All plugin versions and changes at a glance — new features, bugfixes and improvements.
v3.9.8
04.05.2026
Cohort Analysis Removed
Remove
Cohort Analysis removed: With daily-rotating salt, cross-day retention is mathematically no longer measurable — we prefer to keep the "no cookies" promise strict rather than ship a half-broken feature
v3.9.7
29.04.2026
Search Engine Split
Feature
Traffic Sources: Organic traffic is now broken down by individual search engine (Google, Bing, DuckDuckGo, Ecosia etc.)
v3.9.6
23.04.2026
UTM Cookie Session-Only
Improve
UTM cookie insyta_p_utm: Session-only (instead of 30 days) and clearly marked as optional in settings
v3.9.5
22.04.2026
Tracker localStorage Cleanup
Improve
Tracker script no longer uses localStorage — legacy insyta_p_vid value is automatically cleared
v3.9.4
21.04.2026
Cookieless Visitor ID
New
Cookieless Visitor-ID: Visitors are identified server-side from anonymized IP + User-Agent + daily-rotating salt (Plausible/Fathom approach) — no cookies, no localStorage, no consent needed
v3.9.3
15.04.2026
External Conversion Tracking
Feature
External Conversion Tracking: Track conversions on external pages (booking systems, ticket shops) via JS snippet — ideal for hotels, events & external checkout systems
v3.9.2
12.04.2026
License Tracking Fix
Fix
License Tracking: Validation calls now also register the site — fixes missing activations on some installations
v3.9.1
11.04.2026
Auto-Deactivation
Improve
Auto-Deactivation: Plugin notifies the server when deactivated or deleted — orphaned sites are automatically removed from the activation list
v3.9.0
08.04.2026
Multi-Language Support
Feature
Multi-Language Support: Dashboard now available in German, English, French, Spanish, Italian, Dutch, Portuguese, Polish and Ukrainian
v3.8.3
08.04.2026
WCAG Button-Kontrast Fix
Fix
Accent-colored buttons: Text contrast is now properly calculated instead of hardcoded white — fixes unreadable text with light accent colors
v3.8.2
07.04.2026
IPv6 CIDR Blocking Fix
Fix
IPv6 CIDR Blocking: IPv4-mapped IPv6 addresses are now correctly normalized — cross-family matching between IPv4/IPv6
IP Blocklist: Warning in settings when IPv6 ranges are listed but the server only delivers IPv4
v3.8.1
07.04.2026
WCAG Compliance, Dark Mode & Bugfixes
New
Improve
Fix
WCAG Compliance: Accent color buttons now automatically use the highest contrast text color (black/white)
Dark Mode Text Brightness: New slider under Settings → Appearance (50%–100%)
Accent Color without White-Label: Color picker in settings for buttons, links and highlights
Access Control: "No Access" message instead of silent redirect when role lacks permissions
Cohorts & Funnel Builder: Menu items were shown even when modules were disabled
Dashboard widgets now respect role permissions (e.g. Recent Conversions)
Plugin Update: Fixed "Forbidden" error during download
Cohorts Dashboard: Fixed KPI cards layout
v3.8.0
06.04.2026
Kohortenanalyse & Funnel Builder
New
Improve
Fix
Cohort Analysis: Group visitors by first-visit week/month with retention heatmap
Cohort Analysis: Segment filter by device, country and UTM source
Salespage: Feature lists, pricing tables and comparisons unified across all pages
Salespage: Smart Alerts added to all pricing cards
Salespage: Hotjar price references corrected and standardized
Salespage: Missing EN translations added
v3.6.1
01.04.2026
Performance & Security
Improve
Fix
Complete migration from admin-ajax.php to WP REST API: 64 endpoints converted. Faster response times, no more WordPress admin bootstrap overhead on tracking requests.
OWASP security audit: XSS protection with escapeHtml() for all dynamic DOM content (journey, sites, license). innerHTML outputs consistently secured.
SSRF protection strengthened: DNS failures now treated as unsafe (deny by default). Slack webhook URLs are validated.
Capability checks added for wizard, order reset, and white-label pricing (defense-in-depth).
Path traversal: basename() protection added to cleanup routines in tab-forms.php.
Replaced json_encode with wp_json_encode (JSON_HEX_TAG) for safe script context in dashboard.
Multi-site connection: REST API call with admin-ajax fallback for backward compatibility between different plugin versions.
v3.6.0
01.04.2026
Smart Alerts, Newsletter & Landingpages
New
Improve
Smart Alerts: automatic anomaly detection with email and Slack notifications. 5 alert types: rage click spike, traffic drop, new dead clicks, conversion drop, form abandonment spike. Cooldown system to prevent alert spam.
Newsletter: send customer newsletters directly from the admin dashboard. Opt-out mechanism with unsubscribe link in every email. Campaign history and preview function.
Landing page: White Label — custom logo, custom colors, custom dashboard title. Perfect for agencies.
Landing page: Smart Alerts — proactive anomaly detection. Feature comparison and all 5 alert types explained.
