Skip links
Opti-Behavior
Opti-Behavior
made by OptiUser
Product Changelog

Every release, every fix, every improvement.

Follow the Free and Pro plugin release history in one clean timeline, sourced from the official plugin readme changelogs.

Free Core v1.9.2 2026-09-25
Pro Add-on v1.9.2 2026-09-25
01

Opti-Behavior Core changelog

Analytics, heatmaps, funnels, settings, privacy, performance, compatibility and WordPress.org package updates.

v1.9.2

2026-09-25
  • Security: Fixed an unauthenticated stored cross-site scripting issue in the post analytics box and the dashboard (CVE-2026-95686, CVE-2026-95809, reported through Wordfence). Link addresses, referrers and location data sent by the public tracker are now validated before they are stored, the country name is always resolved by the server, values already stored are cleaned when they are read back, and every value is escaped before it is displayed. Update recommended.
  • Feature: "How it works" page (was Roadmap): an animated view of the seven collectors feeding Smart Insights with your own numbers, the four-step loop, a first-days checklist, the Free and Pro modules, the latest release notes, the roadmap and support. Its "Setup check" card shows whether visits are received, whether a caching or optimization plugin blocks a tracker and whether your own visits are counted, with a button to fix each item.
  • Fix: Spam filter — after saving the Traffic & Behavior thresholds, the spam recalculation could flag every session as spam ("few scrolls"), so "Exclude spam" hid all recordings, sessions and stats. The recalculation and the scheduled spam cleanup now read scrolls and clicks from the same sources as the rest of the plugin, and sessions wrongly flagged by 1.9.1 are re-checked automatically in the background after the update. Nothing to do on your side.
  • Fix: A click on a cookie / consent banner no longer counts as a visitor click, so a visitor who only answered the banner is no longer counted as engaged when spam is excluded. Single-page visits are no longer counted as having at most one scroll.
  • Feature: Admin menu in two groups: "Your data" (Traffic, Heatmaps, Recordings, Funnels, User Journeys, Errors Tracking, Forms), then "What to fix" (Smart Insights, A/B Testing). The Dashboard is now "Traffic", with a chart icon; its page is titled "Traffic Overview". The Smart Insights menu item pulses in the colour of your open problems: red = a Critical problem, yellow = High or Medium, green = nothing to fix. Nothing is computed on page load and nothing is added to the public site.
  • Feature: Cookie preferences shortcode — paste [opti_behavior_cookie_settings] into your Privacy or Cookie Policy page: visitors see their current choice and can change or withdraw it at any time (GDPR art. 7). Withdrawing removes the tracking cookies and identifiers immediately and tracking falls back to cookie-free anonymous mode. [opti_behavior_cookie_settings display="link"] (or the CSS class ob-consent-open on any link) reopens the banner instead. Settings → Privacy & GDPR.
  • Enhancement: The visitor's consent choice is now remembered for 6 months by default (CNIL recommendation); 12 months remains available in Settings → Privacy & GDPR. When the choice expires or is refused, the identifiers stored under the earlier consent are removed from the browser. A/B tests in Full Tracking mode write the variant cookie only after the visitor accepts the consent banner; until then tests keep running cookie-free, exactly like Anonymous mode, and a visitor who accepts later keeps the variant already seen.
  • Feature: Smart Insights "How it works" strip: what each module sent over the period, then what was found, fixed and confirmed.
  • Feature: Page X-Ray, the per-page report of Smart Insights, is part of Opti-Behavior Pro. In the free version the "Page X-Ray" tab shows a lock and a PRO badge, what the tab does and an example report; the "Dossier" button of the heatmap list carries the same lock.
  • Feature: Two one-time messages, on Opti-Behavior screens only: 2 days after installation, if your own visits are still counted, an offer to exclude them; after an update, a note that the menu changed, with a link to the guide. The welcome popup now ends on the "How it works" page, and the welcome screen and popup say "Smart Insights" (was "AI Insights").
  • Enhancement: Smart Insights cards are more reliable. Confidence comes from the number of visits measured (a 65-visit card is Medium at most) and Critical must be earned: enough visits measured, High confidence and a loss that matters on this site. Cards with the same numbers get the same priority, "Worse" / "Better" needs a real change, site-wide cards no longer read "Observation on 0 sessions", cards with identical data are merged into one, and a "Provisional · N visits" badge marks cards built on few visits.
  • Enhancement: Funnel drop-off cards name the step visitors leave ("between Product and Cart, 60 of 90 visitors leave"), count visits instead of tracking rows, need two steps and 50 visits, show a "Where visitors leave" step bar and open the funnel on that step. The end-to-end drop rule, true of almost every funnel, is gone, and the Funnels page warns when two funnels track the same steps.
  • Enhancement: Smart Insights money figures are real: an amount "at risk" is shown only for a funnel that ends at the checkout (with at least 20 orders over the period) or for a form priced with your own value of a conversion. Content funnels, errors, slow pages and engagement drops show the visitors they lose instead of a dollar figure, and amounts computed by the previous rule are no longer displayed.
  • Enhancement: Insight details say each thing once, show "Things to check" when nothing was measured, show no lift range without a published source, and show the "Result" of a resolved card (before, after, verdict or the day the measurement ends). Cards the new rules no longer confirm close as "Closed: rule updated" and never count as resolved.
  • Enhancement: Heatmap page: each device button shows its icon above the number and keeps the same width whatever the number (12 k above 9 999, exact number on hover); Views, Clicks and Avg Time sit on the same row as the heatmap types.
  • Fix: Smart Insights: a custom date range that ends before it starts shows a clear message; the notification panel no longer lists locked Pro previews one by one and no longer covers the buttons of the A/B test wizard; high bounce and low scroll cards use one rule (30 visits, same limits, same comparison with the site average).
  • Fix: Heatmaps: the background tasks no longer schedule the same hourly job twice or queue pages without an ID again and again, and the action buttons of the heatmap list no longer overlap the "Last Updated" column.
  • Fix: Danger Zone: "Heatmap Data" now counts and deletes the archived heatmaps too, deleting Smart Insights resets the menu colour at once, and a reset is recorded in Cleanup History. Cleanup History folds repeated runs that deleted nothing into one entry and only says "deleted" when something was deleted.
  • Fix: Funnels: a link to a funnel opens the list page that contains it, and the suggestions panel keeps both display choices when they are clicked quickly.
  • Fix: Dashboard: the real-time visitors globe shows again for visitors without a country, instead of a raw code snippet, and the User Intent card no longer shows rows of zeros above its empty state.
  • Fix: Translations: Smart Insights is fully translated (spam filter button, one label per category), the plugin's own admin language now also applies to Smart Insights and Forms, the deactivation survey and about 100 Portuguese strings carry their accents, and every new string is translated in French, German, Spanish, Italian and Portuguese.
  • Compatibility: Pair with Opti-Behavior Pro 1.9.2. Update both plugins together.

