DevDome Analytics: Visitor Tracker, Site Stats & Bot Detection
DevDome Analytics: Visitor Tracker, Site Stats & Bot Detection

DevDome Analytics: Visitor Tracker, Site Stats & Bot Detection

5/5 (1 ratings) 60 active installs Updated Sep 22, 2026
DevDome Analytics inside wp-admin: visitors, live visitors, bots, clicks, pageviews, pages per visit, session duration and bounce rate.

DevDome Analytics inside wp-admin: visitors, live visitors, bots, clicks, pageviews, pages per visit, session duration and bounce rate.

DevDome Analytics is a WordPress visitor tracker for real-time website statistics, traffic sources, sessions and outbound clicks. It reports known bots and AI crawlers separately from human visitors, so detected automated traffic does not inflate your visitor stats. A free DevDome account is required to process analytics events and generate reports through the hosted service.

Site stats and real-time visitors

Use DevDome as a traffic monitor to see visits as they happen and review website traffic over time. Key metrics appear inside WordPress; detailed web analytics reports in your DevDome dashboard cover periods from the last 24 hours up to 12 months.

The reports include:

  • Visitors, unique visitors, live visitors, pageviews and sessions.
  • Top pages, traffic sources and referrers.
  • Countries, devices, operating systems and browsers.
  • Outbound link clicks, bot hits, AI crawlers and AI referral traffic.
  • Pages per visit, session duration and bounce rate.

The live visitor count answers how many people are visiting now. These real time visitors are shown as aggregate traffic stats, without identifying WordPress user accounts.

Page views and blog stats

Review page views and post views in the Pages report to find popular posts and other frequently visited content. Per-page reports include visits, visitors, pageviews, referrers, outbound clicks, countries, browsers, operating systems and devices.

For private reporting, the visitor counter and page view counter provide different measures: how many visitors arrived and how many pages they viewed. This website counter is part of your analytics reports; the plugin does not provide a public counter widget.

Bot detection and AI crawler tracking

Search engines, SEO crawlers, monitoring services and AI bots request WordPress pages. DevDome Analytics detects known crawlers and separates them from human traffic in your visitor analytics.

Detected crawlers include Googlebot, Bingbot, GPTBot, ChatGPT-User, ClaudeBot, PerplexityBot, Google-Extended, CCBot, AhrefsBot, SemrushBot and other known crawlers. Unknown, new or deliberately disguised bots may not always be identifiable.

Known AI bots are also distinguished from search-engine bots, helping you see when services such as ChatGPT, Claude, Perplexity and Google-Extended access your content. The plugin reports detected crawlers. It does not block them.

AI referral tracking identifies visits referred by supported assistants, including ChatGPT and Perplexity, separately from other traffic sources.

Outbound click tracking and event tracking

Track clicks on links that leave your WordPress site, including:

  • Affiliate and product links.
  • Partner websites.
  • Social profiles and other external destinations.

The link click counter records outbound clicks in your reports. Clicks can be relayed through your own WordPress server so they can continue to be measured when ordinary third-party analytics requests are blocked.

Event tracking also covers the documented page activity and, while Track Clicks is on, searches made through your site’s search form. Search terms are limited to 200 characters. External services below lists the fields sent with each event.

Cookieless analytics and First-Party Delivery

General website analytics are cookieless on new installations. Track Returning Visitors is optional and disabled by default.

Outbound click tracking can use random visitor and session identifiers when someone clicks an external link. With returning-visitor tracking off, those identifiers stay in memory for the current page. Outbound tracking can be disabled independently.

First-Party Delivery is available on supported DevDome plans. When enabled, the analytics script is served from your own domain and events are relayed through your WordPress server using randomized paths specific to your site.

This can reduce data loss caused by browser extensions and ad blockers that target known third-party analytics domains. No tracking method guarantees detection of every visit.

Tracking settings and privacy controls

You control collection through separate settings:

  • Enable Tracking is the master switch.
  • Track Returning Visitors controls recognition across days.
  • Track Clicks and Track Outbound Links control click collection.
  • Track AI Referrals controls AI referral identification.
  • Track Bot Visits controls bot and crawler reporting.

Administrators and editors are excluded by default on new installations. You can exclude additional WordPress roles. The browser Do Not Track signal is respected by default.

DevDome Analytics does not collect post content, WordPress user accounts, customer data, order data or activity inside wp-admin. It does not collect visitor form field values except the site’s own search terms when tracking and click tracking are enabled. Full transmission and storage details appear below.

Hosted reports without WordPress analytics tables

DevDome is a lightweight Google Analytics alternative for WordPress. Analytics events are processed by the hosted DevDome Analytics service, with no custom analytics tables or analytics event storage inside your WordPress database.

