <code>cnwa_<\/code>. Deleting the plugin removes all of them. The country lookup table is a read only file inside the plugin folder and holds nothing about your visitors.<\/p>\n\n<p><strong>Clicks, downloads and searches, when you want them<\/strong><\/p>\n\n<p>Off by default, and honest about why. A page view writes one database row per page; a click writes one per interaction, so an events table grows with how much people do on your site rather than with how many of them turn up. Nothing is collected until you choose it, one type at a time:<\/p>\n\n<ul>\n<li>Outbound links, with the destination and the domain<\/li>\n<li>File downloads, matched by extension<\/li>\n<li>Email and phone links<\/li>\n<li>Anything you name with a CSS selector, labelled by <code>data-cnwa-label<\/code> or its own text<\/li>\n<li>Page views that returned a 404, and the pages that linked to them<\/li>\n<li>What people typed into your search box<\/li>\n<\/ul>\n\n<p>The last two are effectively free: they ride along with a page view that is already being recorded, so they cost one row and no extra request. Broken links and empty searches are usually the fastest wins on any site.<\/p>\n\n<p>The settings screen tells you what switching this on will cost before you switch it on, using your site's own traffic from the last thirty days and a per event size measured on a real database rather than guessed. Events have their own retention window, separate from page views, because they are the rows that grow fastest.<\/p>\n\n<p><strong>Notes on the chart<\/strong><\/p>\n\n<p>A spike six weeks ago is just a shape unless something tells you what it was. Mark the day you redesigned, sent the newsletter or changed your prices, and the note stays on the chart with the traffic it explains. They are stored in one option row, so there is no table and nothing left behind.<\/p>\n\n<p><strong>A weekly email<\/strong><\/p>\n\n<p>Last week against the week before, your five most read pages and five biggest sources, in an email you can read in fifteen seconds. It comes from your own site, contains no tracking pixel, and reads from the daily summaries, so it costs the same whether you had a hundred visitors or a million. Off until you ask for it, and there is a button to send one now and find out whether email leaves your site at all.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>1.3.0<\/h4>\n\n<p><strong>Revenue, for the sites that have any.<\/strong> Orders are recorded and attached to the visit that produced them, so the same dimensions that answer \"which page got read\" now answer \"which page paid for itself\". Seven new screens: revenue at a glance, by channel, by landing page, by referrer, by campaign, by author, and from AI assistants.<\/p>\n\n<ul>\n<li><strong>WooCommerce and Easy Digital Downloads are read server side<\/strong>, from their own order hooks, when payment completes rather than when an order is created. Nothing depends on the visitor's browser, so an ad blocker, a closed tab or a redirect through a payment provider cannot lose a sale. Refunds are subtracted rather than hidden, so the net figure matches what the shop actually kept.<\/li>\n<li><strong>Anything else reports from the page.<\/strong> A Shopify Buy Button, Snipcart, Gumroad, Lemon Squeezy or a bespoke checkout calls <code>window.cnwa.purchase({ id: 'ORDER-123', amount: 49.00, currency: 'EUR' })<\/code> from the thank you page. Off until you switch it on, because unlike the server side adapters it takes a figure from the browser. The order id makes a repeat call harmless: one id is stored once however many times somebody reloads a thank you page.<\/li>\n<li><strong>A sale is classified exactly the way the visit was.<\/strong> The channel rules are shared with the traffic screens, so a purchase that began in ChatGPT is filed under assistants here and under assistants there, rather than landing in organic search because Gemini answers from a google.com address.<\/li>\n<li><strong>Attribution is last non direct touch<\/strong>, inside the buyer's own recorded history, and the screen says what share of orders it could trace at all rather than quietly dropping the rest.<\/li>\n<li><strong>Money is stored as an integer in minor units.<\/strong> Floats do not add up, and a revenue report that is a cent out from WooCommerce is a revenue report nobody trusts again.<\/li>\n<li><strong>No shop, no menu.<\/strong> On a site with nothing to sell the whole Revenue section is absent: not greyed out, not present and empty. It appears when a store plugin is active or an order has been recorded, and Settings \u2192 Tracking \u2192 Revenue reports forces it either way.<\/li>\n<\/ul>\n\n<p><strong>Correct counting behind a cache or a CDN.<\/strong> This is the part that matters most, and one of these was losing whole pages of traffic.<\/p>\n\n<ul>\n<li><strong>The beacon no longer depends on who rendered the page.