v1.9.1

2026-09-18
  • Feature: Heatmaps only where they matter — recorded for posts, pages, products, home and shop; tag, category, author, date, search and paginated archives no longer create one heatmap per URL. Existing archive-page heatmaps are archived in the background and can be restored in one click (Settings → Data Collection).
  • Feature: Database size caps — optional global and per-table caps (Data Retention → Advanced). Oldest raw rows go first; the last 7 days and dashboard summaries are always kept.
  • Feature: Cleanup Tasks — "Run all now", plus two new tasks: "Database size cap" and "Database schema upkeep".
  • Enhancement: Page speed — frontend trackers are minified and loaded with defer: nothing blocks rendering, tracker weight drops by about half. Tracking behaviour is unchanged.
  • Enhancement: Smaller database — the heatmap events table is up to 10x smaller, duplicate indexes are dropped automatically, and all tables use InnoDB (older MyISAM tables are converted in the background).
  • Enhancement: Funnels page — Suggested Funnels comes first when you have no funnels; your funnel list leads once you do.
  • Enhancement: Clearer data-retention summary, WP-Cron hint under Settings → Reports, and all new strings translated in French, German, Spanish, Italian and Portuguese.
  • Compatibility: Tables shared with Opti-Behavior Pro are now defined once, in Free. Both plugins can be updated in any order without data loss.
  • Code Quality: Passes the WordPress.org Plugin Check with no errors and no warnings.
  • Fix: Server stability on busy sites — cache sweeps on wp_options no longer cause "Lock wait timeout exceeded"; the realtime "Active visitors" widget uses an indexed query and polls every 15 s; heatmap files are written atomically under a per-page lock; daily database upkeep is size-capped.
  • Fix: Duplicate entry … for key PRIMARY on the visitors table when two first hits raced.
  • Fix: Cleanup now respects every retention window — heatmap files, recording side files, archived heatmap data, bot visit logs, error summaries and 404 reports no longer grow without limit.
  • Fix: Dashboard CSV export no longer leaves a temporary file behind; the archive-page cleanup "Configure" link opens the right tab.

