[WordPress] 外掛分享: DevDome Analytics – WordPress Analytics, Visitor Stats & AI Bot Tracking

首頁外掛目錄 › DevDome Analytics – WordPress Analytics, Visitor Stats & AI Bot Tracking
WordPress 外掛 DevDome Analytics – WordPress Analytics, Visitor Stats & AI Bot Tracking 的封面圖片
50+
安裝啟用
★★★★★
5/5 分(1 則評價)
剛更新
最後更新
問題解決
WordPress 6.0+ PHP 7.4+ v1.1.0 上架:2026-07-30

內容簡介

DevDome Analytics 是一款 WordPress 外掛,提供即時訪客統計、網站流量分析及機器人追蹤功能,幫助用戶清楚了解真實訪客與自動化流量的區別,並提供詳細的網站分析報告。

【主要功能】
• 即時訪客統計與流量分析
• 機器人與 AI 爬蟲追蹤
• 外部連結點擊追蹤
• 隱私控制選項
• 無需在 WordPress 數據庫中儲存分析數據

外掛標籤

開發者團隊

⬇ 下載最新版 (v1.1.0) 或搜尋安裝

① 下載 ZIP → 後台「外掛 › 安裝外掛 › 上傳外掛」
② 後台搜尋「DevDome Analytics – WordPress Analytics, Visitor Stats & AI Bot Tracking」→ 直接安裝(推薦)
📦 歷史版本下載

原文外掛簡介

WordPress Analytics & Visitor Tracking
DevDome Analytics is a WordPress analytics plugin for real-time visitor statistics, website traffic analytics, visitor tracking, bot detection, AI crawler tracking, traffic sources, pageviews, sessions, and outbound click tracking.
See how many real people visit your WordPress site while bots and AI crawlers are measured separately, so automated traffic does not inflate your human visitor statistics.
A lightweight Google Analytics alternative for WordPress that stores no analytics data in custom tables inside your WordPress database.
Real-Time WordPress Analytics
Track visitors, pageviews, sessions, live visitors, top pages, traffic sources and referrers, countries, devices and browsers, outbound link clicks, bots, AI crawlers, and AI referral traffic.
Key visitor statistics appear directly inside WordPress, while your DevDome dashboard provides detailed website analytics reports covering periods from the last 24 hours up to 12 months.
Separate Real Visitors From Bots
Search engines, SEO crawlers, monitoring services, and AI bots constantly request WordPress websites. DevDome Analytics detects known bots and reports them separately from human visitors.
Detected crawlers include Googlebot, Bingbot, GPTBot, ChatGPT-User, ClaudeBot, PerplexityBot, Google-Extended, CCBot, AhrefsBot, SemrushBot, and other known crawlers.
Unknown or deliberately disguised bots may not always be identifiable.
AI Crawler Tracking & AI Referral Traffic
See which AI crawlers visit your WordPress website. Known AI bots are identified separately from search-engine bots and human traffic, helping you understand when services such as ChatGPT, Claude, Perplexity, and Google-Extended access your content.
The plugin reports detected crawlers. It does not block them.
DevDome Analytics can also identify visits referred by supported AI assistants such as ChatGPT and Perplexity, helping you measure AI referral traffic separately from other website traffic sources.
Outbound Click Tracking
Track clicks on links that take visitors away from your WordPress site, including affiliate links, product links, partner websites, social profiles, and other external destinations.
Outbound clicks can be relayed through your own WordPress server so they can continue to be measured when ordinary third-party analytics requests are blocked.
Cookieless & First-Party Analytics
General website analytics are cookieless on new installations.
Returning-visitor tracking is optional and disabled by default. Outbound click tracking can use random visitor and session identifiers when a visitor clicks an external link and can also be disabled independently.
First-Party Delivery is available on supported DevDome plans. When enabled, the analytics script is served from your own domain and tracking events are relayed through your WordPress server using randomized site-specific paths.
This can reduce analytics data loss caused by browser extensions and ad blockers that target known third-party analytics domains, although no tracking method can guarantee detection of every visit.
Privacy Controls
You can independently enable or disable analytics tracking, returning visitor tracking, outbound click tracking, AI referral tracking, and bot and crawler tracking.
Administrators and editors are excluded by default, additional WordPress roles can be excluded, and the browser Do Not Track signal is respected by default.
DevDome Analytics does not collect form field values, post content, WordPress user accounts, customer data, order data, or activity inside wp-admin.
No Analytics Tables in WordPress
Analytics events are processed by the hosted DevDome Analytics service instead of being stored in custom analytics tables inside your WordPress database.
A free DevDome account is required because analytics events are processed and reports are generated by the hosted service.
No visitor data is tracked or sent until the site is connected (the DevDome Tools dashboard’s plugin catalog request and the connection-status check on the plugin’s own screen are described below).
AI and Agent Support
On WordPress 6.9 and newer, DevDome Analytics registers WordPress Abilities covering the plugin: connection status, the traffic numbers of the last 1, 7 or 30 days (the same the dashboard shows), every tracking setting (read and update), the connection test, the one-click connect link, disconnect and data reset. Compatible AI agents and MCP clients can discover and use these abilities when the site exposes them, for example through the official WordPress MCP Adapter. Every ability runs the same code as the plugin screen under the same administrator capability; disconnect and data reset require an explicit confirmation and are annotated destructive; agent output never carries e-mail addresses or the site token. Nothing is sent to DevDome for an unconnected site.
External services
Error reports (devdome.com), only when you press “Report this error” on an error message. The plugin sends the error text, the plugin, WordPress and PHP versions, the screen you were on, its connection state (flags and timestamps, secrets masked), your site address and your admin e-mail (so support can reply) to https://devdome.com/api/plugin/error-report. Nothing is sent unless you press the button. Service provider: DevDome. Terms: https://devdome.com/terms-of-service Privacy policy: https://devdome.com/privacy-policy
Plugin catalog (devdome.com). The DevDome Dashboard inside wp-admin fetches the list of DevDome plugins (names, descriptions, logos, links, WordPress.org slugs) from https://devdome.com/wp-plugins/catalog.json at most once every 12 hours, so the list stays current. Only the bundled core version is sent in the request; no site or visitor data. Service provider: DevDome. Terms: https://devdome.com/terms-of-service Privacy policy: https://devdome.com/privacy-policy
DevDome Analytics is a connector for the DevDome Analytics service. It talks to two hosts, both operated by DevDome.
Terms of service: https://devdome.com/terms-of-service
Privacy policy: https://devdome.com/privacy-policy
analytics.devdome.com – the analytics service
The tracking script, https://analytics.devdome.com/track.js
Loaded in your visitors’ browsers on public pages, once the site is connected and Enable Tracking is on. It is not added to your pages before you connect. With First-Party Delivery on, a copy of this script that ships inside the plugin is placed in your uploads folder and served from your own domain instead; nothing is downloaded from DevDome for it.
The event ingest, https://analytics.devdome.com/api/event
This is where analytics events are recorded, and there are four ways it is reached.

