[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f6FQNmGdsLFe2v7rADmlpwZchwRLlDmkY5MxxwEwoOM4":3},{"slug":4,"display_name":4,"profile_url":5,"plugin_count":6,"total_installs":7,"avg_security_score":8,"avg_patch_time_days":9,"trust_score":10,"computed_at":11,"plugins":12},"dominikshaim","https:\u002F\u002Fprofiles.wordpress.org\u002Fdominikshaim\u002F",1,0,100,30,94,"2026-08-29T00:24:04.141Z",[13],{"slug":14,"name":15,"version":16,"author":4,"author_profile":5,"description":17,"short_description":18,"active_installs":7,"downloaded":19,"rating":7,"num_ratings":7,"last_updated":20,"tested_up_to":21,"requires_at_least":22,"requires_php":23,"tags":24,"homepage":30,"download_link":31,"security_score":8,"vuln_count":7,"unpatched_count":7,"last_vuln_date":32,"fetched_at":33},"trackless","Trackless – Cookieless Analytics","1.1.16","\u003Cp>Trackless measures your site’s traffic — and, on WooCommerce stores, your real revenue and margin — entirely server-side. No own analytics cookies, no JavaScript snippet, and consent-banner needs depend on your site setup. You read the reports in your Trackless account dashboard.\u003C\u002Fp>\n\u003Cp>Trackless is part of \u003Cstrong>WooModuly.cz\u003C\u002Fstrong>, a collection of WordPress and WooCommerce plugins — see https:\u002F\u002Fwoomoduly.cz\u002Fprodukt\u002Ftrackless\u002F.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>How visitors are counted (privacy by design):\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>The visitor key is a daily-rotating HMAC-SHA256 hash of IP + User-Agent + day, keyed with a secret salt that exists only on your server. It cannot be reversed and changes every day.\u003C\u002Fli>\n\u003Cli>The raw IP address is never stored and never transmitted — only a keyed hash.\u003C\u002Fli>\n\u003Cli>Global Privacy Control (the \u003Ccode>Sec-GPC\u003C\u002Fcode> browser signal) is honoured: opted-out visitors are not tracked at all.\u003C\u002Fli>\n\u003Cli>No data is written to the visitor’s browser — no cookies, no localStorage, no fingerprinting scripts.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>What it measures:\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Visits and sessions with source \u002F medium \u002F campaign and a GA4-style channel group\u003C\u002Fli>\n\u003Cli>Page views and events: product view, category view, search, add to cart, cart, checkout, 404\u003C\u002Fli>\n\u003Cli>Device, browser, OS, country and language (one row per visitor per day)\u003C\u002Fli>\n\u003Cli>With WooCommerce: orders, revenue, refunds, payment and shipping methods, first-order flag, order attribution (computed server-side from the cookieless visitor match), ordered items — including per-unit purchase cost for margin reporting if you store it (\u003Ccode>_wc_cog_cost\u003C\u002Fcode>, \u003Ccode>_alg_wc_cog_cost\u003C\u002Fcode>, \u003Ccode>_cost\u003C\u002Fcode> or the \u003Ccode>trackless_wholesale_price\u003C\u002Fcode> filter)\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Events are collected into a small queue table in your own database and flushed once a day via WP-Cron (or manually with the “Send now” button). The delivery is HMAC-SHA256 signed and idempotent, so retries are safe.\u003C\u002Fp>\n\u003Cp>WooCommerce is optional: on a plain WordPress site you get cookieless web analytics; with WooCommerce you also get the e-commerce metrics.\u003C\u002Fp>\n\u003Ch4>External service: Trackless (please read)\u003C\u002Fh4>\n\u003Cp>This plugin is a connector for \u003Cstrong>Trackless\u003C\u002Fstrong> (https:\u002F\u002Ftrackless.cz), a hosted analytics service. It is \u003Cstrong>not\u003C\u002Fstrong> a standalone statistics plugin — the reports live in your Trackless account, and the plugin sends data to the service’s ingest endpoint at \u003Ccode>https:\u002F\u002Ftrackless.cz\u002Fingest\u003C\u002Fcode>.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>When data is sent:\u003C\u002Fstrong> only after you enter your API key \u003Cstrong>and\u003C\u002Fstrong> explicitly tick the Data Processing Agreement (DPA) consent checkbox in the plugin settings. Until you do both, the plugin collects and sends nothing.