v1.9.0

2026-09-08
  • Feature: Smart Insights v2 — insights are ranked by measured cost (the visitors and conversions actually lost, blended with severity and confidence) and labelled Critical/High/Medium/Low by rank inside the batch, so a busy site gets a short ordered shortlist instead of dozens of "high priority" items. Thinly observed signals are flagged as observations to confirm instead of being promoted.
  • Feature: Business impact in money — when a value per conversion is known, cards and the detail modal show the exposure ("≈ $1,240 at risk this period") with the drop-off count, conversion rate and order value behind it. A new "Value of one conversion" setting covers sites without readable WooCommerce order history; WooCommerce data takes precedence.
  • Feature: "Where is the problem?" — every insight now names the audience carrying it. The segment split is computed on the real behaviour tables across 8 dimensions (device, browser, country, traffic source, campaign, new vs returning, time of day, day type) with a significance test, comparison bars you can click to re-scope the evidence, and a daily chart of the metric with the previous period behind it and a "first detected" marker.
  • Feature: Outcome verification — resolving an insight freezes its "before" measurement and a daily job re-measures the same signal over the two weeks that follow. Resolved cards carry a "Fixed — → " chip, the weekly brief gained a "Wins this month" block, and the CSV export gained `outcome_verdict` and `outcome_change` columns. Too little post-fix traffic stores an honest `inconclusive` verdict instead of a win.
  • Feature: Automatic funnel creation — Opti-Behavior detects what kind of site you run (WooCommerce, Easy Digital Downloads, blog/content, lead generation, signup, membership, LMS, booking) and suggests ready-made funnels on the Funnels page, with one-click creation, a "Set up recommended funnels" bulk action, and a "Customize" path that opens the normal builder pre-filled.
  • Feature: Suggested funnel steps resolve their URLs through each source plugin's own API, so localized slugs (`/panier/`, `/commander/`, `/kasse/`) are used as-is. Funnels record where they came from (`source` / `recipe_id`) so re-scanning never creates duplicates, and a "Re-scan site" button plus a per-card Dismiss keep the list under your control. New `opti_behavior_funnel_site_context`, `opti_behavior_funnel_recipes` and `opti_behavior_funnel_recipe_steps` filters and an `opti_behavior_funnel_created` action for developers.
  • Feature: With Opti-Behavior Pro, a funnel created from a suggestion is backfilled from your existing session history so it opens with real numbers, alongside Pro-tier recipes, data-driven "discovered" funnels and a weekly automatic re-scan.
  • Changed: The insight detail modal is readable again — it lists only the reports you can actually open (the rest collapse behind one line), caps recommended actions at three and reconciles their wording against those reports, shows the measured probe-ranked causes with their values, and drops the empty placeholder sections. Traffic-source insights of the same signal collapse into a single list card, and the weekly CRO summary opens with the three costliest issues instead of a count.
  • Changed: Smart Insights opens on Last 3 Months by default (new period option), and the Suggested Funnels panel collapses to a one-line summary ("2 new · 8 created") once you have funnels.
  • Changed: Scheduled cleanup no longer stalls on spam-heavy sites. Spam, bot and automated sessions are an exempt class the daily tier purges unconditionally within its per-run cap, the mass-delete safety limit is measured on the non-spam rules against the non-spam session count only, and a tripped limit produces a logged partial run instead of cancelling the whole run. New `opti_behavior_cleanup_spam_bypasses_safety_limit` escape hatch, and Cleanup History collapses repeated identical entries.
  • Changed: Scheduled cleanup "Maximum sessions per run" default raised from 5000 to 50000 — installs still on the old default are migrated once, custom values are preserved.
  • Changed: All funnel and user-journey admin messages are translatable; all 5 locale catalogs were refreshed.
  • Fix: Report links now arrive already filtered. Opening a report from an insight used to land on an unfiltered view: the Analytics dashboard applies the incoming device, browser, country, OS, traffic source, campaign, medium, channel, visitor-type and entry/exit-page parameters to its first data request, funnel links open the funnel they name on the window the insight was measured on, internal segment keys are decoded to the values the reports really filter on, and device values match regardless of case.
  • Fix: Concurrent first-visit tracking requests could return HTTP 500 through a visitor/session insert race.
  • Fix: Previous-period trends were empty on every insight — the previous window inherited the current window's minimum-sessions filter, device insights were never given a previous period, and Pro-produced error, form and segment insights were skipped entirely.
  • Fix: Funnel insights offered no session recordings and site-wide error or friction insights were collapsed as "not applicable"; both now open the exact scope they were measured on.
  • Fix: "Direct" was missing from the Form Analytics referrer filter options.
  • Fix: Heatmap detail applies a desktop viewport floor, so a narrow reference width no longer selects a mobile or tablet breakpoint.
  • Fix: "Could not load funnel suggestions" on busy, memory-constrained hosts — funnel requests now raise the admin memory limit like the rest of the admin, and the suggestions panel retries its first load once.

v1.8.3

2026-08-27
  • Feature: Filter Profiles — save a named set of advanced-filter values (Visitor, Session, Pages & Traffic, UTM) and reuse it across the Analytics Dashboard, Funnels, and Pro screens. Save / Edit control sits next to Apply / Reset; date range is never stored.
  • Feature: configurable cache purge after funnel modification. New Funnels setting to purge all page caches on every save/delete/status change (default) or never. With "Never", cached pages keep the old funnel config until the cache expires. Per-mutation override via the new `opti_behavior_should_purge_cache` filter (receives the action and funnel ID).
  • Feature: schema parity for Pro's Error Tracking visitor filters. Error, friction, and performance tables now store visitor country; friction and performance also store OS. Existing rows are backfilled. Data-model change only — no free-side behavior change.
  • Fix: cached-page visitor merging — anonymous visitor and session IDs baked into cached HTML made every direct visitor count as one visitor in one session. Identity is now recomputed server-side on each (uncached) tracking request, preserving cookieless privacy.
  • Fix: cached-page traffic under-counting — a stale baked nonce caused bounce visits to go unrecorded. The page-view/session-start request now re-sends once with the fresh nonce, and click batches queued during a refresh are preserved.
  • Fix: cached-page funnel under-counting — with two or more active funnels, a stale nonce silently dropped every step past the first. Funnel tracking now refreshes the nonce once and re-sends each step.
  • lockstep release keeping free and Pro version numbers in sync with Pro's Error Tracking filter enhancement. Free-side change is limited to a shared filter-ui stylesheet sync.