SEO landing page: Hotjar Alternative for WordPress — detailed feature comparison, GDPR advantages, migration guide.
SEO landing page: Microsoft Clarity Alternative for WordPress — feature comparison, privacy advantages, self-hosted.
Header: features dropdown extended with Smart Alerts and White Label.
Footer: new links for Smart Alerts, White Label, Hotjar Alternative and Clarity Alternative.
Features page, pricing, FAQ and docs updated with Smart Alerts and White Label.
Feature count updated: 32 features (26 Pro + 4 Agency-exclusive).
v3.3.0
24.03.2026
Session Journey, PayPal Capture & Critical Fixes
New
Fix
Session Journey: Recording button directly in each journey row — opens the recording modal without page change.
Session Journey: Scroll milestones (25/50/75/100%) visualized per page as mini bars.
Sort mode: Long-press (600ms) on a panel or nav item activates sort mode — no button required. Toast notification at bottom. Click outside to exit.
PayPal: Capture step implemented — payments are now correctly completed and licenses created.
Critical: Switching dark mode deactivated all feature toggles. AJAX handler now only saves explicitly sent fields (array_key_exists instead of isset).
Critical: Button scanner save deactivated features — same fix in save_settings handler.
Email reports: Sections were not saved (only 3 of 9 sections in handler). All 9 sections are now correctly persisted.
Email reports: Report content was output 3 times in the mail. Template fixed.
Checkout: insytad_register_customer() was undefined → fatal error on purchase. Replaced with wp_create_user().
Deal pages (Facebook, LinkedIn, Limited): Parse errors from broken fragment cache wrappers. Cache completely removed.
Navigation: Items could be dragged without activating sort mode.
Download filename: Plugin was downloaded as button-click-tracker-pro-v3.1.0.zip instead of insyta-pro-v3.1.0.zip.
v3.2.0
22.03.2026
Mobile UX & UI Polish
Improve
Mobile: All stat cards (sg-3, sg-4) wrap to 2×2 grid. Entry/exit pages stacked. Filter bar in single scrollable row.
Mobile: All tables are horizontally scrollable. two-col layouts stacked on small screens.
Mobile navigation: Docs link was missing, added.
Button text color: All amber buttons now have white text instead of black.
Dark mode: Calendar icon in the filter bar is now correctly displayed light.
v3.1.0
19.03.2026
Traffic Analytics
New
Traffic Analytics: New tab in the plugin dashboard with visitors, pageviews, bounce rate, avg session duration, 60-day chart, traffic sources (Direct/Organic/Social/Email/Referral), top pages, entry and exit pages, devices, browsers and OS.
New landing page: /traffic-analytics-plugin/
Feature count updated: 29 features (25 Pro + 4 Agency-exclusive).
DB migration: browser, os, language are now stored in the journey table.
Affiliates page: Success message after registration showed SVG code as text (innerHTML fix).
v3.0.0
18.03.2026
Dead Click Detection & Form Analytics
New
Dead Click Detection (Pro+): clicks on non-interactive elements are automatically detected and visualized in a new dashboard tab — reveals UX issues where users think something is clickable.
Form Analytics (Pro+): form starts, completions, drop-off fields and submit rate are automatically tracked — no manual tagging required, for all forms on the page.
2 new dashboard tabs: "Dead Clicks" and "Form Analytics" in the plugin dashboard, fully in DE/EN.
Feature toggles for dead clicks and form analytics in settings.
Feature count updated: 29 features (24 Pro + 4 Agency-exclusive).
Version numbers: plugin v3.0.0, admin dashboard v1.7.0.
v2.9.5
17.03.2026
Live-Dashboard & Affiliate-Fixes
Fix
New
Live dashboard 403 error fixed: nonce is now generated directly via PHP, no stale cached value.
ip_anon database migration: now runs on every plugin load (not only on activation) — fixes missing column on existing installs.
Feature toggles reset after saving: all toggles (live visitors, click tracking, journey, goals, email reports, A/B tests) are now correctly persisted.
Live dashboard: fixed "undefined (undefined)" for session duration and start time.
OS detection: iOS devices were incorrectly identified as macOS — detection order fixed (iOS before macOS).
Affiliate dashboard: tier-2 partner block and individual commission rates per plan now display correctly.
Device icons in live dashboard: mobile, tablet, desktop, iOS/macOS, Windows, Android, Linux.
v2.9.4
17.03.2026
Feature-Toggles & Live-Dashboard
New
Feature toggles in settings: live visitors, click tracking, session journey, conversion goals, email reports, A/B tests individually toggleable.
Auto-refresh toggle in live dashboard: ⏸/ to pause/resume.
v2.9.3
17.03.2026
IP-Anonymisierung & Feature-Defaults
New
Improve
IP anonymization: anonymized IP (192.168.1.xxx) shown in live dashboard, sessions and recordings — GDPR-compliant, no cookie consent needed.