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>What is sent (once a day, HMAC-signed):\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Pseudonymous traffic aggregates: hashed visitor identifiers (keyed HMAC, daily-rotating), hashed IPs, page URLs, referrers, UTM parameters and click IDs, the raw User-Agent (used server-side to derive device\u002Fbrowser\u002FOS and to flag bots — not stored), country code, language\u003C\u002Fli>\n\u003Cli>With WooCommerce: order data including order ID, totals and refunds (amounts), currency, payment method, shipping method, order status, and line items with prices and (if configured) per-unit purchase costs\u003C\u002Fli>\n\u003Cli>Site metadata: site name, domain, timezone, currency, order statuses, product categories, carriers, payment gateway names\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>IP\u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan>country database:\u003C\u002Fstrong> to show visitor country on hosting without a geo header (no Cloudflare \u002F GeoIP module), the plugin downloads a small public IP\u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan>country database from \u003Ccode>https:\u002F\u002Ftrackless.cz\u002Fapi\u002Fgeoip\u002Fcountry.dat.gz\u003C\u002Fcode> (refreshed about once a week) and resolves the country locally — the visitor IP never leaves your server for this. The database is \u003Cstrong>DB-IP Lite\u003C\u002Fstrong> by DB-IP (https:\u002F\u002Fdb-ip.com), licensed \u003Cstrong>CC BY 4.0\u003C\u002Fstrong>.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>IP\u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan>hosting database:\u003C\u002Fstrong> to keep bot farms out of your statistics, the plugin downloads a second public database from \u003Ccode>https:\u002F\u002Ftrackless.cz\u002Fapi\u002Fgeoip\u002Fhosting.dat.gz\u003C\u002Fcode> (also refreshed about once a week) listing IP ranges that belong to datacentres, clouds and VPNs, and checks the visitor IP against it locally — again the IP never leaves your server. Consumer ISPs and Apple iCloud Private Relay ranges are excluded from that database, so an ordinary customer is not affected. Built from \u003Cstrong>DB-IP ASN Lite\u003C\u002Fstrong> by DB-IP (https:\u002F\u002Fdb-ip.com), licensed \u003Cstrong>CC BY 4.0\u003C\u002Fstrong>.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>CDN edge ranges:\u003C\u002Fstrong> the plugin downloads a small JSON list of Cloudflare edge IP ranges from \u003Ccode>https:\u002F\u002Ftrackless.cz\u002Fapi\u002Fgeoip\u002Fcdn.json\u003C\u002Fcode> (also refreshed about once a week). If your site sits behind a CDN, this is what lets the plugin tell a visitor’s own IP from the CDN’s — without it every visitor would look like the same person. A copy ships with the plugin, so this works from the very first request.\u003C\u002Fp>\n\u003Cp>None of these three downloads sends anything about your site or your visitors — they are plain requests for public files.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Terms and pricing:\u003C\u002Fstrong> Trackless is a paid service with a 30-day free trial; you need a Trackless account and API key to use this plugin.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Terms of Service: https:\u002F\u002Ftrackless.cz\u002Fen\u002Fobchodni-podminky\u003C\u002Fli>\n\u003Cli>Data Processing Agreement (DPA): https:\u002F\u002Ftrackless.cz\u002Fen\u002Fzpracovatelska-smlouva\u003C\u002Fli>\n\u003C\u002Ful>\n","Cookieless server-side analytics: traffic, sources and devices. With WooCommerce also orders, revenue and margin. No cookies, no measurement JS.",551,"2026-07-18T22:37:00.000Z","7.0.2","6.2","7.4",[25,26,27,28,29],"analytics","cookieless","privacy","statistics","woocommerce","https:\u002F\u002Fwoomoduly.cz\u002Fprodukt\u002Ftrackless\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Ftrackless.1.1.16.zip",null,"2026-07-22T17:31:50.256Z"]