Incode Heatmap

説明

Incode Heatmap shows you how visitors really use your pages — where they click, where they
hesitate and how far down they read — and keeps every measurement in your own WordPress
database. No account, no external service, no data leaving your server.

The heavy work happens in the administrator’s browser, on demand: aggregating points and
painting the map. On the front-end there is only a small, deferred, consent-aware tracker,
so real visitors pay virtually nothing for it.

What you get

  • Click heat map and mouse-movement heat map.
  • Scroll-depth map: see the line where readers drop off.
  • “Confetti” view: every click coloured by the moment it happened.
  • Device segmentation (desktop / tablet / mobile) — separate maps, because they rarely agree.
  • Configurable sampling, so the database does not balloon on a busy site.
  • Consent aware: Complianz, Cookiebot and Google Consent Mode v2 are detected automatically,
    plus Do-Not-Track.
  • Input masking: nothing typed into a form is stored.
  • Front-end viewer: the heat is painted over your live page, in its real context — not on
    a screenshot inside the dashboard.
  • Automatic retention with a daily cleanup job.
  • A setup wizard and an in-plugin quick guide, so the first map takes a couple of minutes.

No limits

Everything above is in this plugin, free and without limits: no caps on pages, on
events, or on how long you keep them. Nothing is locked, metered or timed out.

How it works

The tracker batches events and sends them with navigator.sendBeacon to a REST endpoint on
your own site. Coordinates are stored resolution-independently, so a map recorded on a 4K
monitor lines up with one recorded on a laptop. Nothing is computed on the visitor’s page
beyond collecting the events; rendering happens only when an administrator opens a map.

Privacy

Incode Heatmap stores behavioural data (clicks, mouse movement and scroll depth) on your own
server only. It does not collect names, email addresses or IP addresses, and text typed
into form fields is masked. Capture runs only after consent when a consent banner is
present, and honours the browser Do Not Track signal. Data is deleted automatically after
the retention period you configure. The plugin registers suggested privacy-policy text and
integrates with WordPress’ personal-data export and erase tools.

スクリーンショット

インストール

  1. Upload the incode-heatmap folder to /wp-content/plugins/, or install the ZIP from Plugins Add New Upload Plugin.
  2. Activate it. The setup wizard asks three questions and leaves the plugin measuring.
  3. Open any page of your site as an administrator and use the “Heatmap” button in the admin bar to see the map over that page.

FAQ

Does this send my visitors’ data to a third party?

No. Everything is stored in your WordPress database and never leaves your server.

Will it slow down my site?

The front-end tracker is a few KB, loads deferred after everything else and sends batched
events. All aggregation and rendering happens in the administrator’s browser, on demand,
so regular visitors do not pay for it.

Is it GDPR compliant?

It is built to respect consent: it can require analytics consent (Complianz, Cookiebot,
Consent Mode v2), honours Do-Not-Track, masks form input, stores no personal identifiers
and deletes data after a retention period you choose. Compliance also depends on how you
configure and disclose it on your own site.

I browse my site and no data shows up.

Administrators and editors are excluded on purpose, so your own browsing does not pollute
the data. Open the page in a private window to test it.

How do I exclude certain pages or roles?

Excluded roles (administrators and editors by default) are never tracked, and you can list
URL patterns to include or exclude from the settings screen.

How long is the data kept?

As many days as you set under Retention (60 by default). A daily task deletes anything
older on its own.

評価

このプラグインにはレビューがありません。

貢献者と開発者

Incode Heatmap はオープンソースソフトウェアです。以下の人々がこのプラグインに貢献しています。

貢献者

“Incode Heatmap” をあなたの言語に翻訳しましょう。

開発に興味がありますか ?

コードを閲覧するか、SVN リポジトリをチェックするか、開発ログを RSS で購読してみてください。

変更履歴

0.6.5

  • Fixed: if a second copy of the plugin code is active at the same time, it now stays idle instead of stopping the site with a fatal error.

0.6.4

  • Renamed to Incode Heatmap for the WordPress.org directory.

0.6.3

  • Housekeeping only: no user-visible changes in this edition.

0.6.2

  • Admin notices shown on the plugin screens are readable again: they were
    inheriting the white text of the header and came out white on white.
  • The “Privacy decided” line of the setup checklist now describes the privacy
    settings you actually have. It used to claim consent was required and
    Do-Not-Track honoured even when both were switched off.

0.6.1

  • A missing plugin file no longer takes the whole site down: the modules are
    checked before they are loaded, and if any is missing the plugin stays inert
    and says so in the dashboard instead of throwing a fatal error.

0.6.0

  • Scroll history is now stored per day, so retention prunes it like everything
    else instead of keeping one ever-growing row per page.
  • Internal: schema version 3, applied automatically on update.

0.5.0

  • New: setup wizard on activation — three questions and the plugin is measuring.
  • New: in-plugin quick guide with the four steps, how to read a map and the frequent
    questions.
  • Reorganised admin: shared header with live status, cards instead of one long form, and
    key figures on the Maps screen.
  • Settings now expose everything that previously required editing code: page whitelist,
    extra masking selectors and data purge on uninstall.
  • Removed an unused admin script that was still being loaded.

0.4.1

  • Sampling and retention fixes; smaller footprint on busy sites.

0.4.0

  • Front-end viewer: fixed a REST nonce issue that could return 403 on the front-end.
  • Confetti view coloured by click timing.
  • GDPR: suggested privacy-policy content and personal-data exporter/eraser hooks.
  • Server-side revalidation of role and URL rules on ingestion (defence in depth).
  • Performance: the page list for the viewer is loaded on demand.
  • Internationalisation: all user-facing strings are translatable (text domain incode-heatmap).

0.1.0

  • Initial release: click and scroll capture, batched REST ingestion, admin-side
    aggregation and the click heat map viewer. Consent and retention from day one.