v1.8.2

2026-08-16
  • New: re-architected, user-configurable data retention — set your own tiered retention periods so the plugin auto-manages storage, keeps the database lean and stops resource/space bloat, all from a rebuilt Smart Cleanup screen.
  • New: visitor-segment filtering — slice dashboard stats and every heatmap page by visitor type and attributes, so you can read behavior per segment.
  • Enhancement: heatmap list and detail pages now scale to 500K+ recording files, with faster heatmap table loading on large datasets.
  • Fixed: heatmap session totals are now consistent across the list, filters and detail page (the reset floor is applied everywhere).
  • Enhancement: redesigned heatmap detail page — filter option counts scoped to the hero session set, detail date inputs synced with the presets, and a more compact stats layout.
  • Enhancement: never-synced pages are merged into the heatmap fast path instead of forcing a full scan.
  • Fixed: cache poisoning — bot and IP exclusion moved from asset enqueue to data ingest, so cached pages no longer skew stats.
  • Fixed: session-duration over-accumulation and spam-excluded average session time.
  • Fixed: A/B variant filters are treated as advanced result filters, and stale/under-counted filter options under A/B variant scope are corrected.
  • Enhancement: simplified the sessions pill tooltip to single-number semantics.
  • Enhancement: Top Pages widget redesigned with a stacked layout; the Top Engaged Users table now fills the widget height instead of a fixed 380px cap.
  • Fixed: on large sites, upgrading could make the site unreachable — heavy database migrations and index builds now run in the background (one step per cron tick, resumable), never in a web or AJAX request.
  • Enhancement: the storage stats tab now loads asynchronously to stop long blank-page waits.
  • Enhancement: debug mode auto-disables after 3 hours and debug JavaScript is no longer loaded when debug is off.
  • Fixed: the Admin Language setting had no effect on WordPress 6.7+ — translations now load through WordPress's standard pipeline, with a new "Same as WordPress" default, and all locale catalogs were refreshed.

v1.8.1

2026-08-02
  • Fix: Bug in the last update that stopped the plugin.

v1.8.0

2026-08-01
  • New: Interactive heatmap preview — click to expand accordions, menus, popups and other collapsed elements directly inside the preview, with clicks anchored to their element and redrawn correctly as it’s shown/hidden. Preview now also renders at the selected device’s real viewport width (mobile/tablet/desktop), so heatmaps match the actual responsive layout.
  • New: IP exclusion setting to exclude specified addresses from tracking.
  • Fix: Guest preview iframe AJAX/REST requests failed nonce checks by running with admin cookies instead of the guest context.
  • Enhancement: Tracker assets are cache-busted/versioned with the plugin version, and the anon broker script is registered in the optimizer-compat registry so cache/optimizer plugins never delay it.
  • Enhancement: Filter-bar buttons on the heatmap page aligned to filter select height; “All devices” view reprojects anchored clicks onto the current layout for consistent hotspots.

v1.7.2

2026-07-16
  • Enhancement: Smart Insights notification cards, the Smart Insights center list, and the insight detail footer now show when each signal was detected as a relative time ("4 hours ago") with the exact localized date and time on hover.
  • Fix: Saving Traffic Classification settings no longer resets the "Track admin users" preference — the admin tracking setting saved on the same tab is now preserved instead of being silently re-enabled.