Feature defaults: all features (heatmap, session recording, rage clicks, link tracking, goals, journey, email reports) are active by default on fresh install.
v2.9.2
16.03.2026
Heatmap: Mobile Scroll-Filter
Fix
Heatmap: scroll movements on mobile were incorrectly recorded as clicks. Touchstart/touchmove detection now filters out scroll events (>8px = scroll, not tap).
Wir verwenden Cookies und ähnliche Technologien (z. B. Pixel, Tags, Skripte), um Ihnen die bestmögliche Erfahrung auf unserer Website zu bieten. Einige davon sind technisch notwendig für den Betrieb der Seite, während andere uns helfen, die Website zu verbessern, Inhalte zu personalisieren und Werbung auszuspielen.
Im Rahmen der Nutzung unserer Website können personenbezogene Daten (z. B. IP-Adresse, Geräteinformationen, Nutzungsverhalten) erhoben, an Drittanbieter übermittelt und von diesen verarbeitet werden — auch in Ländern außerhalb der EU/des EWR (z. B. USA), in denen kein gleichwertiges Datenschutzniveau gewährleistet ist (Art. 49 Abs. 1 lit. a DSGVO). Mit Ihrer Einwilligung stimmen Sie auch dieser Datenübermittlung ausdrücklich zu.
Einige Verarbeitungen können auf Grundlage eines berechtigten Interesses (Art. 6 Abs. 1 lit. f DSGVO) erfolgen. Sie können Ihre Einwilligung jederzeit mit Wirkung für die Zukunft widerrufen oder Ihre Einstellungen anpassen, indem Sie diese Cookie-Einstellungen erneut öffnen.
Weitere Informationen finden Sie in unserer Datenschutzerklärung. Die Nutzung dieser Website setzt ein Mindestalter von 16 Jahren voraus.
Die Ablehnung ist jederzeit möglich und hat keine Nachteile für die Nutzung der Website (Art. 7 Abs. 4 DSGVO). Details zu den einzelnen Cookies und Technologien finden Sie in den Kategorien unten.
Notwendig(5)▼
consenta_authconsent.js6 monate
HMAC-SHA256-signiertes Auth-Cookie für die kryptographisch sichere serverseitige Consent-Verifikation. HttpOnly und Secure — für JavaScript nicht lesbar, kein XSS-Leak möglich. Wird nach erfolgreichem Consent-Log gesetzt und von API::has_consent() für PHP-seitige Consent-Prüfungen gelesen.
consenta.iodomain
insyta_api_tokenInsyta30 tage
Optionaler API-Token für License-Server.
insyta_customerInsyta30 tage
Insyta-Kunden-Login-Session.
usprivacyconsent.js1 jahr
Speichert den CCPA-Datenschutzstatus des Nutzers gemäß dem IAB US Privacy Framework.
Funktional(5)▼
//fonts.googleapis.comGoogle
Google APIs für verschiedene Dienste wie Maps, Fonts und YouTube
//fonts.gstatic.comGoogle
Google Static Content Delivery für Ressourcen und Bibliotheken
gstatic.comGoogle
Google Static Content Delivery für Ressourcen und Bibliotheken
https://fonts.gstatic.comGoogle
Google Static Content Delivery für Ressourcen und Bibliotheken
insyta_p_utmtracker-pro.js
Statistiken(14)▼
_gaGoogle Site Kit2 jahre
Unterscheidet eindeutige Nutzer durch Zuweisung einer zufällig generierten Nummer als Client-Kennung für Google Analytics.
_ga_*Google Site Kit2 jahre
Speichert den Session-Status und wird zur Berechnung von Besucherdaten für GA4-Berichte verwendet.
_gatGoogle Site Kit1 minute
Begrenzt die Anfragerate an Google Analytics, um die Datenerfassung auf Websites mit hohem Besucheraufkommen zu drosseln.
_gat_*Google Site Kit1 minute
Wird von Google Analytics verwendet, um die Anfragerate zu drosseln. Enthält die Tracker-ID im Cookie-Namen.
_gcl_auGoogle Site Kit90 tage
Wird von Google AdSense zur Optimierung der Werbewirksamkeit auf Websites verwendet.
_gcl_awGoogle Site Kit90 tage
Speichert Conversion-Informationen von Google Ads Klicks zur Messung des Werbeerfolgs.
_gidGoogle Site Kit24 stunden
Unterscheidet Nutzer und speichert Informationen über den Seitenbesuch für 24 Stunden.
//www.googletagmanager.comGoogle
Google Tag Manager zur Verwaltung von Tracking-Tags und Skripten
Google Analytics (inline)Google
google-analytics.comGoogle Site Kit
Google Analytics Tracking-Dienst für Website-Analyse
googleapis.comGoogle Site Kit
Google APIs für verschiedene Dienste wie Maps, Fonts und YouTube
googlesyndication.comGoogle Site Kit
Google AdSense Werbenetzwerk für die Anzeigenauslieferung
googletagmanager.comGoogle Site Kit
Google Tag Manager zur Verwaltung von Tracking-Tags und Skripten