<\/strong> It used to be left out for excluded users, which is fine until a page cache is involved. An administrator is nearly always the first person to load a page after publishing it, administrators are excluded by default, so the cache filled with a copy that had no tracker in it and every real reader of that URL went uncounted until the cache expired. The beacon now ships to everybody and the collect request, which is never cached and carries the real visitor's cookies, decides whether to record. Exclusion still works and now works per request rather than per cache fill.<\/li>\n<li><strong>Page optimisers are told to leave the beacon alone.<\/strong> Cloudflare Rocket Loader, Autoptimize, LiteSpeed, WP Rocket and Perfmatters all read one of <code>data-cfasync<\/code>, <code>data-no-optimize<\/code>, <code>data-no-defer<\/code> or <code>nowprocket<\/code>. The delay until interaction setting several of them offer is the dangerous one: it is right for a chat widget and wrong for a pageview counter, because a reader who lands, reads and leaves without clicking is never recorded.<\/li>\n<li><strong>The collect endpoint and the pixel refuse to be cached.<\/strong> <code>no-store<\/code>, a CDN specific header, and the two constants the common WordPress page caches look for. A cached pixel means the second visitor to a page never reaches PHP.<\/li>\n<li><strong>A shared CDN address no longer throttles the site.<\/strong> Flood protection counted against the visitor's address, which behind Cloudflare, an office or a mobile carrier is hundreds of people. On a busy site that stopped recording partway through every minute, silently, and looked exactly like a traffic drop. The tight cap is now per visitor, where a flood actually shows up, and the per address cap is a loose backstop that is skipped entirely when the address is a proxy we could not see past.<\/li>\n<\/ul>\n\n<p><strong>Also in this release.<\/strong> The insights cache is keyed by the caller's authorisation, like every other cached route, so a payload built for an administrator can never be served to a shared-link reader. A range that ends \"now\" now includes the current second, which sounds like nothing and is not: an order completed seconds before opening the dashboard was being excluded, which reads exactly like a broken integration. Saving a setting rebuilds the report list in the same request, so switching the Revenue section off takes effect immediately instead of on the next page load. Admin notices from other plugins now appear above ConvertNow's header bar instead of inside it, and the report sidebar scrolls within itself when every group is expanded rather than pinning its top and putting its own last items out of reach.<\/p>\n\n<p><strong>Documentation you can search.<\/strong> The Documentation screen gained a search box that filters the whole page as you type, marks the words it found, and says how many blocks matched and where. It reads as two columns on a wide screen, a contents rail that tracks where you are and the pages themselves, and folds to one column with the contents as chips on a narrow one. Sixteen sections now, up from nine, with worked examples you can copy: campaign links for a newsletter, a social post, two links in one email and a printed QR code; the JavaScript purchase call for a hosted checkout; a selector and a label for click tracking; and filter snippets for excluding a path or hiding a report. New sections cover getting started, clicks and events, revenue, caching and CDN behaviour, exports and retention, and the filters and REST routes the plugin exposes.<\/p>\n\n<p><strong>Settings are shorter.<\/strong> Twelve cards became eight, the help text lost a third of its length with nothing left over 190 characters, and three settings went entirely: the week start duplicated WordPress's own, the anomaly threshold asked people to pick a standard deviation, and the currency fallback was a fallback for a fallback since orders carry their own.<\/p>\n\n<h4>1.2.3<\/h4>\n\n<p><strong>Accuracy release. Your numbers will get smaller, and that is the point.<\/strong> Four separate faults were inflating visitors and views, sometimes by an order of magnitude. Every one of them is fixed here, and the stored history is cleaned in the background after you update.<\/p>\n\n<ul>\n<li><strong>The no script image was counting machines.<\/strong> A browser running JavaScript never requests an image inside a <code>noscript<\/code> tag. Crawlers, HTML parsers, link preview fetchers, feed readers, uptime monitors and security scanners routinely do, and each one arrived with a freshly minted view id, so it counted as a brand new visitor on a brand new visit. The setting is now off by default and is switched off once on existing sites. Turned back on, the request has to look like an image loaded by a browser that is on your site, and repeat requests for the same page from the same client collapse into one view.<\/li>\n<li><strong>Forwarded IP headers were believed on sites with no proxy.