=== BimBeau Privacy Analytics ===
Contributors: BimBeau
Tags: analytics, privacy, statistics, traffic, self-hosted
Requires at least: 6.4
Tested up to: 7.1
Requires PHP: 7.4
Stable Tag: 8.47.3
License: GPLv3 or later
License URI: https://www.gnu.org/licenses/gpl-3.0.html

A WordPress analytics plugin you can trust — self-hosted, privacy-conscious insights with your data stored in WordPress.

== Description ==

= A WordPress analytics plugin you can trust =

Understand your website traffic directly from WordPress with clear, real-time analytics designed with privacy in mind.

BimBeau Privacy Analytics stores your analytics data in your own WordPress database. No third-party analytics account is required, and your reports are available directly from the WordPress dashboard.

Simple to install, easy to understand, and built for website owners who want useful analytics without depending on a traditional external analytics platform.

= See what matters at a glance =

BimBeau Privacy Analytics gives you the insights you need to understand how people find and use your website:

* Visits, page views, and recent activity.
* Active visitors in real time.
* Top pages and content performance.
* Traffic sources, referrers, campaigns, and acquisition channels.
* Devices, browsers, operating systems, and screen sizes.
* Country-level geolocation.
* Internal searches.
* 404 errors and missing pages.
* Visitor activity and engagement insights.

Everything is presented inside a clean WordPress interface, so you can understand your traffic without leaving your site.

= Included in the Free plugin =

BimBeau Privacy Analytics on WordPress.org is the complete Free plugin.

Its Free analytics features work without a license, payment, quota, or time limit. No third-party analytics account is required.

The Free plugin also includes configurable data retention, role exclusions, optional Do Not Track and Global Privacy Control handling, privacy settings, country-level geolocation, and real-time analytics.

A separate Pro edition is available from the author outside WordPress.org and replaces the Free plugin when installed.

= Privacy and consent =

BimBeau Privacy Analytics is designed around privacy-conscious analytics workflows.

Two levels of measurement are available:

* **Essential statistics** use the base tracker and are intended for situations where consent exemption applies.
* **Advanced statistics** use an enriched tracker that may require prior consent depending on local rules and your website configuration.

For consent-based setups, configure your consent management platform (CMP) to block `bbpa-advanced-tracker` / `assets/js/bbpa-advanced-tracker.js` before consent and release it only after the visitor accepts the Analytics / Statistics category.

BimBeau Privacy Analytics does not provide a consent banner, decide whether consent has been granted, or store consent records.

The plugin does not use tracking cookies or cross-site advertising identifiers. Essential tracking may use a temporary first-party browser storage identifier to group activity, prevent technical duplicate hits, and produce aggregated or anonymized audience statistics. It is not used for advertising, cross-site tracking, or visitor profiling.

BimBeau Privacy Analytics does not make a website GDPR-compliant by itself. Site owners remain responsible for their legal basis, privacy policy, consent configuration, and applicable legal requirements.

= Pro edition =

BimBeau Privacy Analytics Pro is a separate edition for users who want to go further with their analytics.

Depending on the active license, site configuration, consent setup, and available analytics data, Pro can add:

* Analytics exports for supported reports.
* Page Details for deeper page-level analysis.
* City geolocation reports and interactive map markers.
* Custom event tracking and event configuration.
* Content analytics directly inside WordPress content lists and the editor.
* An installable Stats App for desktop and mobile.
* White-label admin header controls.
* Panel visibility customization for the analytics navigation.
* Additional detailed reports and analysis tools.

Learn more about Pro:

* [Pro version overview](https://bimbeau.fr/bimbeau-privacy-analytics/en/pro/overview/)
* [Pro pricing](https://bimbeau.fr/bimbeau-privacy-analytics/en/pricing/)

The WordPress.org Free package remains fully usable without the Pro edition.

= External services =

The core analytics reports use data stored in your WordPress installation. A small number of optional or account-related features can contact external services when they are explicitly configured or used.

**BimBeau GeoIP Database Service** — Used to download the optional local database for country-level geolocation. Automatic database downloads are disabled by default. A request is made only after an administrator manually requests a download/update or later enables automatic updates. The service can receive the WordPress server IP address and a technical User-Agent; visitor IP addresses are not sent to BimBeau for local GeoIP lookups.

