EN
Language · same page NLNederlands/wordpress-heatmap-en-scrollmap-plugin/ ENEnglish (UK)/en/wordpress-heatmap-and-scrollmap-plugin/ ESEspañol/es/wordpress-heatmap-y-scrollmap-plugin/ We do not remember your choice and never redirect you automatically.
SRV · service · heatmap plugin reg. T.000 · wordpress · gplv2 or later

WordPress heatmap and scrollmap plugin by us

With our heatmap and scrollmap plugin, you see where visitors click and where they drop off, without any data going to an external platform. This page is the explanation that goes with it: how those maps are built, how to read them without drawing the wrong conclusion, what gets recorded per event, and what deliberately doesn't. You can download it yourself below, and the product page with the map view is at heatmap and scrollmap without cookies.

Download the plugin ↓ Book a call wp-ux-heatmap-2.1.0.zip · 82 KB · version 2.1.0 · GPLv2 or later · no account, no registration, no key
WordPress6.0 or higher. The plugin states it has been tested up to and including 7.0.
PHP7.4 or higher. The code has been checked against 8.5.
PermissionsYou need manage_options, so administrator.
Screen languageThe screens are written in English, with a full Dutch translation included in the zip. So on a Dutch WordPress site, they appear in Dutch.
Also found on Full source code on GitHub The zip file above and the source code on GitHub are the same version, 2.1.0. This page describes what gets recorded per event; on GitHub you can verify that yourself instead of taking our word for it. The table structure is in includes/class-wpuxh-install.php and what comes in is in includes/class-wpuxh-request.php. This plugin isn't in the official WordPress plugin directory yet: it hasn't been submitted.
Gianluca, who does the work on this page himself
image · whoever does the work also writes the guide
FIG.01 · The switches, not the map

The screen where you decide what gets measured

The map itself is on the product page. This is the other screen, and the most important one for this explanation: under UX Heatmaps and then Settings, you'll find what is and isn't measured, how long it's kept, and how many rows are currently in your table. Measuring stays switched off after activation; you turn it on yourself here.

wp-admin · UX Heatmaps · Settingsschematic · not a screenshot from a live customer site

UX Heatmap and Scrollmap

Settings

Measuring

Enable trackingOff after activation. If you switch it off again later, the data already collected simply stays where it is.
Track logged in usersOff. So you and your colleagues don't clutter the map with your own clicks.
Track scroll depthOn. Switch this off and it only measures clicks, leaving the scroll panel empty.

Privacy

Respect Do Not TrackOn. That's what the field in the screen is called. The plugin looks for two signals: Do Not Track and Global Privacy Control. If the browser sends either one, the plugin measures absolutely nothing for that visitor.
Keep events for90 daysA daily task deletes anything older than that. If you choose to keep everything, the screen notes that nothing disappears automatically.

What is in the table right now

Rows in wp_wpuxh_events4.812
Oldest event21 May 2026
Columns with visitor data0
Delete all events
The numbers in this view are an example. What is accurate is the structure and the settings: measuring is off after activation, logged-in users aren't tracked, Do Not Track is respected, and the retention period is set to ninety days. The line showing zero columns of visitor data isn't decoration: version 1.x kept a hashed fingerprint of the IP address and the full browser string, and version 2.0.0 removes those two columns, including everything that was already in them.
DOC.01
DOC.02

Why a plugin of your own often works better than external tools

Many heatmap tools run outside your website entirely. You send your visitors' behaviour to an external platform, need an account for it, and usually get a cookie notice thrown in. UX Heatmap and Scrollmap takes a different route: everything stays inside your own WordPress. Events go to your own admin-ajax.php and into a table of their own in your own database, and the plugin makes no request to any other server whatsoever. Not even to us: we don't even see that you've installed it.

What that costs in speed is easy to see

The front-end script is a 17.7 KB file with no dependencies, roughly 5.3 KB compressed over the wire, it loads in the footer, and it caps itself at a maximum of 250 events per page view. It doesn't block the page from rendering. No promise about your own load time, mind, since that depends on your whole site; this is just what this plugin adds to it.

The plugin is part of our wider software range, which also includes the AI Traffic Loss Shield and the llms.txt generator, both of which are free too.

This plugin suits your situation if you want to see behaviour without loading visitors up with external scripts, if you want insight inside the same WordPress dashboard, or if you're after a lightweight solution that fits a fast site.

DOC.03

What the plugin does and how the data comes in

Under the hood, exactly two things happen on the front end of your site, and nothing else. On a click, the script remembers where that click landed, and on scrolling, how far down the visitor got on that page. That goes to your own WordPress, and that's where it stops.

