AVAR Analytics

Description

AVAR Analytics shows you how your website is doing — who visits, what they read, where they come from and what they do — right in your WordPress admin. There is no tracking code to paste, no external dashboard to log in to and, by default, no analytics cookie. Every pageview is recorded by your own site and stored in your own database.

It is made for site owners who want clear numbers they can trust without handing their visitors’ data to a third party, and for agencies who want the same on every client site. Activate it and it starts counting.

Why AVAR Analytics

  • Private by design. Cookieless by default. Raw IP addresses are never stored: the IP is used in memory to work out the country and a pseudonymous daily identifier, then discarded.
  • Your data stays yours. Everything lives in your WordPress database. Export it as CSV or erase it with one click, whenever you like.
  • Numbers you can trust. Known bots and obvious automated traffic are filtered. AVAR Analytics uses browser-confirmed tracking for visitor-facing reports to reduce scanner and crawler noise.
  • Built into WordPress. Reports sit in wp-admin next to your content, with a summary on the dashboard. Nothing to configure before the first visit is counted.
  • Fast on large sites. Reports read compact daily summaries instead of every stored pageview, so they stay quick as your history grows: an Overview of 30 days opened in under a second on a test site with 1.4 million pageviews.
  • All features free. No locked reports, no upgrade screens.

Everything you need to understand your traffic

  • Overview — unique visitors, pageviews, visits, views per visit, bounce rate and average visit, each compared with the previous period, plus a trend chart that shows a day’s figures beside the pointer as you move across it.
  • Real-time — visitors active in the last five minutes and a live feed of recent pageviews.
  • Pages and content — most-viewed pages, landing and exit pages, and traffic by author, category and post type, with the biggest gains and drops against the previous period.
  • Sources and campaigns — direct, organic search, social, referral, paid and campaign traffic, top referrers and UTM campaigns, with a Campaign URL Builder to tag your links.
  • Countries and devices — visitors by country, device type, browser and operating system. Country detection works out of the box with a database bundled with the plugin and read on your own server.
  • Engagement — time on page, scroll depth and a weekday × hour heatmap of when your visitors come.
  • Segments — click a source, country, device, browser or operating system to filter the Overview, Pages, Sources, Countries and Devices reports to it.
  • Dashboard summary — today against yesterday, visitors active now and the last 30 days with their chart, on the WordPress dashboard. The wider the widget, the more it shows: visits, bounce rate and average visit, then top pages, sources, countries and devices.
  • Chart annotations — mark a launch or a campaign on the trend chart.

Conversions, forms and WooCommerce

  • Goals — build goals from page visits, link clicks, file downloads or custom events, and see conversions and conversion rate per source and campaign.
  • Events — outbound links, file downloads, internal site search (including searches that found nothing) and email, phone, SMS and WhatsApp link clicks are tracked automatically. Add your own events with one line of JavaScript.
  • Form analytics — submissions and the traffic source behind them for Contact Form 7, WPForms, Fluent Forms and Elementor Pro forms, without storing anything a visitor typed.
  • WooCommerce essentials — orders, gross revenue, average order value, store conversion rate and revenue by source and campaign. Works with the classic and the block checkout and with high-performance order storage (HPOS). No customer data is stored.
  • 404 report — broken links your visitors actually hit, with where they came from.

Privacy you can explain to your visitors

  • Cookieless mode (default) — no analytics cookies. A visitor is counted with a pseudonymous identifier that changes every day, and a temporary visit id is kept in the browser’s session storage for the current visit only.
  • Optional first-party cookie mode — counts returning visitors across days more precisely, for sites whose consent setup allows it.
  • Consent before tracking (optional) — nothing is recorded, in the browser or on the server, until the visitor agrees. Consent plugins that use the WP Consent API need no wiring (tested with Complianz); any other banner can call a two-line JavaScript API. A refusal recorded by a WP Consent API plugin, or in the consent cookie you configure, is honoured even when consent is not required.
  • Do Not Track and Global Privacy Control are respected (on by default), and you can exclude user roles, IP addresses, user agents, paths, post types and single posts.
  • Forms and orders stay private. No field values, names, email addresses, phone numbers, messages or order numbers are ever stored.

Cookieless mode is designed to minimise personal data collection. Whether you need consent still depends on your configuration, the features you enable and the laws that apply to you.