v1.7.1

2026-07-12
  • Feature: Added a tracker heartbeat detection layer — if site traffic keeps flowing but no heatmap/funnel/A/B events arrive for six hours, a dismissible admin notice identifies the caching or optimization plugin most likely blocking the trackers, with a link to the fix guide.
  • Feature: Added an early-event capture queue printed at the very top of the page, so clicks and interactions that happen before the (deferred or delayed) tracker script loads are buffered and replayed instead of lost. Guarantees zero missed early clicks under WP Rocket "Delay JavaScript execution" and similar optimizers.
  • Enhancement: Centralized the cache and page-optimizer compatibility logic into a single `Opti_Behavior_Optimizer_Compat` layer, replacing the duplicated exclusion rules that lived across the heatmap, funnel, and Pro tracking classes.
  • Enhancement: Unified the tracking script-tag protection attributes (`nowprocket`, `data-cfasync="false"`, `data-no-optimize`, `data-no-defer`, `data-noptimize`, `data-jetpack-boost="ignore"`) so every self-hosted tracker is shielded consistently from JS minify, combine, defer, and delay optimizations.
  • Enhancement: Registered verified optimizer exclusion filters — WP Rocket (minify/combine, defer, deferred and combined inline JS), SiteGround Optimizer (handle-based combine and inline combine), Perfmatters (defer and minify), WP-Optimize (URL-substring minify), Jetpack Boost (concatenation), LiteSpeed Cache (defer), W3 Total Cache (tag minification), and Breeze (aggregation) — all fed from the shared protected-scripts registry for zero-config coverage.
  • Enhancement: A/B tracking batches now retry up to 3 times with backoff on network or HTTP failure (nonce re-read on every retry), and expired security nonces are transparently refreshed with one retry, so conversions recorded on long-cached pages are no longer rejected. Server-side unique keys keep retries idempotent.
  • Enhancement: A/B variant assignment now also sets a companion `opti_ab_v` cookie registered with WP Rocket and LiteSpeed Cache dynamic-cookie/vary lists, so variant-specific caching stays correct.
  • Enhancement: Preview and editor requests now set cache-bypass constants (`DONOTCACHEPAGE`, `DONOTROCKETOPTIMIZE`) so page previews are never optimized or cached.
  • * Enhancement: Activating or deactivating the plugin now purges all known full-page caches (WP Rocket, LiteSpeed, W3 Total Cache, WP Super Cache, WP Fastest Cache, Cache Enabler, Hummingbird, SiteGround Optimizer, Autoptimize), so stale cached HTML never keeps serving trackers that no longer match the plugin state. Page caches are also purged when funnels change, so new funnels start tracking on cached pages immediately.
  • Performance: Cut per-visitor admin-ajax request volume by roughly 90% through consolidated tracker batching and reduced flush frequency, stopping site-wide slowdowns on busy sites.
  • Fix: WP Rocket minify/combine and defer exclusion patterns were emitted as self-delimited regexes that never matched once WP Rocket joined and re-wrapped them; they are now bare regex fragments, restoring tracker exclusion under "Minify/Combine JavaScript" and "Defer JavaScript".
  • Fix: SiteGround Optimizer exclusion filters now receive script handles (previously filenames, which never matched), and WP-Optimize filters now receive URL substrings only — both silently ineffective before. Removed a Jetpack Boost render-blocking filter that does not exist in the plugin; concatenation exclusion via `js_do_concat` remains and is verified.
  • Fix: Funnel "Exact match" steps compared the full page URL against the stored path pattern with raw string equality, so path-only patterns (e.g. `/checkout/`) never matched and conversions silently recorded zero. Matching is now a normalized comparison (scheme/host aware, trailing-slash and case insensitive, fragments ignored, query compared only when the pattern includes one), mirrored in PHP and JS.
  • Fix: Funnels analytics queried the wrong sessions table and columns, so funnel reports could undercount or miss sessions entirely.
  • Fix: A new funnel did not appear in the dashboard until a manual page refresh.
  • Fix: Pages with an active A/B test send `Cache-Control: no-store` and set `DONOTCACHEPAGE`, so page caches and CDNs never serve stale variant HTML or expired nonces.
  • Fix: Element A/B variant changes never rendered for non-`#id` selectors (class, attribute, or path selectors); all valid CSS selectors now apply.
  • Fix: The A/B unload flush stayed disarmed after the first tab switch, dropping conversions recorded near the end of a visit.
  • Fix: With the Pro add-on deactivated, the heatmap dashboard showed no data when "Exclude spam traffic" was on — the spam allow-list depended on a table only Pro populates. It now also accepts equivalent evidence from the free tracker's own pageview records, so free-only installs keep full heatmap visibility with identical spam/bot/duration gates.
  • Fix: The heatmap tracker crashed when optimization plugins delayed script execution; it now initializes safely regardless of load order.
  • Fix: Heatmap overlays failed on very tall pages in Firefox due to the browser canvas area cap; rendering now respects the cap and stays visible.
  • Fix: `CREATE TABLE IF NOT EXISTS` statements caused dbDelta fatals under W3 Total Cache database caching; table creation is now dbDelta-safe.
  • Fix: Empty page titles are backfilled from tracked data and orphan URL-less page stubs are removed, so pages stop showing as "Untitled Page".
  • Maintenance: Safer data-cleanup defaults for new and updated installs — scheduled cleanup now runs daily (was weekly), the short-session cleanup rule is now "shorter than 5s, older than 1 day" (was 2s/30 days), and the spam duration threshold is now 3s (was 10s). Existing installs receive the new defaults once after update.

v1.7.0

2026-07-04
  • Performance: Rebuilt the Analytics dashboard and Heatmaps page for large sites — parallel cached widgets, four collapsible sections, chart rendered from the shared stats payload, and pre-computed indexed heatmap aggregates. Cold loads drop from ~35–50s to seconds; all displayed numbers are identical and live.
  • Fix: Rewrote the User Intent query to drop a fan-out join that corrupted intent classification, and resolved dashboard load races (duplicate widget AJAX, chips stuck on "—", stuck chart spinner).
  • Enhancement: Redesigned the collapsible section headers and added a heatmap schema migration plus a `tools/backfill-heatmap-aggregates.php` pre-warm script.
  • Compliance: Passed the WordPress.org Plugin Check with no warnings; bumped to 1.7.0 and synced the Pro add-on to the same version. No data changes.

v1.2.8.1

2026-04-28
  • Fix: A/B Testing Visual Editor launchers now use native direct links for saved variants, preventing ad blockers and popup blockers from making Open Visual Editor appear broken.
  • Fix: Visual Editor Preview now uses a server-side save-and-redirect form flow instead of script-created popups, so preview opens reliably with unsaved changes.
  • Enhancement: Added regression coverage for popup-blocker-safe Visual Editor opening and preview behavior.

v1.2.8

2026-04-28
  • Feature: Added expanded A/B testing tools for page-split experiments, visual variant previews, winner application, and conversion goal tracking.
  • Feature: Added improved A/B test results reporting with impressions, conversions, conversion rate, and winner indicators.
  • Enhancement: Improved A/B attribution for page-split variant pages and cross-page goals so experiment results stay accurate across visitor journeys.
  • Maintenance: Prepared the Free plugin package metadata, version constants, readme stable tag, and changelog for the 1.2.8 release.