<\/strong> <code>X-Forwarded-For<\/code>, <code>X-Real-IP<\/code> and <code>CF-Connecting-IP<\/code> are written by the client, so anything varying them arrived as a new person on every request. Automatic detection now reads them only when the connection itself came from a private address, carrier NAT or a Cloudflare edge, and only accepts a routable public value. Everywhere else it uses the connecting address, which cannot be forged. A <code>cnwa_trusted_proxies<\/code> filter covers load balancers on public addresses.<\/li>\n<li><strong>A retried beacon could store the same pageview twice.<\/strong> When a request reached the database but its answer did not come back, the retry wrote the view again under a second visitor. The view id is now unique and the write is an <code>INSERT IGNORE<\/code>, so the same pageview can be sent as often as it likes and is stored once. Duplicates already in the table are removed after the update, in resumable chunks, and the summaries are rebuilt from the corrected rows.<\/li>\n<li><strong>Bot filtering was an agent list and nothing else.<\/strong> Roughly half of automated traffic now copies a current Chrome agent string, which no agent list can see through. The list is much longer, and the request itself is checked as well: prefetch and prerender markers in every spelling, and the headers a browser always sends. A Strict mode drops anything whose agent does not say Mozilla\/5.0. <code>cnwa_is_bot<\/code> and <code>cnwa_should_count<\/code> filters let a site add its own rules.<\/li>\n<li><strong>Prerendered pages are no longer counted until they are shown.<\/strong> A page that a browser renders speculatively and never displays is not a pageview.<\/li>\n<li>The visitor identifier now rotates on your site's own day rather than on UTC. On any timezone other than UTC the old behaviour split one local day across two identifiers, so anyone reading across that boundary was counted twice.<\/li>\n<li>The origin check is applied to all three ways in. The front end fallback endpoint and the pixel were skipping it, which meant anything anywhere could POST pageviews at your site and have them counted.<\/li>\n<li>Flood protection gained a second, tighter cap on the visitor rather than the address, so one client hammering the endpoint is caught without penalising everybody behind a shared address.<\/li>\n<li>Excluded paths are honoured before the beacon is printed rather than after the payload arrives.<\/li>\n<\/ul>\n\n<p><strong>Built for sites with a lot of pages.<\/strong> The ranked reports page now, so Pages, Posts, Entry pages, Exit pages, Referrers, Sources and the rest are no longer a top twenty with everything else invisible.<\/p>\n\n<ul>\n<li>Every ranked report has a pager and a row count: previous, next, 25 to 200 rows a page, and an honest \"Showing 1 to 50 of 4,182\" underneath. Rank numbers continue across pages rather than restarting at one.<\/li>\n<li>A search box sits above each table and runs on the server against the whole report, not against the rows on screen. On a big site that is the right tool anyway: nobody wants to page to row 3,000 to see how one post did.<\/li>\n<li>The share column is measured against the whole report instead of the visible page. Before, every page of a long report added up to 100%, which made row 200 look as important as row 1.<\/li>\n<li>Ranking is capped at 2,000 rows, because sorting forty thousand candidates to show fifty is how an analytics screen becomes the slowest page on a site. The cap is stated on screen when it bites, the total next to it still says how many rows there really are, and search reaches everything below it.<\/li>\n<li>Each day now keeps a sensible number of labels per report rather than 500 of everything: twelve for device, sixty for browser, five hundred for pages. What falls past the cap is added into one row per report per day instead of being discarded, so the totals stay right and the dashboard can say how much traffic sits in the tail. Previously anything past the top 500 simply vanished from the history.<\/li>\n<li>Entry and exit pages get a composite index covering the range scan and the visit grouping together. Those two reports were the heaviest reads the plugin makes, and on a large table they were a filesort over the whole window.<\/li>\n<li>Summaries are rebuilt once after updating, because a day summarised under the old caps has no tail row and would read as if that traffic never happened.<\/li>\n<\/ul>\n\n<p><strong>A review request, asked once and asked properly.<\/strong> The plugin is free, has no paid tier and is advertised nowhere, so a review on WordPress.org is the only thing that puts it in front of the next person looking for self hosted analytics. It now asks for one, under rules that keep it from becoming a nuisance: not until the plugin has been installed a fortnight and has actually recorded a few hundred pageviews, because a prompt on an empty dashboard asks somebody to vouch for something they have not seen work; only on ConvertNow's own screens, never while you are editing a post; and only for people who can see the dashboard. Four answers, all of them honoured: write one, not now (a fortnight), remind me in three months, or never ask again, which is never. Following the link ends it too, whether or not you write anything. The whole state is one option, so a site that has answered costs nothing to check.