From the visitor’s browser, by the tracking script above. While Track Clicks is on, a site search also sends the search words typed into your site’s search form (up to 200 characters). Each event carries: your Site ID (this site’s domain), your DevDome Account ID, the page URL and path, the page title, the referring URL, browser, operating system, device type, user agent, browser language, country, the target URL of a click, and a visitor ID and session ID only when the browser is storing them (see Privacy). The browser contacts the service directly, so its IP address is visible to it, as with any web server.
From your server, when it forwards an outbound-link click. The visitor’s browser sends the click to the /dd-e path on your own domain and your server relays it. Your server adds two fields to that relayed event: the visitor’s country code and the visitor’s IP address, so location and per-visitor counts stay correct when the event arrives from your server instead of from the browser.
From your server, when First-Party Delivery is on: the visitor’s browser sends every tracking event (the same fields as item 1) to a randomized path on your own domain and your server relays it, authenticated with this site’s secret token. The relay adds the same two fields as item 2, the visitor’s country code and the visitor’s IP address, and forwards nothing else: each event is rebuilt from an allowlist and the site and account identity always come from the plugin’s own settings.
From your server, when a known crawler requests a page and Track Bot Visits is on. That event carries the crawler’s user agent, the bot name and type, the requested URL and path, your Site ID and a timestamp. No human visitor data is in it.