The WordPress Overview tab shows key metrics. Your DevDome account provides full traffic, referral, click, location, device and crawler reports.

No visitor data is tracked or sent until the site is connected. The DevDome Tools dashboard’s plugin catalog request and the connection-status check on the plugin’s own screen are described under External services.

AI and agent support

On WordPress 6.9 and newer, DevDome Analytics registers WordPress Abilities for:

  • Connection status and traffic numbers for the last 1, 7 or 30 days, matching the dashboard.
  • Reading and updating every tracking setting.
  • Testing the connection and obtaining the one-click connect link.
  • Disconnecting and resetting data.

Compatible AI agents and MCP clients can discover and use these abilities when the site exposes them, for example through the official WordPress MCP Adapter.

Every ability runs the same code as the plugin screen under the same administrator capability. Disconnect and data reset require explicit confirmation and are annotated destructive. Agent output never carries email addresses or the site token.

On an unconnected site, only abilities you deliberately invoke contact DevDome: the confirmed connect-link request and the connection test. The pre-connection requests are detailed under External services.

External services

Error reports (devdome.com), only when you press “Report this error” on an error message. The plugin sends the error text, the plugin, WordPress and PHP versions, the screen you were on, its connection state (flags and timestamps, secrets masked), your site address and your admin e-mail (so support can reply) to https://devdome.com/api/plugin/error-report. Nothing is sent unless you press the button. Service provider: DevDome. Terms: https://devdome.com/terms-of-service Privacy policy: https://devdome.com/privacy-policy

Plugin catalog (devdome.com). The DevDome Dashboard inside wp-admin fetches the list of DevDome plugins (names, descriptions, logos, links, WordPress.org slugs) from https://devdome.com/wp-plugins/catalog.json at most once every 12 hours, so the list stays current. Only the bundled core version is sent in the request; no site or visitor data. Service provider: DevDome. Terms: https://devdome.com/terms-of-service Privacy policy: https://devdome.com/privacy-policy

DevDome Analytics is a connector for the DevDome Analytics service. Its analytics and account requests use two hosts, both operated by DevDome. The separate catalog and optional error-report requests to devdome.com are described above.

Terms of service: https://devdome.com/terms-of-service
Privacy policy: https://devdome.com/privacy-policy

analytics.devdome.com – the analytics service

The tracking script, https://analytics.devdome.com/track.js

Loaded in your visitors’ browsers on public pages, once the site is connected and Enable Tracking is on. It is not added to your pages before you connect. With First-Party Delivery on, a copy of this script that ships inside the plugin is placed in your uploads folder and served from your own domain instead; nothing is downloaded from DevDome for it.

The event ingest, https://analytics.devdome.com/api/event

This is where analytics events are recorded, and there are four ways it is reached.

  1. From the visitor’s browser, by the tracking script above. While Track Clicks is on, a site search also sends the search words typed into your site’s search form (up to 200 characters). Each event carries: your Site ID (this site’s domain), your DevDome Account ID, the page URL and path, the page title, the referring URL, browser, operating system, device type, user agent, browser language, screen size, time zone, country, the target URL of a click (for a link on your own site, without its query string), whether the browser reports itself as automated, the bundled bot detector’s verdict, whether the referrer was an AI assistant (only while Track AI Referrals is on), and a visitor ID and session ID only when the browser is storing them (see the FAQ on what is stored). The browser contacts the service directly, so its IP address is visible to it, as with any web server.
  2. From your server, when it forwards an outbound-link click. The visitor’s browser sends the click to the /dd-e path on your own domain and your server relays it. Your server adds two fields to that relayed event: the visitor’s country code and the visitor’s IP address, so location and per-visitor counts stay correct when the event arrives from your server instead of from the browser.
  3. From your server, when First-Party Delivery is on: the visitor’s browser sends every tracking event (the same fields as item 1) to a randomized path on your own domain and your server relays it, authenticated with this site’s secret token. The relay adds the same two fields as item 2, the visitor’s country code and the visitor’s IP address, and forwards nothing else: each event is rebuilt from an allowlist and the site and account identity always come from the plugin’s own settings.
  4. From your server, when a known crawler requests a page and Track Bot Visits is on. That event carries the crawler’s user agent, the bot name and type, the requested URL and path, your Site ID and a timestamp. No human visitor data is in it.

The plan check, https://analytics.devdome.com/api/plugin/entitlements

Asks whether this site’s DevDome plan includes First-Party Delivery. Sent only on a connected site: when you turn the switch on, once a day by the refresh job while it is on, and while the Analytics screen is open at most once every two minutes so a plan change shows quickly. It carries your Site ID and this site’s secret token. No visitor data.

