| 开发者 | pluptak |
|---|---|
| 更新时间 | 2026年10月9日 02:04 |
| PHP版本: | 7.4 及以上 |
| WordPress版本: | 7.1 |
| 版权: | GPLv3 or later |
| 版权网址: | 版权信息 |
[avar_analytics] shortcode for public visitor counters (off until you turn it on).window.avarAnalytics.event( 'signup' ) records a custom event, optionally with a value: window.avarAnalytics.event( 'purchase', 49.90 ).window.avarAnalytics.grantConsent() and window.avarAnalytics.revokeConsent() connect any consent banner.wp avar-analytics stats prints the figures of a period (as a table, or JSON with --format=json), wp avar-analytics import brings in historical pageviews from a CSV file, and wp avar-analytics summary looks after the report summaries.avar_an_attribution_form_selectors let other forms receive the attribution token.If what you need is visitors, pages, traffic sources, campaigns, goals, forms and WooCommerce revenue, yes — without sending anything to Google. It does not build advertising audiences or long-term visitor profiles, by design.
The default cookieless mode is designed to minimise personal data collection and sets no analytics cookies. Whether consent (or a banner) is required still depends on your configuration, the features you enable and the laws that apply to you, so please confirm this against your own legal requirements. If you switch on the optional first-party cookie mode, treat it like any other first-party analytics cookie. If you turn on "Require consent before tracking", nothing is recorded — in the browser or on the server — until consent is granted.
In cookieless mode each visitor is reduced to a short-lived pseudonymous identifier: an HMAC of the current date in your site's timezone, the visitor's IP address and user agent, keyed with a secret generated on your site at activation. This is pseudonymisation, not anonymisation, and it is described here so you can judge it yourself. No analytics cookie is set, the raw IP is never stored and the secret never leaves your server. Because the date is part of the identifier, it changes every day and is not designed for cross-day profiling. The tracker keeps a temporary visit id in the browser's session storage for the current visit only.
The tracker is a small script that loads without blocking your page. It sends one request when a page is viewed and a short one when the visitor leaves or hides it (time on page, scroll depth), plus one for each click you chose to measure and each custom event your site sends. It works with page caching, because all of this happens in the browser. Reports stay fast on large sites because they read compact daily summaries.
From a local IP-to-country database (DB-IP Lite) that ships with the plugin and is read on your own server — it works out of the box, with no account and no per-lookup calls. Behind Cloudflare, or a proxy you configured that sends a country header, that header is used first. You can also point the plugin at your own MaxMind GeoLite2-Country database. The plugin can download an updated country database from DB-IP, but visitor IP addresses are never sent to DB-IP (see External services).
With a consent plugin that uses the WP Consent API, turn on "Require consent before tracking": nothing is recorded until the visitor allows statistics, and no further wiring is needed. A visitor who refuses statistics is not tracked even when that setting is off. For any other banner, turn on "Require consent before tracking" and call window.avarAnalytics.grantConsent() when the visitor accepts and window.avarAnalytics.revokeConsent() when they withdraw (or dispatch the avar-analytics-consent-granted and avar-analytics-consent-revoked document events). If you configure a consent cookie in the settings, that cookie decides. Until consent is granted, nothing is recorded: pageviews, events, form submissions, purchases and site searches are all held back.
No content, ever. A form submission stores the form's name, the page and the time, with the same pseudonymous visitor and visit references a pageview carries — never field values, names, email addresses, phone numbers or messages. A WooCommerce purchase stores the order total and the time with those same references — never the order number or any customer details. Their traffic source is worked out from the visit when you open a report.
The tracker receives a short-lived, signed token that contains only an opaque visit reference and a timestamp, and adds it as a hidden field to the forms that read it: Contact Form 7, WPForms, Fluent Forms, Elementor Pro forms and the WooCommerce checkout. Other forms can opt in with a data-avar-analytics-attribution attribute or the avar_an_attribution_form_selectors filter. When a form is sent, the server checks the token's signature and age and credits the submission to that visit's traffic source; for an order, the check happens at checkout and the result is kept on the order for up to 30 days, so a payment that completes later within those 30 days keeps its source. Without a valid token the event is recorded as unattributed rather than credited to the wrong source.
Yes. The [avar_analytics] shortcode shows one site-wide figure — metric="visitors" (default), "pageviews" or "sessions" — for range="30d" (default), "today", "7d", "90d", "month" or "12mo", with an optional label. Counters stay off until an administrator turns on Settings → Display → Public counters. While they are on, anyone who can write posts on your site — including a Contributor previewing a draft — can place a counter and see those site-wide totals, which is why it is your choice and not the default.
Yes. Each site of the network keeps its own statistics and settings, and network administrators get a network overview with the totals of every site.
Yes, from the command line: wp avar-analytics import file.csv reads daily pageviews per page and source (columns day,path,source,pageviews). Running the same file again adds nothing twice.
No. Everything lives in your own database. Export it as CSV at any time, or erase it with one click.