<\/p>\n\n<p><strong>Stability.<\/strong> CSV and TSV exports no longer emit a deprecation notice on PHP 8.4, and the files they write are now plain RFC 4180 rather than PHP's proprietary backslash escaping, so a value containing a quote reads back as it was written instead of arriving double escaped. A stored date that will not parse no longer throws out of a cron run: the rollup, the visit repair, the retention grid and the weekly rhythm all handle a malformed value by skipping it. IPv6 ranges are supported in CIDR matching. The collector no longer runs its front end handler during cron or REST requests.<\/p>\n\n<h4>1.2.2<\/h4>\n\n<p><strong>Anonymous usage reporting, off by default.<\/strong> The plugin can now send one report a month to its author, so that decisions about what to build next come from how the plugin is actually used rather than guesswork. It is off on every install and it stays off unless you say yes.<\/p>\n\n<ul>\n<li>You are asked once, on ConvertNow's own screen, and the notice shows the exact payload from your own site before you decide. Saying no is remembered permanently and you are never asked again.<\/li>\n<li>The payload is your site address and name, the date you installed the plugin, your pageview and visitor totals for the last 30 days, and the ConvertNow, WordPress, PHP and locale strings. Nothing about your visitors is included under any circumstances: no pages, no referrers, no IP addresses, no visitor hashes.<\/li>\n<li>Settings \u2192 Data retention \u2192 Anonymous usage report turns it on or off at any time. Off removes the scheduled event straight away, and deactivating or deleting the plugin removes it too.<\/li>\n<li>The readme's External services section documents every field, the endpoint, the frequency and the links to the terms and privacy policy, as WordPress.org requires.<\/li>\n<\/ul>\n\n<h4>1.2.1<\/h4>\n\n<p><strong>Insights on demand.<\/strong> Data \u2192 AI insights runs a statistical read of the selected period and hands back fifteen to twenty ranked findings across traffic shape, content, engagement, acquisition, assistant visibility and audience. Pick which groups to run, press generate, export as CSV or JSON. Nothing runs until you ask, because it reads the whole period and the one before it; results are cached for five minutes so a second press is free. Administrators and anyone with dashboard access.<\/p>\n\n<ul>\n<li>Every finding carries the figure behind it, a confidence taken from the fit or the sample size, and plain language about what it does and does not prove.<\/li>\n<li>The methods are least squares fits, median absolute deviation, share and concentration comparisons. Everything runs on your server against your own rows. No model is called and nothing leaves the site, and the screen says so rather than implying otherwise.<\/li>\n<li>An incomplete final day is excluded from any trend or forecast, so a range that ends today no longer reads half a day as a collapse.<\/li>\n<li>Direct is excluded from referrer concentration, where counting the absence of a referrer as the largest referrer was a category error.<\/li>\n<\/ul>\n\n<p><strong>Returning readers, if you want them.<\/strong> Settings \u2192 Tracking \u2192 Visitor recognition widens the visitor salt window from one day to 30, 90 or 365. Off by default and staying that way. The setting carries the privacy note it needs: no cookies and nothing stored on the reader's device either way, but you will need to update your own disclosures before turning it on.<\/p>\n\n<h4>1.2.0<\/h4>\n\n<p><strong>Fewer requests, and it stops when your host says stop.<\/strong> If your host has been reporting 429s or rate limiting, this release is for you.<\/p>\n\n<ul>\n<li><strong>The engagement beacon no longer repeats.<\/strong> Switching to another tab and back re-armed it, so a reader who did that five times sent six requests for one page read instead of two. It now sends once, and a second time only if the reader came back and did enough to change the number materially. Never more than twice.<\/li>\n<li><strong>A 429 or 503 is obeyed.<\/strong> The beacon reads the status, honours <code>Retry-After<\/code>, and sends nothing at all until that window has passed. Until now it could not see the response and kept sending into a rate limit, which turns a busy minute into a sustained one.<\/li>\n<li><strong>A request budget per visit.<\/strong> At most one beacon every 0.8 seconds and 60 in a visit. A theme that calls <code>pushState<\/code> in a loop used to be able to produce hundreds of requests from a single reader; measured on 200 route changes, that is 411 requests before and 60 after.<\/li>\n<li><strong>Flood protection now answers 429 with a Retry-After<\/strong> instead of a silent 204, so a flooding client is told to stop rather than ignored and left to continue.<\/li>\n<li><p><strong>A page read costs one request instead of two, and nothing is lost.