v1.2.7

2026-04-09
  • Feature: Selective data deletion in Danger Zone — 9 category checkboxes (Sessions, Visitors, Events, Heatmaps, Recordings, Traffic, Errors, Funnels, Forms) let users choose which data to delete instead of deleting everything
  • Enhancement: Select All / Deselect All toggle for quick category selectio
  • Fix: False-positive broken links — same-origin images and internal pages no longer flagged as "Blocked" when server blocks HEAD requests (LiteSpeed Cache, WAF). HEAD failures now fallback to GET verification before saving
  • Fix: Error source now shows actual JS file path instead of generic "admin-ajax.php" — uses call stack capture at fetch/XHR call time
  • Fix: Session recorder console.log/warn messages now gated behind the Debug & Logging "Enable JavaScript Debug Logging" setting — no more console spam on production sites
  • Enhancement: JS Errors page file links now show full URL on mouse hover (tooltip) and are clickable to open the source file directly
  • Enhancement: IMG resource error verification uses HEAD + GET fallback with _optiVerify flag to prevent XHR interceptor self-tracking

v1.2.6

2026-04-7
  • Fix: Attention heatmap showing click stats instead of scroll stats
  • Enhancement: Admin tracking settings, admin bar offset, login detection
  • Enhancement: Translations updated (FR, DE, ES, IT, PT-BR)
  • Feature: Onboarding popup

v1.2.5.1

2026-04-5
  • Enhancement: Replace raw console.log/warn/info in session-recorder.js
  • Fix: All visitor-facing and admin console output now respects the debug logging settings in wp-admin

v1.2.5

2026-04-5
  • Fix: Session recording playback shows white empty page on live server — set inlineStylesheet:false to prevent oversized FullSnapshot payloads (3–7 MB) that Hostinger nginx rejects
  • Fix: Added oversized-payload guard in session-recorder.js — warns when non-beacon payload exceeds 1 MB
  • Fix: PHP empty-events guard — rejects AJAX saves with no events when no DB row exists yet
  • Enhancement: Comprehensive debug logging in JS (FullSnapshot detection, save batch type distribution, server response) and PHP (error_log for event types, FullSnapshot presence, file save confirmation)
  • Fix: Removed console plugin from rrweb config to eliminate type-6 events and extra payload bulk

v1.2.4.2

2026-04-04
  • Fix: Heatmap data protection improvements and welcome page refinements
  • Enhancement: Minor code quality improvements across core files

v1.2.4.1

2026-04-03
  • Fix: Resolve PHP 8.2 null deprecations + wpdb prepare mismatch

v1.2.4

2026-04-03
  • Fix: Resolved all WordPress Plugin Check errors and warnings (escape output, nonce verification, readme compliance)
  • Fix: GDPR consent banner not displaying — admin-notices CSS/JS no longer hides plugin's own ob-* elements
  • Enhancement: Default auto-cleanup on fresh install (weekly, 90-day retention, bot/bounce session removal)
  • Enhancement: Moved Pro trial offer above feature list on welcome page for better visibility
  • Fix: Consent banner logic simplified — removed obsolete checkbox, uses Consent Banner Source radios only

v1.2.3

2026-03-29
  • Feature: Frontend Stats Bar — admin-only analytics overlay on every frontend page with 6 color themes and per-stat visibility settings
  • Feature: Custom SMTP email configuration for scheduled reports with WP Mail fallback, and Cron Monitor for scheduled task health
  • Enhancement: Full cache plugin compatibility (Autoptimize, LiteSpeed, WP Rocket, SG Optimizer) — nonce refresh, client-side cookie IDs, script tag protection, and visibilitychange flush
  • Enhancement: Optimized live visitors query, esc_sql() hardening, admin submenu reorder, and PHPCS compliance fixes
  • Fix: 10 Smart Data Cleanup bugs (recording file deletion, cascade orphans, scheduling), debug log download fatal error, and auto-cleanup via daily cron

v1.2.2

2026-03-22
  • Feature: Rich banner styles — info, warning, success, promo, custom with configurable colors, images, and CTA buttons
  • Enhancement: Dismiss tracking stores timestamps for duration-based re-show logic with automatic migration from old format
  • Fix: Self-referral bug — site's own domain no longer appears as referrer in analytics, user journey, and form analytics views

v1.2.1

2026-03-17
  • Feature: Server-side proxy for heatmap iframe loading — bypasses CDN-level X-Frame-Options restrictions (e.g., Hostinger) that block iframe embedding
  • Enhancement: Heatmap iframe now uses `srcdoc` with proxied HTML content, injecting `<base href>` for correct relative URL resolution
  • Enhancement: Generic JS scan to detect and cap elements with inflated inline heights from unknown/custom slider frameworks
  • Fix: Heatmap iframe blank/error on sites with CDN-level `X-Frame-Options: deny` (e.g., Hostinger-hosted sites)
  • Fix: Server-side proxy added to both Free and Pro AJAX classes to prevent action not registered error when Pro overrides Free
  • Fix: Removed broken CDN Lucide CSS (`cdn.jsdelivr.net`) from Pro detail page that caused MIME type error
  • Security: Proxy endpoint restricted to same-site URLs only, with nonce verification and `manage_options` capability check