The connection handshake, https://analytics.devdome.com/api/plugin/status

Sent when you connect the site and when the connection is re-verified. Contains your Site ID, this site’s secret token, your Account ID, the site URL, the site name, the site administrator’s email address, the WordPress version, the PHP version, the plugin version, the active theme name, the timezone, the site language and whether this is a multisite install. No visitor data.

A shorter form (Site ID and secret token only) also runs when you open the plugin’s screen, at most once per 15 minutes: a site already connected on devdome.com shows as connected here without a second connect step. No visitor data, nothing on public pages.

The one-click connect handshake, https://analytics.devdome.com/api/plugin/connect/start and /api/plugin/connect/claim

connect/start runs only when you press the "Connect Via DevDome Account" button, never on its own (opening the plugin's screen makes only the connection-status check described above). It sends this site's domain, its secret token and the wp-admin address to return to, and receives a short-lived connect link. `connect/claim` runs when your browser returns from devdome.com and exchanges that link for your Account ID.

The stats read, https://analytics.devdome.com/api/plugin/stats

Sends your Site ID, this site’s secret token (so only your own site can read its numbers) and the selected day range. Used to fill the Overview tiles in wp-admin, and the bot-visit figure shared with DevDome Bot Protection when that plugin is installed.

Deleting your data, https://analytics.devdome.com/api/plugin/purge

Sends your Site ID and this site’s secret token, and only when you press Reset Analytics, or tick “Also delete my data on DevDome” while disconnecting.

api.devdome.com – DevDome account services

These two are made by the shared DevDome library bundled with every plugin in the suite.

The account check, https://api.devdome.com/plugin/account

A POST carrying this site’s domain and its secret token, answered with the Account ID and account email address that the token belongs to, so the DevDome screen can show which account this site is linked to. It runs when a DevDome admin screen is displayed and its cached answer has expired: a good answer is kept fifteen minutes (so a plan change shows quickly), a refusal one hour, an outage ten minutes. Never before you have acted: until you press a Connect button, save an Account ID or complete a connection, this check is not made at all.

When you connect from the DevDome Tools dashboard, whose Connect card states this before you press the button, those account checks also carry the slug and version of each active DevDome plugin on the site plus the bundled DevDome library, WordPress and PHP versions, so your DevDome account can show your sites and their DevDome plugins for support and update notices. Nothing about other plugins, users, email addresses, content or visitors is included. Sites connected before this was introduced, and sites connected from a button that does not show that text, do not send the list. Disconnecting stops the plugin list.

Disconnecting, https://api.devdome.com/plugin/disconnect

A POST carrying this site’s domain and its secret token, sent only when you press Disconnect, to unlink the site from the account.

Not contacted on this WordPress.org build

The bundled shared library also references endpoints this build never calls: the https://api.devdome.com/bot-protection/ signature feeds (used by other DevDome plugins; never fetched here, no cron scheduled) and https://api.devdome.com/plugin-updates/ (self-hosted updates, disabled here; updates come from WordPress.org).

devdome.com

https://devdome.com/connect/ is a link you click, not a request the plugin makes. Your browser goes there to sign in and approve the connection, and comes back. The only server-side requests to devdome.com are the two listed above: the plugin catalog (at most every twelve hours) and an error report you send by pressing the button.

Never sent, in any request

  • Passwords and password hashes.
  • Form field values submitted by visitors. The one exception is the text typed into the site’s own search box, recorded as the site-search term of that visit (only while tracking and click tracking are on).
  • Post, page, comment or any other WordPress content.
  • User accounts, user lists, or the email addresses of your registered users. The exceptions are the site’s administration email address, sent with the connection handshake and with every Test connection request described above, and the error report you send yourself with “Report this error”, which carries it so support can reply.
  • Customer, order or payment data.
  • Anything at all about what happens inside wp-admin.

Source code

All of this plugin’s own PHP and JavaScript ships unminified and human-readable. The one bundled third-party file, assets/botd.js (FingerprintJS BotD 2.0.0, MIT), ships as published by its authors; its source is at https://github.com/fingerprintjs/BotD and it is used only in First-Party Delivery mode, where a copy is served from your own domain (otherwise the same file loads from analytics.devdome.com).

One file is generated: assets/devdome-tools-tw.css, the admin screen’s stylesheet. It is a Tailwind CSS v3 utility bundle built from src/tw.css and tailwind.config.cjs with:

npx tailwindcss -c tailwind.config.cjs -i src/tw.css -o assets/devdome-tools-tw.css --minify

Those two build inputs are not included in the distributed package. Ask for them at https://devdome.com/contact and we will send them.