Description
Hitsteps is a real-time visitor tracking plugin for WordPress. Watch live visitors, follow page-by-page journeys, and connect behavior to referrers, campaigns, devices, approximate locations, and returning visitor profiles.
Add visitor tracking without editing your theme. Connect an account in the plugin settings, save the API key, then verify real-time tracking as soon as the first live visit arrives.
See more than aggregate pageview totals by following the journeys behind them.
Use Hitsteps to answer practical questions:
- Who is visiting my WordPress site right now, and which page are they viewing?
- Which referrers, traffic sources, campaigns, and landing pages bring engaged visitors?
- What did a visitor view before placing an order, submitting a form, or starting live chat?
- Which links, buttons, menus, products, and page sections receive clicks in heatmaps?
- Did traffic stop after a deployment, cache change, or outage?
Real-Time Visitor Tracking for WordPress
Hitsteps adds the tracking code after you connect an account and API key. The live dashboard shows active and recent visitors without a next-day wait.
Live Visitors and Page-by-Page Journeys
Follow activity page by page. See current and entry pages, session duration, browser, device, country, region, and available approximate IP-based city context.
Visitor Profiles and Returning Visitors
Visitor profiles connect repeat browser visits and journey history. Optional aliasing can associate a known identifier supplied after login, form submission, chat, or purchase. Anonymous visits do not reveal a person’s identity automatically.
Referrer Analytics and Traffic Sources
Connect journeys to available referrers, search engines, campaigns, landing pages, and entry sources. Browsers, privacy controls, apps, and copied links can omit referral data.
WordPress Heatmaps and Page Analysis
Click heatmaps and Page Analysis show which links, buttons, menus, products, and page sections receive attention, helping explain where journeys stall.
WooCommerce and Form Visitor Context
Hitsteps can add recent visitor journeys to WooCommerce admin order emails and supported form notifications. Integrations include Contact Form 7, Gravity Forms, Ninja Forms, and Jetpack Contact Form.
More Hitsteps Features
- Live chat and support-button options.
- Bot detection and referral-spam filtering.
- Invisible tracking with no public counter badge.
- Real-visitor page-speed reporting.
- Uptime monitoring and alert channels, depending on plan and configuration.
- WordPress dashboard summaries, visitor maps, recent graphs, Online Visual live visitor paths, and pageview widgets.
- Optional registered-user aliasing across devices when your site has the required permission or consent.
Learn more on the Hitsteps features page.
External Service and Privacy
This plugin connects WordPress to the hosted Hitsteps analytics service. An account and API key are required. It sends analytics data such as page URLs and titles, referrers, browser and device information, IP-derived approximate location, and interactions. Optional aliasing, WooCommerce, or form integrations can also send identity or journey context.
Site owners are responsible for providing any notice and obtaining any consent required for their use of analytics, cookies, identity features, chat, and related integrations. Review the Hitsteps Terms of Service and Hitsteps Privacy Policy before enabling the service.
Security Policy
Reporting Security Bugs
Please report security issues in the Hitsteps plugin through the Patchstack Vulnerability Disclosure Program. Patchstack can assist with verification, CVE assignment, and developer notification.
Screenshots





Installation
- Install and activate Hitsteps Web Analytics.
- Open the Hitsteps settings page in WordPress.
- Connect an existing Hitsteps account or create one, then save the website API key.
- Visit the site once and open the Hitsteps dashboard to confirm live visitor tracking.
- Review visitor journeys, traffic sources, heatmaps, and configured alerts as data arrives.
FAQ
-
How do I see live visitors on my WordPress site?
-
Activate Hitsteps, open Settings > Hitsteps, connect your account and API key, then visit the site in another tab. The live dashboard shows the test visit, page, available referrer, device, approximate location, and journey.
-
Can Hitsteps track WordPress visitors in real time?
-
Yes. Hitsteps sends tracked page activity to its hosted dashboard as it happens. Follow active and recent visits, page changes, entry pages, and returning visits.
-
Does Hitsteps create visitor profiles and track returning visitors?
-
Yes. Profiles connect returning browser visits and page history. They represent browser or session activity unless your site supplies a known identifier after login, a form, chat, or purchase. Anonymous visitors are not identified automatically.
-
Does the WordPress plugin include heatmaps?
-
Yes. Enable click tracking to build heatmaps and Page Analysis reports showing which links, buttons, menus, products, and page sections receive clicks.
-
Can I see which referrers and traffic sources send each visitor?
-
Hitsteps records available referrers, landing pages, campaigns, search-engine signals, and entry sources. Browsers, privacy settings, apps, redirects, and copied links can remove referrer data, making visits direct or unattributed.
-
Does Hitsteps work with WooCommerce and WordPress forms?
-
Yes. Hitsteps can add visitor context to supported WooCommerce order emails and integrates with Contact Form 7, Gravity Forms, Ninja Forms, and Jetpack Contact Form. Enable only what fits your privacy and consent requirements.
-
Is Hitsteps a replacement for Google Analytics?
-
Use it alone or beside Google Analytics. Hitsteps focuses on live visitors, individual journeys, returning profiles, referrers, heatmaps, chat context, and website monitoring.
-
How do I verify that WordPress visitor tracking is working?
-
After saving the API key, clear WordPress or CDN caches, browse two or three pages in a separate window, and confirm the path appears live. If not, check the API key, consent settings, caching, content-security policy, and duplicate analytics installations.
For account-specific help, visit the Hitsteps support page.
Reviews
Contributors & Developers
“Hitsteps Web Analytics” is open source software. The following people have contributed to this plugin.
ContributorsTranslate “Hitsteps Web Analytics” into your language.
Interested in development?
Browse the code, check out the SVN repository, or subscribe to the development log by RSS.
Changelog
5.95
- Refreshed the WordPress.org screenshot gallery.
- Reworked WordPress.org discovery copy around real-time visitor tracking, live visitors, heatmaps, visitor profiles, and referrers.
- Added query-focused FAQs for live visitors, profiles, heatmaps, referrers, integrations, and verification.
- Verified compatibility with WordPress 7.0.3; the WordPress.org
Tested up toheader remains7.0as required for the release branch. - Added the Online Visual live visitor-path widget to the WordPress administrator dashboard.
- Redesigned the Hitsteps settings page with responsive, accessible controls and high-resolution branding.
- Kept WordPress administrator notices in a dedicated area outside the branded hero.
- Restored a high-resolution Hitsteps dashboard preview to the settings sidebar.
- Added App Store and Google Play links below the dashboard preview.
- Removed the redundant disconnected Get an API key button from the header.
- Corrected the minimum PHP requirement metadata to 5.3 to match existing plugin syntax.
- Secured automatic account registration with HTTPS and validated returned API codes before saving them.
- Handled registration connection failures safely, retained legacy 32-character API keys, and stopped repopulating submitted passwords.
5.94
- Refreshed the WordPress.org description, search tags, service disclosure, and release metadata.
5.93
- WordPress compatibility update.
5.88
- Updated service endpoints.
5.87
- Confirmed Patchstack VDP enrollment.
- Fixed CVE-2023-45268 and CVE-2023-45057.
5.86
- Enrolled in the Patchstack Vulnerability Disclosure Program.
5.85
- Updated PHP 8.2 compatibility.
5.83
- Improved API-code validation.
5.81
- Improved Safari compatibility, WordPress 6 compatibility, and contact-form visitor detection.
Earlier release history remains available in the WordPress.org SVN repository.