v1.2.0

2026-03-11
  • Feature: "Try Pro FREE for 6 Months" admin banner with trial countdown, dismiss, and expired state variants
  • Feature: ipwho.is secondary geolocation API fallback when ip-api.com is rate-limited (free, HTTPS, no rate limit)
  • Enhancement: License-aware trial banner visibility using Manifest Manager (hidden for valid Pro license, shown for expired trial)
  • Enhancement: Geolocation fallback chain expanded: CloudFlare → Cache → ip-api.com → ipwho.is → Timezone → Browser Language
  • Enhancement: Added ipwho.is to External Services disclosure, FAQ, and Privacy Policy sections in readme.txt
  • Fix: Trial banner dismiss button now removes element from DOM instead of CSS hide (fixes specificity conflict with admin-notices.css)
  • Fix: Trial banner no longer appears when Pro plugin is active with a valid license
  • Fix: "Unknown" country in Real-time Visitors resolved for high-traffic sites exceeding ip-api.com 45 req/min rate limit
  • Fix: Stable tag mismatch between readme.txt and main plugin file header
  • Fix: Short description trimmed to 150-character WordPress.org maximum

v1.1.1

2026-03-10
  • Fix: PHP version compatibility check was comparing against non-existent PHP 7.6 instead of 7.4, preventing activation on PHP 7.4.x servers
  • Enhancement: Added OptiUser API (api.optiuser.com) and OptiUser Website (optiuser.com) to External Services disclosure for WordPress.org compliance
  • Enhancement: Expanded FAQ "Does this plugin call any external services?" with detailed list of all 4 external services
  • Enhancement: Added "Try Pro FREE for 6 months" call-to-action in Pro Features section with direct download link
  • Enhancement: Updated upgrade pages with 6-month free Pro trial messaging and hidden download page URL

v1.1.0

2026-03-09
  • Feature: Plugin install tracker with 24-hour heartbeat mechanism for anonymous usage statistics
  • Feature: Automatic plugin type detection (Free/Pro) in tracker heartbeat data
  • Feature: Deactivation notification to API for immediate status updates
  • Enhancement: Autoloader class conflict prevention for shared Free/Pro classes (Ajax, Detail Page, Parser, Cache)
  • Enhancement: Heatmaps sessions column now uses file-based device counts (Desktop + Mobile) for accurate sorting
  • Enhancement: Heatmap table column widths rebalanced to accommodate tooltip icons and translations
  • Enhancement: Table headers no longer truncated — always fully readable with nowrap styling
  • Enhancement: Title truncation moved from PHP to CSS text-overflow for cleaner hover tooltips
  • Fix: Autoloader excluding shared Pro/Free classes to prevent Free overriding Pro AJAX handler
  • Fix: Heatmap detail page duplicate rendering caused by auto-instantiation
  • Fix: SQL prepared statement parameter mismatch when date filters were active on heatmaps
  • Fix: Sessions ORDER BY alias referencing non-existent table alias
  • Fix: Plugin re-activation now triggers immediate heartbeat to update API status
  • Fix: Removed unexpected ARCHITECTURE.md file from plugin root (Plugin Check compliance)
  • Fix: Wrapped all error_log() calls in WP_DEBUG guards for production safety
  • Fix: Synced Stable tag and Plugin Name between readme.txt and main plugin header
  • Fix: Removed localhost/development URL from tracker API endpoint
  • Code Quality: Clean uninstall with tracker options and cron job cleanup

v1.0.9

2026-02-10
  • Feature: Smart Data Cleanup system with bot/spam removal, quality thresholds, and scheduled auto-cleanup via WordPress cron
  • Feature: Comprehensive tooltip system across all pages (Dashboard, Heatmaps, Funnels, Settings, Form Analytics, Error Tracking)
  • Feature: Form Analytics upgrade page with menu integration, database table handlers, and scheduled report support
  • Feature: Danger Zone redesign with horizontal sub-tabs (Full Reset, Date Range, Smart Cleanup, Auto Schedule)
  • Feature: German (de_DE) language support with complete translations
  • Feature: Italian (it_IT) language support with complete translations
  • Feature: Spanish (es_ES) complete translation files
  • Feature: Portuguese (pt_BR) complete translation files
  • Enhancement: Replaced all emoji icons with Lucide SVG icons throughout the plugin for professional UI
  • Enhancement: Unified page header style across all pages (Dashboard, Heatmaps, Funnels, Settings, Recordings, Errors)
  • Enhancement: Country flag icons in language dropdown selector
  • Enhancement: Funnel step cards made more compact with improved layout and per-funnel country filter with flag icons
  • Enhancement: Heatmaps page search functionality and mobile preview mode for heatmap iframe
  • Enhancement: Guest preview mode for accurate non-logged-in heatmap display
  • Enhancement: Replaced Data Protection tab with Storage Stats page with improved tooltips
  • Enhancement: Standardized button styles with Lucide icons and btn-danger class for destructive actions
  • Enhancement: Added User Journeys and Form Analytics data to scheduled email reports
  • Enhancement: Improved browser/OS detection with HarmonyOS support and better bot detection
  • Enhancement: PRO feature gating with badges on menu items, heatmap tooltips, and blocked PRO heatmap types for free users
  • Enhancement: Admin menu icon updated to 35×35 PNG with hover states
  • Enhancement: French translations extensively improved with shortened menu labels
  • Enhancement: AI Insights panel with Lucide icon styling and default message
  • Fix: Move Heatmap trajectory rendering with proper coordinate scaling and adaptive colors based on website background
  • Fix: Scroll Heatmap legend positioning and visibility
  • Fix: Attention Heatmap legend positioning moved outside iframe with smooth gradients and base color coverage
  • Fix: Bounce rate KPI mismatch with daily history chart
  • Fix: Heatmaps page Mobile Traffic showing 0% – Device Split now uses sessions data
  • Fix: Session count mismatch between total and device split
  • Fix: Time period filter icon and dropdown functionality with correct default selection
  • Fix: Traffic Overview chart layout with reduced empty space
  • Fix: Funnel URL matching filters and string concatenation bug
  • Fix: Conditional cleanup settings not persisting after page refresh
  • Fix: Date range file deletion now includes uploads/opti-behavior-data/ directory
  • Fix: Delete All Data not clearing storage properly
  • Fix: Top Engaged Users widget column width for long country names
  • Fix: Scheduled reports SQL error and instant stats update
  • Fix: Heatmap download now includes page content with overlay
  • Fix: Stat history bar charts display
  • Fix: Stats inconsistency when Pro is active
  • Code Quality: WordPress Plugin Check – 0 errors, 0 warnings (100% compliant)
  • Code Quality: Renamed non-prefixed variables in HTML templates with opti_behavior_ prefix
  • Code Quality: Complete uninstall cleanup with all database tables, cron jobs, transients, and legacy directories