<\/strong> How a page was read used to be its own request, every time. It now travels inside the next pageview from the same tab, which was going to be sent anyway. A visit to five pages costs six requests instead of ten, and all five readings still arrive. Only the last page of a visit spends a request of its own, because there is no next request to put it in. Nothing to configure and nothing to trade away.\n<strong>More accurate counting.<\/strong> Three reasons a figure here could come out lower than a hosted service reporting on the same site, all addressed.<\/p><\/li>\n<li><p><strong>Readers whose browser ran no JavaScript are now counted.<\/strong> Script blockers, text browsers, accessibility tools and JavaScript simply switched off were invisible to a beacon and missing from every figure. A one pixel image inside a <code>noscript<\/code> tag records them: page and referrer, since screen size and read depth need a script. A browser that runs the beacon never requests it, so it costs nothing on almost every visit. Settings \u2192 Tracking.<\/p><\/li>\n<li><strong>A blocked REST route no longer means lost traffic.<\/strong> Some security plugins harden <code>\/wp-json\/<\/code> off by default and some firewall rules refuse it, and on those sites every beacon was quietly rejected, which looks exactly like undercounting. A pageview refused there is retried once on an ordinary front end URL, and whichever route answered is used for the rest of the visit.<\/li>\n<li><p><strong>Do Not Track is no longer skipped by default on new installs.<\/strong> ConvertNow identifies nobody, sets no cookie, stores no personal data and sends nothing anywhere, so the signal is asking it not to do a thing it does not do, while dropping those readers was the single biggest reason its numbers sat below a service that ignores the signal. Existing sites keep whatever they have; upgrading changes no setting. The switch is still there, and when it is on the signal is now honoured on the pixel as well, not only in the browser.<\/p><\/li>\n<li><p><code>beforeunload<\/code> is no longer used. It duplicated <code>pagehide<\/code> and blocks the browser's back-forward cache.<\/p><\/li>\n<li>Fixed: on a browser without <code>sendBeacon<\/code>, the engagement beacon could be dropped instead of falling back to a keepalive request.<\/li>\n<\/ul>\n\n<h4>1.1.1<\/h4>\n\n<p><strong>Deleting the plugin no longer deletes your data, unless you ask it to.<\/strong><\/p>\n\n<p>Updating a plugin by deleting the old copy and uploading the new one is a normal thing to do, and WordPress runs the uninstall routine on the delete. Until now that meant an update done this way took your settings, your shared dashboard link and every day of history with it. It does not any more: nothing is removed unless <strong>Settings \u2192 Data retention \u2192 If the plugin is deleted<\/strong> says so, and that box says keep by default. A clean removal is still one switch away for anyone who wants it.<\/p>\n\n<p><strong>The AI screens describe AI traffic and nothing else.<\/strong><\/p>\n\n<ul>\n<li>AI at a Glance was drawing a site-wide trend line above assistant-only numbers, and comparing AI against every other channel in a panel. Both are gone. The chart now plots assistant traffic, so the line and the figures under it describe the same visits.<\/li>\n<li>The panels are assistants, assistants over time, and the pages they sent people to.<\/li>\n<\/ul>\n\n<p><strong>Filtering reaches every report.<\/strong><\/p>\n\n<ul>\n<li>Authors, content types, AI assistants, pages cited by AI, UTM mediums and UTM campaigns can all be filtered on now. Previously clicking those names did nothing.<\/li>\n<li>The glance screens carry the open-in-a-new-tab link the report tables already had, so a page name behaves the same wherever it appears.<\/li>\n<li>A filter chip shows the name rather than the stored value: filtering by an author reads \"Author: Amara Okafor\", not \"Author: 4\".<\/li>\n<\/ul>\n\n<h4>1.1.0<\/h4>\n\n<p><strong>AI visibility.<\/strong> Visits arriving from an AI assistant are now counted as their own channel and reported on their own screens.<\/p>\n\n<ul>\n<li>A new <strong>AI Visibility<\/strong> section: AI at a Glance, AI Assistants, Pages Cited by AI, and Fastest Growing Assistants.<\/li>\n<li><strong>AI assistant<\/strong> joins direct, organic search, social, email, referral and paid as a channel, so it appears everywhere a channel appears, including the Overview and the Channels report.<\/li>\n<li>An <strong>AI<\/strong> tab on the Overview's Sources panel.<\/li>\n<li>ChatGPT, Perplexity, Claude, Gemini, Copilot, Grok, DeepSeek, Meta AI and Le Chat are recognised by name. <code>cnwa_ai_sources<\/code> adds more.<\/li>\n<li><strong>Fixed: Gemini was being counted as organic search.<\/strong> Gemini is served from gemini.google.com and Copilot from microsoft.com, so the search-engine rule matched both. Assistants are now tested before search engines. Summaries are rebuilt on upgrade, so past days are reclassified as well.