Built for real-world sites

  • Works with full-page caching: everything is sent from the visitor’s browser.
  • Correct behind Cloudflare and reverse proxies. Proxy headers are trusted only when the request really comes from your proxy, so they cannot be spoofed from outside.
  • A Data & Health screen checks tracking, the database, scheduled tasks, storage and geolocation, and tells you how to fix what is wrong.
  • Configurable data retention. Days older than your window are removed in small nightly batches, while the daily totals behind your trend charts are kept.
  • Weekly or monthly email summaries, CSV export, an optional admin-bar counter and an [avar_analytics] shortcode for public visitor counters (off until you turn it on).
  • Multisite ready: every site keeps its own statistics, and network administrators get a network overview.
  • Read-only report access for the roles you choose; settings stay with administrators.

For developers

  • window.avarAnalytics.event( 'signup' ) records a custom event, optionally with a value: window.avarAnalytics.event( 'purchase', 49.90 ).
  • window.avarAnalytics.grantConsent() and window.avarAnalytics.revokeConsent() connect any consent banner.
  • WP-CLI: wp avar-analytics stats prints the figures of a period (as a table, or JSON with --format=json), wp avar-analytics import brings in historical pageviews from a CSV file, and wp avar-analytics summary looks after the report summaries.
  • Filters such as avar_an_attribution_form_selectors let other forms receive the attribution token.

How the numbers are measured

  • Visitors — distinct people in the period. In cookieless mode a visitor is one pseudonymous daily identifier, so the same person on two days counts twice; in cookie mode they are counted once across days.
  • Visits — a visit ends after 30 minutes of inactivity; continued activity keeps extending it.
  • Bounce rate — the share of visits that viewed exactly one page.
  • Time on page — seconds while the page was actually visible, measured in the browser and sent as one summary when the visitor leaves.
  • Attribution — a conversion (a goal, a form submission or an order) is credited to the source and campaign of the visit it happened in, taken from that visit’s landing page. UTM parameters take priority over the referrer.

Part of AVAR Tools

AVAR Analytics belongs to AVAR Tools, a family of focused, privacy-friendly WordPress plugins by AVAR. Install more than one and they share a single AVAR Tools menu with a combined dashboard.

External services

AVAR Analytics does not send your visitors’ analytics data to any external service. All tracking data is stored in your own WordPress database.

The only optional outbound connection is the country database updater. When you turn on automatic updates (off by default) or click “Update database now”, the plugin downloads an updated IP-to-country database file from DB-IP (https://db-ip.com, download endpoint https://download.db-ip.com). Only a database file is downloaded; no visitor IP address or any other visitor data is sent to DB-IP. Like any download, the request shows DB-IP your server’s IP address, and it names the plugin and its version in its user agent (“AVAR-Analytics/” and the version number); it does not carry your site’s address. Country lookups themselves always happen locally on your server, against the bundled or the downloaded database. DB-IP’s terms of service: https://db-ip.com/tos.php. DB-IP’s privacy policy: https://db-ip.com/privacy.php.

If you choose the Cloudflare or reverse-proxy connection mode, the plugin reads the country from a request header set by that proxy; it does not contact the proxy itself.

Credits

This product includes IP-to-country data created by DB-IP (https://db-ip.com), licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/).

Screenshots

Installation

  1. In your WordPress admin, go to Plugins Add New Plugin, search for “AVAR Analytics” and click Install Now, or upload the plugin ZIP there.
  2. Activate it. Tracking starts right away — there is no code to paste.
  3. Open Analytics in the admin menu (or AVAR Tools Analytics when you run more than one AVAR Tools plugin).
  4. Optionally, review privacy, consent, exclusions and display options on the Settings tab.

FAQ

Can AVAR Analytics replace Google Analytics?

If what you need is visitors, pages, traffic sources, campaigns, goals, forms and WooCommerce revenue, yes — without sending anything to Google. It does not build advertising audiences or long-term visitor profiles, by design.

Do I need a cookie-consent banner?

The default cookieless mode is designed to minimise personal data collection and sets no analytics cookies. Whether consent (or a banner) is required still depends on your configuration, the features you enable and the laws that apply to you, so please confirm this against your own legal requirements. If you switch on the optional first-party cookie mode, treat it like any other first-party analytics cookie. If you turn on “Require consent before tracking”, nothing is recorded — in the browser or on the server — until consent is granted.