[BimBeau GeoIP Database Service](https://github.com/BimBeau/bimbeau-geoip-database)
[BimBeau Terms of Use](https://bimbeau.fr/bimbeau-privacy-analytics/en/legal/terms-of-use/)
[BimBeau Privacy Policy](https://bimbeau.fr/bimbeau-privacy-analytics/en/privacy-policy/)

**Referrer favicons** — When this optional feature is enabled, the WordPress server may contact a referring website to retrieve its icon. The administrator browser uses the locally stored copy rather than requesting the icon directly from the referring website.

**MaxMind** — MaxMind API mode is optional and remains disabled until an administrator selects it and provides their own MaxMind credentials. When configured, MaxMind receives the IP address being resolved. The local GeoIP database mode does not use the MaxMind API.

[MaxMind GeoLite EULA](https://www.maxmind.com/en/geolite/eula)
[MaxMind privacy policy](https://www.maxmind.com/en/privacy-policy)

**Freemius** — The plugin can use Freemius for account, licensing, pricing, upgrade, support, uninstall, and package-related functionality. These services are separate from the analytics reports stored in WordPress.

[Freemius Terms of Service](https://freemius.com/terms/)
[Freemius Privacy Policy](https://freemius.com/privacy/)

= Documentation and support =

* [Official plugin website](https://bimbeau.fr/bimbeau-privacy-analytics/en/)
* [Getting started guide](https://bimbeau.fr/bimbeau-privacy-analytics/en/getting-started/)
* [Source code on GitHub](https://github.com/BimBeau/bimbeau-privacy-analytics)

= Debug logging =

Optional diagnostic logging is available for troubleshooting. BimBeau Privacy Analytics writes diagnostic information only when Debug mode is enabled and an appropriate WordPress debug log destination or plugin-safe log destination is available.

== Installation ==

1. Install **BimBeau Privacy Analytics** from the WordPress Plugins screen or upload the plugin manually.
2. Activate the plugin.
3. Open **BimBeau Privacy Analytics** from the WordPress admin menu.
4. Follow the configuration assistant to choose your analytics and privacy settings.
5. If you use advanced statistics where prior consent is required, configure your CMP to control `bbpa-advanced-tracker` / `assets/js/bbpa-advanced-tracker.js`.

You can change all configuration choices later from the plugin settings.

== Frequently Asked Questions ==

= Is BimBeau Privacy Analytics free? =

Yes. The WordPress.org edition provides its Free analytics features without a license, payment, quota, or time limit.

A separate Pro edition is available for additional analytics and customization features.

= Where is my analytics data stored? =

Analytics data is stored in your own WordPress database.

Your reports are generated directly from data stored inside your WordPress installation.

= Does BimBeau Privacy Analytics use tracking cookies? =

No. BimBeau Privacy Analytics does not use tracking cookies or cross-site advertising identifiers.

Essential tracking may use a temporary first-party browser storage identifier for technical visitor grouping, duplicate-hit prevention, and aggregated or anonymized statistics. It is not used for advertising or cross-site tracking.

= Does BimBeau Privacy Analytics replace a CMP? =

No.

BimBeau Privacy Analytics does not provide a consent banner, decide whether consent has been granted, or store consent records.

When advanced statistics require prior consent, configure your CMP to control the advanced tracker.

= Can I use BimBeau Privacy Analytics alongside Google Analytics or another analytics tool? =

Yes.

BimBeau Privacy Analytics can run alongside other analytics solutions as long as your tracking scripts, consent configuration, and privacy documentation are configured appropriately.

= Can I exclude administrators and other internal users? =

Yes.

Role exclusions can be configured so administrators, editors, contributors, or other internal roles are not included in your analytics according to your website policy.

= Can I track campaign traffic? =

Yes.

Campaign parameters, referrer information, and available acquisition signals can be used to understand traffic from campaigns, search engines, social networks, email, paid traffic, referrals, and other sources.

= What does the Pro edition add? =

The separate Pro edition adds advanced features such as exports, Page Details, city-level geolocation, event tracking, WordPress content analytics, the installable Stats App, white-label controls, and interface customization.

