Roadmap
Four phases, built in order. Phase 1 is a complete product on its own — traffic, heatmaps and section analytics on a privacy-first core — and each later phase adds modules on top of the same tracker and storage. Phases 1 and 2 are complete.
Verified against the extension source on 2026-10-11.
Phase 1 · CoreDone
9/9The tracker, the collector and the storage everything else rides on. Privacy and consent are built in here, once, so no module can skip them.
- Extension scaffold — Done
manifest.php, the extension class and a settings screen under Unyson+ → Visitor Insights. Ships inactive by default. - Tables + migrations — Done
Pre-aggregated daily tables keyed by page, day and device, so storage grows with pages × days rather than with traffic. Versioned installer with
migrate(); tables are never dropped on deactivation. - Consent gate — Done
WP Consent API integration (
wp_has_consent, live reaction to consent changes), Global Privacy Control, an opt-out shortcode, and a Require consent everywhere switch. Decided in JavaScript so it works behind page caches. - Core tracker script — Done
Starts in idle time after consent, passive listeners, batches events and sends them with
sendBeacon/fetch(keepalive). Target: core + heatmaps ≤ 8 KB gzipped. - Collector endpoint — Done
A collector that skips the WordPress boot and appends to a per-minute buffer file, with a REST fallback switched on automatically when the direct endpoint is blocked.
- Endpoint protection — Done
No nonces (they break on cached pages). Instead: size and schema checks, an origin check, a rotating HMAC page token, rate limits, per-page daily caps and bot filtering.
- Roll-up + retention — Done
A one-minute job folds buffer files into the daily tables with
INSERT … ON DUPLICATE KEY UPDATE; reports also roll up when opened, so a stalled cron never shows stale data. Batched pruning by the retention setting. - Privacy tools — Done
Suggested privacy-policy text and WordPress personal-data export / erase hooks.
- Builder element IDs on the page — Done
On tracked pages only, sections, columns and elements carry their builder
unique_idasdata-fw-item-id, so every click is attributed to a named builder item.
Phase 1 · Traffic dashboardDone
3/3The everyday numbers, without cookies: enough for many sites to stop needing an outside analytics service.
- Admin screen — Done
Unyson+ → Visitor Insights, with a tab per module and date / device filters.
- Traffic reports — Done
Page views, unique visitors (a daily-rotating salted hash; IPs are never stored), top pages, referrers and UTM campaigns, devices, countries.
- Live view — Done
Visitors on the site in the last 5 minutes and the pages they are on.
Phase 1 · HeatmapsDone
3/3Click, scroll and attention maps per device, drawn over the live page. Clicks are stored relative to their builder element, so the map stays accurate at every screen width.
- Click, scroll + attention capture — Done
Element-relative click positions with page coordinates as a fallback, sticky / fixed elements flagged, maximum scroll depth, visible time per section.
- Heatmap viewer — Done
The live page in a same-origin frame at the chosen device width, with a canvas overlay: clicks, scroll reach, attention and an element ranking.
- Admin-bar fallback — Done
A Show heatmap toggle on the live page, for sites where a security plugin blocks framing.
Phase 1 · Section analyticsDone
3/3The part only a page builder can do: reach, attention and drop-off for every builder section.
- Section reach + attention — Done
How many visitors reach each section and how long it is visible, per device.
- Live Editor overlay — Done
A heat overlay mode in the Live Editor, next to wireframe and box-model.
- Builder badges — Done
Each item in the backend builder shows its share of clicks and its reach.
Phase 2 · Goals & conversionsDone
2/2Count what matters without writing code.
- Track any element as a goal — Done
A Track as goal switch in every element's Advanced tab.
- Automatic goals — Done
Form submissions, newsletter sign-ups, WooCommerce orders and short-link clicks, counted from events the other extensions already fire.
Phase 2 · FunnelsDone
1/1Step-by-step drop-off between pages and goals.
- Funnel builder + report — Done
Define steps (a page visited, an element clicked, a goal reached) and see the drop-off between each.
Phase 2 · Frustration & errorsDone
2/2Find the places where the site lets visitors down.
- Rage, dead and error clicks — Done
Rage: 3 or more clicks within 30 px and under 1 s apart. Dead: nothing on the page changes within 2.5 s. Error: a script error right after the click.
- Script errors + 404s — Done
JavaScript errors and missing pages, grouped and ranked.
Phase 2 · Real-visitor performanceDone
1/1Core Web Vitals from real visitors, per page and template — proof that an optimisation helped.
- LCP, INP and CLS collection + report — Done
Field data by device, with the 75th percentile shown the way search engines judge it.
Phase 3 · Form analyticsPlanned
0/1Which field makes visitors give up — without recording what they type.
- Field-level drop-off — Planned
Starts, completions and the last field touched before abandoning.
Phase 3 · Site search insightsPlanned
0/1What visitors look for, and what they cannot find.
- Search terms + zero-result searches — Planned
Top searches, searches with no results, and the page searched from.
Phase 3 · Section A/B testingPlanned
0/1Two versions of a section, served by the builder, with the winner decided by goals.
- Section variants + results — Planned
An even split, a cache-safe variant choice made in the browser, and a result with its confidence.
Phase 3 · AI summaries & digestPlanned
0/2The numbers explained in plain words.
- Weekly email digest — Planned
Traffic, top movers and new friction points.
- Ask the AI Assistant — Planned
Questions such as why is nobody clicking the Pricing button? answered from the site's own data.
Phase 4 · Session recordingPlanned
0/2Optional replay of individual visits. Always opt-in consent, masked by default, sampled, short retention — never sent off the site.
- Consent-only recorder — Planned
A separate script loaded only after consent; every input masked in the browser before anything is sent; checkout, account and login pages excluded.
- Player + controls — Planned
Playback in wp-admin behind its own capability, per-session delete, 30-day default retention.
How this page stays current
Status is not ticked by hand. src/data/visitor-insights-roadmap.json lists every task with a
detect block naming the files (and, where needed, code symbols) that make it real, and
scripts/gen-roadmap.mjs checks them against the extension's source tree:
| Result | Status |
|---|---|
| Every file and symbol found | Done |
| Some found, some missing | In progress |
| None found | Planned |
npm run roadmap:vi # scan and rewrite the JSON
npm run roadmap:vi -- --dry # report only, write nothing
npm run roadmap:vi -- --check # exit 1 if stale
The detect paths double as the extension's agreed file layout, decided before the code is
written. The same mechanism keeps the POS Sync roadmap honest.
Not on the roadmap
Stated plainly, so nobody waits for them:
- Identifying visitors or building personal profiles. Visitor Insights measures how a site is used, not who uses it.
- Advertising, retargeting or ad attribution. No data is shared with ad platforms.
- Sending data to a hosted service — ours or anyone else's. Self-hosted is the point.
- A second short-link report. Short-link clicks arrive as goals from the Short Links extension rather than being tracked twice.