The plan check, https://analytics.devdome.com/api/plugin/entitlements
Asks whether this site’s DevDome plan includes First-Party Delivery. Sent only on a connected site: when you turn the switch on, once a day by the refresh job while it is on, and while the Analytics screen is open at most once every two minutes so a plan change shows quickly. It carries your Site ID and this site’s secret token. No visitor data.
The connection handshake, https://analytics.devdome.com/api/plugin/status
Sent when you connect the site and when the connection is re-verified. Contains your Site ID, this site’s secret token, your Account ID, the site URL, the site name, the site administrator’s email address, the WordPress version, the PHP version, the plugin version, the active theme name, the timezone, the site language and whether this is a multisite install. No visitor data.
A shorter form (Site ID and secret token only) also runs when you open the plugin’s screen, at most once per 15 minutes: a site already connected on devdome.com shows as connected here without a second connect step. No visitor data, nothing on public pages.
The one-click connect handshake, https://analytics.devdome.com/api/plugin/connect/start and /api/plugin/connect/claim
connect/start runs only when you press the “Connect Via DevDome Account” button, never on its own (opening the plugin’s screen makes only the connection-status check described above). It sends this site’s domain, its secret token and the wp-admin address to return to, and receives a short-lived connect link. connect/claim runs when your browser returns from devdome.com and exchanges that link for your Account ID.
The stats read, https://analytics.devdome.com/api/plugin/stats
Sends your Site ID, this site’s secret token (so only your own site can read its numbers) and the selected day range. Used to fill the Overview tiles in wp-admin, and the bot-visit figure shared with DevDome Bot Protection when that plugin is installed.
Deleting your data, https://analytics.devdome.com/api/plugin/purge
Sends your Site ID and this site’s secret token, and only when you press Reset Analytics, or tick “Also delete my data on DevDome” while disconnecting.
api.devdome.com – DevDome account services
These two are made by the shared DevDome library bundled with every plugin in the suite.
The account check, https://api.devdome.com/plugin/account
A POST carrying this site’s domain and its secret token, answered with the Account ID and account email address that the token belongs to, so the DevDome screen can show which account this site is linked to. It runs when a DevDome admin screen is displayed and its cached answer has expired: a good answer is kept fifteen minutes (so a plan change shows quickly), a refusal one hour, an outage ten minutes. Never before you have acted: until you press a Connect button, save an Account ID or complete a connection, this check is not made at all.
Disconnecting, https://api.devdome.com/plugin/disconnect
A POST carrying this site’s domain and its secret token, sent only when you press Disconnect, to unlink the site from the account.
Not contacted on this WordPress.org build
The bundled shared library also references endpoints this build never calls: the https://api.devdome.com/bot-protection/ signature feeds (used by other DevDome plugins; never fetched here, no cron scheduled) and https://api.devdome.com/plugin-updates/ (self-hosted updates, disabled here; updates come from WordPress.org).
devdome.com
https://devdome.com/connect/ is a link you click, not a request the plugin makes. Your browser goes there to sign in and approve the connection, and comes back. The only server-side requests to devdome.com are the two listed above: the plugin catalog (at most every twelve hours) and an error report you send by pressing the button.

Never sent, in any request

Passwords and password hashes.
Form field values submitted by visitors. The one exception is the text typed into the site’s own search box, recorded as the site-search term of that visit (only while tracking and click tracking are on).
Post, page, comment or any other WordPress content.
User accounts, user lists, or the email addresses of your registered users. The exceptions are the site’s administration email address, sent once during the connection handshake described above, and the error report you send yourself with “Report this error”, which carries it so support can reply.
Customer, order or payment data.
Anything at all about what happens inside wp-admin.

Privacy
What is stored on your site. Roughly thirty option rows: the tracking switches, the service addresses, this site’s ID and secret token, your Account ID and account email, the timestamp of the connection, and, for First-Party Delivery, the switch itself and the randomized path and file names generated for this site. When that switch is on, two JavaScript files (the tracking script and the bundled bot detector, both copied out of the plugin’s own package) are placed under your uploads folder; both are removed at uninstall. Nothing else. No custom tables, no post meta, no user meta, and not one analytics event. The short-lived transients: a connect handle (10 minutes), the cached bot-visit figure (1 hour), the cached plan answer for First-Party Delivery (a day), and flood counters for the /dd-e and First-Party relay endpoints that live for 2 minutes and are keyed by an MD5 hash of the visitor’s IP address.
Public paths the plugin adds. Up to four. /dd-e (only while connected) accepts the outbound-click beacon described in External services; it answers empty to everything else, requires the browser’s own same-site Origin header, ignores requests from excluded roles, is rate limited per IP address and stores nothing. The First-Party Delivery relay (only while that switch is on) is a randomized path unique to your site that accepts the tracking events described in External services under the same rules and stores nothing; its own per-IP limit runs when the site has a persistent object cache (without one, the DevDome service’s per-site limit applies). /.well-known/devdome-analytics.txt (only while connected) returns one short line of fixed text, so DevDome can confirm the plugin really is installed on the domain you connected. /.well-known/devdome-connect-proof.txt returns a one-way SHA-256 fingerprint of this site’s secret token (never the token itself), so DevDome can confirm during connection that the request really came from this site.
What is stored on a visitor’s device. Two settings decide this, and they are independent of each other.

Track Returning Visitors, off on new installs. While it is off, the DevDome tracking script writes nothing at all: no cookie, no localStorage, no sessionStorage. Unique visitors are still counted, using an identifier DevDome derives on its own server from the request (site, date, IP address and user agent, combined with a secret key); it changes daily, differs per site, and cannot be reversed to identify a person. The trade-off: a visitor who returns tomorrow counts as new. Turning the setting on stores a random visitor ID in a first-party cookie and localStorage, plus a session ID in sessionStorage, so the same person is recognised across days and a click can be tied back to its visit. Random values, nothing personal in them, but they are storage on a visitor’s device, so you may need visitor consent for it. The setting says so where you switch it on.
Track Outbound Links, on by default. The built-in click detector counts clicks on links that leave your site. With Track Returning Visitors off it keeps its two random ids in memory only, for the page you are on, and stores nothing on the device; with Track Returning Visitors on it stores them like the page tracker does, so the …

延伸相關外掛

文章
Filter
Mastodon