The Pro edition is not required to use the Free plugin.

= Is technical knowledge required? =

No coding is required for normal installation and everyday analytics.

More advanced privacy configurations, especially consent-based tracking, should be configured according to your website's legal and technical requirements.

== Screenshots ==

1. Dashboard overview with visits, page views, top pages, referrers, and recent activity.
2. See active visitors in real time on an interactive world map.
3. Analyze page-view trends and identify your best-performing content.
4. Review visitor activity with privacy-conscious details and consent-aware context.
5. See which websites and domains send traffic to your site.
6. Understand visitor devices, browsers, operating systems, and screen sizes.
7. Explore traffic by country on an interactive geolocation report.
8. Pro — Analyze city-level traffic with top cities and interactive map markers.
9. Discover what visitors search for on your website.
10. Compare top pages with page views, trends, and average time on page.
11. Configure role access and, with Pro, interface branding and analytics panel visibility.
12. Configure essential and advanced statistics, privacy, and consent-related tracking settings.
13. Configure country geolocation with the local GeoIP database or MaxMind.
14. Manage retention, cleanup, and analytics data maintenance.
15. Pro — Configure and open the PWA Stats App from plugin settings.
16. Contact support from WordPress with topic selection and built-in FAQs.
17. Pro — Add Quick Stats directly to WordPress content lists.
18. Pro — Open page-level insights with summaries, trends, charts, and heatmaps.
19. Pro — Configure custom events and actions and inspect tracked activity.
20. Pro — Export filtered analytics data to CSV, JSON, or Excel.
21. Pro — Install and use the standalone PWA Stats App on desktop or mobile.
22. Pro — White-label the interface, choose visible panels, and configure Quick Stats.

== Changelog ==

= 8.47.3 =
[Improvement] Improve referrer favicon discovery, loading feedback and compatibility while preserving SSRF and SVG security protections.
[Fix] Improve French translations across the plugin and align wording, labels, punctuation and plural forms with WordPress conventions.
[Fix] Prevent the setup assistant from resetting unrelated settings and improve its error handling and recovery.
[Security] Improve MaxMind credential handling by keeping saved license keys out of browser responses and debug logs.
[Performance] Optimize plugin settings loading and reduce unnecessary database, cache and filesystem operations.
[Fix] Restore full admin compatibility with WordPress 6.4 and 6.5.
[Improvement] Improve admin accessibility, translations, date/number formatting and keyboard navigation.
[Fix] Improve Real-time visitor counting, polling, table rendering and bot exclusion.
[Performance] Reduce Real-time requests, prevent overlapping polling and pause background requests when unnecessary.
[Performance] Optimize database upgrades, schema checks and migrations to avoid repeated or unnecessary queries and `ALTER TABLE` operations.
[Fix] Make database upgrades and repairs safer with locking, retry limits and resumable migrations.
[Fix] Improve tracking compatibility with Plain permalinks, custom REST configurations and script optimization plugins.
[Fix] Correct role and path exclusions so excluded visitors and pages are consistently ignored across analytics.
[Fix] Improve bot detection for crawlers, headless browsers, SEO tools, Lighthouse/PageSpeed and uptime monitors.
[Fix] Improve visit, entry/exit and visitor counting to prevent internal navigation, concurrent page loads or delayed heartbeats from creating incorrect statistics.
[Fix] Improve active-time tracking while reducing heartbeat requests.
[Improvement] Strengthen Do Not Track and Global Privacy Control handling.
[Fix] Improve GeoIP database downloading, updating, migration and error recovery.
[Performance] Reduce GeoIP file, cache and MaxMind API operations.
[Security] Strengthen GeoIP storage, temporary-file handling and protection against direct database downloads.
[Security] Improve referrer favicon fetching protections, including DNS rebinding and private-network checks.
[Fix] Improve Top Pages, Referrers, Entry/Exit Pages and 404 reports, including campaign URLs, trailing slashes and subdirectory WordPress installations.
[Fix] Correct handling of accented, non-Latin and encoded page URLs across tracking, visitors, realtime, Top Pages, Entry/Exit Pages and 404 reports.
[Fix] Consolidate equivalent encoded URLs correctly instead of merging them with unrelated pages or the home page.
[Feature] Add an Excluded paths setting to prevent selected pages from being included in analytics.
[Fix] Improve Excluded paths parsing and matching, including query strings, trailing slashes, letter case and comma-separated paths.
[Fix] Make analytics periods, retention, visitor counts, trends, 404s and searches consistently use the WordPress site timezone.
[Fix] Correct period comparisons around UTC offsets and daylight-saving changes.
[Performance] Move raw logs and Real-time visitor data to dedicated database tables for better scalability and concurrency.
[Performance] Improve analytics caching, retention cleanup and batch processing on larger datasets.
[Security] Strengthen public hit ingestion with improved IP parsing, rate limiting, timestamp validation and optional proxy restrictions.
[Security] Limit abusive 404, search-term and page-title requests from bots or scanners.
[Improvement] Improve multisite activation, deactivation, uninstall and data-cleanup behaviour.
[Fix] Make manual and automatic retention cleanup follow the same rules.
[Improvement] Consolidate shared tracking, privacy, REST permission, caching and database-detection logic.
[Fix] Improve admin session-expiration handling so expired sessions show a clear reload message instead of broken reports.
[Performance] Reduce duplicate report, map and admin requests and reuse already loaded data where possible.
[Improvement] Improve debug logging consistency across REST, GeoIP, favicons and tracking.
[Build] Improve release packaging, translation generation and validation to keep Free packages clean and reliable.
[Build] Harden deployment and release tooling and remove unused development files from distributed packages.
[Improvement] Reduce plugin package size by removing files that WordPress does not use.