v1.0.8

2025-12-08
  • Feature: User Intent Rules – Advanced system for analyzing and categorizing user behavior patterns
  • Enhancement: Analytics Dashboard time filter now defaults to 30 Days for better data overview
  • Fix: Improved favicon handling for referrer websites with proper fallback support

v1.0.7

2025-12-02
  • Enhancement: Added French language translations for improved internationalization
  • Fix: Resolved sendPageView function issues for accurate page tracking
  • Fix: Corrected Returning Visitors calculation and display
  • Fix: Fixed Logged In Visitors detection and counting
  • Feature: Display username for logged-in visitors in Top Engaged Users widget
  • Enhancement: Extended device type support for all device categories (desktop, mobile, tablet, PC)
  • Code Quality: WordPress coding standards compliance improvements
  • Code Quality: Added debug logging controls via settings page
  • Security: Fixed nonce verification warnings
  • Security: Enhanced prepared SQL statements with proper phpcs annotations

v1.0.6

2025-11-30
  • Feature: New vs Returning Visitors analytics dashboard widget
  • Feature: Visited Directories analytics with depth tracking and page views
  • Feature: Visitor Authentication analytics showing logged-in vs guest users
  • Fix: WordPress DB coding standards – SQL wildcards now use placeholders
  • Enhancement: Improved prepared SQL statements compliance
  • Code Quality: Full WordPress.DB.PreparedSQLPlaceholders compliance

v1.0.5

2025-11-23
  • Fix: Removed all debug error_log() calls from production code
  • Fix: Replaced date() with gmdate() for timezone-safe date handling
  • Fix: Added translator comments for i18n compliance
  • Fix: Updated API URL from localhost to production endpoint
  • Fix: Corrected stable tag version mismatch
  • Enhancement: Improved readme with better descriptions and FAQ
  • Enhancement: Added Plugin URI and updated Author URI
  • Enhancement: Optimized WordPress.org directory submission compliance
  • Compatibility: Full WordPress 6.8 compatibility verified
  • Enhancement: Added COALESCE for better handling of NULL titles in Top Pages
  • Enhancement: Improved country detection with browser language fallback when IP geolocation fails
  • Enhancement: Top Pages widget now displays page views instead of clicks for better accuracy

v1.0.4

2025-11-20
  • Enhancement: Added file-based storage system for high-traffic sites
  • Enhancement: Implemented automatic bot detection and filtering
  • Enhancement: Added performance optimizer with automatic database indexing
  • Enhancement: Separate mobile and desktop heatmap tracking and visualization
  • Enhancement: Batch processing for improved performance
  • Enhancement: Enhanced debug logging system with WordPress-compliant manager
  • Enhancement: Added Lucide icon library (v0.554.0, ISC License) for modern UI
  • Security: Replaced direct filesystem operations with WP_Filesystem API
  • Security: Replaced unlink() with wp_delete_file() for file deletion
  • Code Quality: WordPress coding standards compliance improvements
  • Code Quality: Improved data sanitization and validation
  • Compatibility: Tested up to WordPress 6.8

v1.0.3

  • Security: Fix Unsafe SQL calls
  • Security: Fix files and directories locations use
  • Security: Moved inline CSS to external stylesheet
  • Security: Moved inline JS to external stylesheet
  • Follows WordPress coding standards
  • Plugin Check validation passed

v1.0.2

  • Review and fix all the issues listed in the review email.

v1.0.1

  • Security: Enhanced sanitization for $_SERVER variables
  • Security: Improved json_decode() data sanitization
  • Security: Moved inline CSS to external stylesheet for WordPress compliance
  • Code Quality: Added proper sanitization for all user inputs
  • Code Quality: Enhanced data validation in AJAX handlers
  • Compatibility: Verified all security checks are in place

v1.0.0

  • Initial release
  • Visual heatmap tracking
  • Real-time analytics dashboard
  • Page performance metrics
  • User journey tracking
  • GDPR compliance features
  • Data export functionality
  • Multisite support
  • Debug mode for troubleshooting

Build with the latest Opti-Behavior release.

Install the free plugin, then upgrade to Pro when you need recordings, advanced diagnostics and deeper journey analytics.

Explore
Drag