How are unique visitors counted without cookies?

In cookieless mode each visitor is reduced to a short-lived pseudonymous identifier: an HMAC of the current date in your site’s timezone, the visitor’s IP address and user agent, keyed with a secret generated on your site at activation. This is pseudonymisation, not anonymisation, and it is described here so you can judge it yourself. No analytics cookie is set, the raw IP is never stored and the secret never leaves your server. Because the date is part of the identifier, it changes every day and is not designed for cross-day profiling. The tracker keeps a temporary visit id in the browser’s session storage for the current visit only.

Does it slow down my site?

The tracker is a small script that loads without blocking your page. It sends one request when a page is viewed and a short one when the visitor leaves or hides it (time on page, scroll depth), plus one for each click you chose to measure and each custom event your site sends. It works with page caching, because all of this happens in the browser. Reports stay fast on large sites because they read compact daily summaries.

Where does the country come from?

From a local IP-to-country database (DB-IP Lite) that ships with the plugin and is read on your own server — it works out of the box, with no account and no per-lookup calls. Behind Cloudflare, or a proxy you configured that sends a country header, that header is used first. You can also point the plugin at your own MaxMind GeoLite2-Country database. The plugin can download an updated country database from DB-IP, but visitor IP addresses are never sent to DB-IP (see External services).

Does it work with my consent banner?

With a consent plugin that uses the WP Consent API, turn on “Require consent before tracking”: nothing is recorded until the visitor allows statistics, and no further wiring is needed. A visitor who refuses statistics is not tracked even when that setting is off. For any other banner, turn on “Require consent before tracking” and call window.avarAnalytics.grantConsent() when the visitor accepts and window.avarAnalytics.revokeConsent() when they withdraw (or dispatch the avar-analytics-consent-granted and avar-analytics-consent-revoked document events). If you configure a consent cookie in the settings, that cookie decides. Until consent is granted, nothing is recorded: pageviews, events, form submissions, purchases and site searches are all held back.

Does it store anything from my forms or orders?

No content, ever. A form submission stores the form’s name, the page and the time, with the same pseudonymous visitor and visit references a pageview carries — never field values, names, email addresses, phone numbers or messages. A WooCommerce purchase stores the order total and the time with those same references — never the order number or any customer details. Their traffic source is worked out from the visit when you open a report.

How does attribution work without a cookie?

The tracker receives a short-lived, signed token that contains only an opaque visit reference and a timestamp, and adds it as a hidden field to the forms that read it: Contact Form 7, WPForms, Fluent Forms, Elementor Pro forms and the WooCommerce checkout. Other forms can opt in with a data-avar-analytics-attribution attribute or the avar_an_attribution_form_selectors filter. When a form is sent, the server checks the token’s signature and age and credits the submission to that visit’s traffic source; for an order, the check happens at checkout and the result is kept on the order for up to 30 days, so a payment that completes later within those 30 days keeps its source. Without a valid token the event is recorded as unattributed rather than credited to the wrong source.

Can I show a visitor count on my site?

Yes. The [avar_analytics] shortcode shows one site-wide figure — metric="visitors" (default), "pageviews" or "sessions" — for range="30d" (default), "today", "7d", "90d", "month" or "12mo", with an optional label. Counters stay off until an administrator turns on Settings Display Public counters. While they are on, anyone who can write posts on your site — including a Contributor previewing a draft — can place a counter and see those site-wide totals, which is why it is your choice and not the default.

Does it work on multisite?

Yes. Each site of the network keeps its own statistics and settings, and network administrators get a network overview with the totals of every site.

Can I import my existing statistics?

Yes, from the command line: wp avar-analytics import file.csv reads daily pageviews per page and source (columns day,path,source,pageviews). Running the same file again adds nothing twice.

Is my data locked in?

No. Everything lives in your own database. Export it as CSV at any time, or erase it with one click.

Reviews

There are no reviews for this plugin.

Contributors & Developers

“AVAR Analytics” is open source software. The following people have contributed to this plugin.

Contributors

Translate “AVAR Analytics” into your language.

Interested in development?

Browse the code, check out the SVN repository, or subscribe to the development log by RSS.

Changelog

1.2.2

  • Initial release on WordPress.org.