= 8.45.183 =
Fixes — Prevent Free/Pro activation conflicts from being reported as fatal WordPress errors.

= 8.45.182 =
Improvements — Refresh the WordPress.org listing with clearer, more engaging content focused on self-hosted, privacy-conscious analytics.

= 8.45.181 =
Improvements — Improve the WordPress.org plugin description, screenshot captions, tags, and listing consistency.
Fixes — Fix readme validation after the WordPress.org listing restructure.

= 8.45.179 =
Fix and sync WordPress.org screenshot captions in readme.txt.
Correct WordPress.org screenshot captions and links.
Localize the analytics date picker with the active WordPress admin interface locale instead of react-day-picker's built-in English locale.
Use the active interface locale for admin date/time formatting fallbacks.
Reject pagination translations that accidentally contain placeholders such as `%s`.
Prevent `Previous` from being fuzzy-remapped to `Previous %s` during the Free-package `msgmerge` pass.
Preserve `Next`, `Rows`, and `Country` translations in the generated Free runtime JSON across all distributed locales.
Generate `assets/js/admin-pro.js` translation JSON only when the Premium admin source exists.
Apply the same package-aware target selection to the runtime i18n audit.
Use a neutral unified-source marker when selecting runtime translation targets.

= 8.45.170 =
Improvements — Separate Previous and Next pagination controls across analytics listings.
Improvements — Restore centered mobile version footer.
Improvements — Restore dashboard KPI navigation.
Improvements — Contain realtime map and table on mobile.
Improvements — Allow shared realtime visits CSS in Free package.
Improvements — Migrate GeoIP database storage under bbpa uploads.
Improvements — Improve content links (animated underline) and limit Dashboard Pages labels to 50 chars.
Improvements — Restrict accent color to listing links.
Fixes — Fix country geolocation visitor scale.
Fixes — Fix aggregated retention cleanup when the object-cache entry for a table has not been initialized.
Fixes — Fix standard SVG favicon validation.
Fixes — Preserve the threshold color scale passed to Nivo so its internal domain assignment cannot replace the legend thresholds, prevent empty or inverted legend ranges, derive the sampled palette from the actual number of valid ranges, and keep country fill colors visible on hover and focus using a stronger outline.
Fixes — Harden admin header branding and package verifiers.
Fixes — Fix admin branding bundle verification.
Fixes — Accept passive SVG favicon structures safely.
Fixes — Update WorldMap stylesheet to use fill-opacity for country hover effects while preserving current fill colors and normal white borders.
Miscellaneous — Require complete, non-fuzzy translations for all distributed locales.
Miscellaneous — Update readme.txt

= 8.45.134 =
Build the initial WordPress.org archive