<\/li>\n<li>Crawlers are unaffected: GPTBot, ClaudeBot, CCBot, PerplexityBot and the rest are still refused before a row is written, so nothing on these screens is a machine.<\/li>\n<\/ul>\n\n<p><strong>Chart insights, all off by default.<\/strong> Four statistical layers for the main chart, each switched on separately in Settings.<\/p>\n\n<ul>\n<li>A least squares trend line.<\/li>\n<li>A seven day centred average, which takes the weekday cycle out.<\/li>\n<li>Unusual days, ringed when they sit further from the trend than this site normally varies. The threshold is configurable.<\/li>\n<li>A forecast: the trend carried past today inside a band the width of the measured variation, so an irregular site gets a wide band rather than a confident wrong line.<\/li>\n<li>These are arithmetic, computed in the browser from the numbers already on screen. Nothing is sent anywhere, no model runs and the plugin does not describe them as AI.<\/li>\n<\/ul>\n\n<p><strong>Goals and funnels are easier to build.<\/strong><\/p>\n\n<ul>\n<li>Every goal row now reads its own rule back as a sentence and says how many of your pages match it, updated as you type, so a mistyped path is obvious before you save rather than after an empty report.<\/li>\n<li>Funnel steps can be reordered without deleting and retyping them.<\/li>\n<li>\"Add an empty row\" is now \"Add a goal\" and \"Add a funnel\", and both put the cursor where you are about to type.<\/li>\n<\/ul>\n\n<p><strong>Fixed<\/strong><\/p>\n\n<ul>\n<li>Pages Cited by AI and other path lists no longer truncate the path to a single character in the glance panels.<\/li>\n<\/ul>\n\n<h4>1.0.0<\/h4>\n\n<p>First public release on WordPress.org.<\/p>\n\n<ul>\n<li><strong>Editorial reporting is the point of it.<\/strong> Traffic by author with real display names, Fastest Growing Authors measured against the previous period of the same length, Blog Posts on a screen of their own so the home page stops drowning out the writing, and Content Types splitting posts from pages, products and archives.<\/li>\n<li><strong>Real engagement, not guessed engagement.<\/strong> Bounce rate and time on page come from an engagement beacon rather than from the gap between two timestamps, and read depth is recorded per post.<\/li>\n<li>Pages, entry pages, exit pages, referrers, channels, UTM campaigns, countries, languages, browsers, systems, devices and screen sizes, each on its own screen and in an at a glance summary.<\/li>\n<li>Goals, funnels, journeys and retention, all defined and edited from the report they feed.<\/li>\n<li><strong>Cookieless by design.<\/strong> No cookie, no browser storage, no device fingerprint. Visitors are counted with a daily rotating hash that cannot be reversed or carried across days, and no IP address is ever written to the database.<\/li>\n<li><strong>Self hosted, end to end.<\/strong> Every figure is computed in your own tables. Nothing is sent anywhere, there is no account, no API key and no paid tier.<\/li>\n<li>Country lookup runs locally against a bundled DB-IP table. No lookup service is contacted.<\/li>\n<li>Daily rollups keep the reports fast on large sites, with configurable retention for raw hits, events and summaries.<\/li>\n<li>Weekly email digest, a dashboard widget, a read only shareable dashboard link, CSV export and annotations.<\/li>\n<li>Every table and column name binds through <code>$wpdb-&gt;prepare()<\/code> with the <code>%i<\/code> placeholder, which is why WordPress 6.2 is the minimum. Nothing the plugin runs is assembled from a string.<\/li>\n<li>Report caching is keyed by permission scope, so a payload built for an administrator can never be served to a shared dashboard link.<\/li>\n<\/ul>","raw_excerpt":"Complete website analytics in your own database, with AI assistant traffic as its own channel. Cookieless, self hosted, no paywall.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/uk.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/361489","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/uk.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/uk.wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/uk.wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=361489"}],"author":[{"embeddable":true,"href":"https:\/\/uk.wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/prateekzare"}],"wp:attachment":[{"href":"https:\/\/uk.wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=361489"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/uk.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=361489"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/uk.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=361489"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/uk.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=361489"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/uk.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=361489"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/uk.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=361489"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}