WordPress: Classify independent analytics in a data protection-conscious manner
Independent Analytics runs locally in WordPress and does not send analytics data to an external analytics service. But it is not a purely anonymous page view counter.
Requirements
WordPress administration access and clarity about whether returning visitors are really needed.
Visitor ID
According to its own current documentation, the plugin initially uses the IP for geolocation and forms a unique ID from the IP, user agent and salt, which is stored in the database. This allows returning visitors to be recognized.
Classification
If you only need page popularity, a pure page view counter is more data-efficient. Anyone who uses Independent Analytics should treat the generated visitor identification transparently as pseudonymization/recognition and not just describe it with “IP is not saved”.
Pay attention to proxy headers
The plugin explicitly checks several forwarded and proxy headers for the real visitor IP. An Origin configuration that intentionally removes these headers may therefore alter Analytics functionality.
Test
Generate test visits and control database and browser requests.
Dismantling
If there are problems, restore the previous setting and check again.
Basics of visitor recognition
For classification purposes, Cookieless is not automatically tracking-free and Unique visitors without recognition use. What is important is not just the presence of cookies, but also whether requests are merged via sessions, hashes, local storage or other features.
Related guides
Sources and verification
This guide is based on multiple current sources. Vendor documentation is not treated as proof that every concrete installation automatically follows the same privacy characteristics.
- Independent Analytics: Privacy
- Independent Analytics: IP headers
- Independent Analytics: IP exclusions
Important: IP processing is not IP storage
An IP address has to be processed to establish and deliver a network connection. Hosting providers, firewalls or DDoS protection may also process or retain it for a limited time for security purposes. No Logging distinguishes this security layer from unnecessary persistent visitor logging by the website, application and ordinary access logs.