What travels with each click is the position within the window, and that same position as a percentage of the full page height

That second figure is the difference between a map that's accurate and one that's nonsense: without that percentage, a click near the bottom of a long page gets drawn near the top, and that's precisely the bug that was in version 1.x. Scroll depth is stored per page view as the deepest point reached, so someone scrolling up and down doesn't get counted four times over.

The desktop, tablet and mobile filter is derived from the window width the browser sends itself, not from a browser fingerprint or a device name

Done deliberately that way: a window width says enough to form three groups and is nothing you could identify anyone by. We didn't want to know any more about it either.

Want to turn your first results straight into action? Use this worksheet:

  • The page you're looking at
  • The pattern that jumps out at you straight away
  • The element that gets a lot of clicks
  • The element that gets almost no clicks
  • The change you want to test at a minimum
DOC.04

How to install the plugin

The download is at the top of this page, with no request and no account needed. It's an ordinary plugin zip that you upload just like any other. Budget five minutes, and a day's worth of traffic before there's anything to see.

STEP 1 · GET IT

Click the download button at the top. You'll get wp-ux-heatmap-2.1.0.zip, 82 KB. Don't unzip it: WordPress wants the zip file itself.

STEP 2 · UPLOAD IT

In WordPress, go to Plugins, then Add New Plugin, and click Upload Plugin there. Choose the zip file, click Install Now, and then Activate Plugin.

STEP 3 · SWITCH IT ON

Measuring is off by default. Go to UX Heatmaps, then Settings, and switch on Enable tracking. You'll then see the screen from FIG.01 above, with the counter alongside it.

STEP 4 · TAKE A LOOK

Open your site in a window where you're logged out and click around a bit. Then open UX Heatmaps and choose your page from the list on the left.

There's no external account involved, and no key is needed. If the list of pages stays empty, either Enable tracking is still off, or you're logged in yourself while logged-in visitors aren't counted. If the window showing your own page stays blank while the numbers next to it are still correct, your site is blocking display in a frame via X-Frame-Options or a Content-Security-Policy; that's a setting on your site, not on the plugin, and the numbers stay accurate regardless.

Would you rather be guided through the installation? Our WordPress specialist can help you get started. If you've just had a new site built, for example with a WordPress website built in Tilburg, this plugin is a logical next step to see straight away how visitors use your new site.

FIG.02 · What a map proves

Half the job is not reading too much into a blob

A heatmap is convincing to look at, and that's exactly the danger of it. This is the line we draw ourselves before we take a page apart: on the left, what the map actually proves; on the right, what you're reading into it that isn't really there.

reading it without fooling yourselfthe map does say this · and not this
This is what the map proves
  • Where people clicked. That's a counted fact, not an interpretation, and it sits exactly where the visitor's finger or mouse actually was.
  • How far people got. The scroll panel shows what share of visitors reached 25, 50, 75 and 100 per cent of the page.
  • That something gets clicked which isn't a link. The list of elements notes whether the clicked element was actually a link.
  • That mobile behaves differently from desktop. The same design regularly produces two different maps.
This is what you're reading into it yourself
  • Why someone clicked. Curiosity, confusion and enthusiasm all produce exactly the same blob.
  • That a cold button is a bad button. Often it simply sits below the point where most people had already left.
  • That the change was what caused it. The map shows difference, not cause. Anyone who wants certainty needs a proper test, and this plugin doesn't run one.
  • That the map still holds after a redesign. It draws at the position of the click, not on the element itself. Move your blocks around, and older clicks no longer point at anything.
  • That this is about individuals. Every page view gets a new random number, so you see behaviour on a page, never anyone's journey.
Practical rule: a blob is a question, not an answer. Change one thing at a time, leave it for a week, and see whether the scroll panel moves with it. What to do with the four common patterns is set out as a reading guide on the plugin's product page.
DOC.05

Privacy: what gets recorded per event

This is the reason this plugin exists alongside every other heatmap tool out there, so it belongs here in full. Every click or scroll step produces exactly one row in your own database, and it contains this:

  • a random number that keeps the events of one page view together and disappears the moment the page closes;
  • the type of event, click or scroll;
  • the page's path, without the query string and without the anchor, because that's the part of a web address where a name, an email address or a token can end up;
  • the click position, and that position as a percentage of the full page height;
  • the width and height of the window;
  • the scroll depth as a percentage;
  • a short CSS selector for the clicked element;
  • the full height of the page at that moment;
  • two flags saying whether the click was part of a rage click or a dead click, plus how big that rage click was;
  • a single figure saying whether this page view started here or arrived via a click on your own site;
  • the time according to your own server.

And this is deliberately not in it: no cookie and nothing in localStorage or sessionStorage, no IP address, not even as a hashed fingerprint, no browser string, no user number, no link to a WordPress account, and no referring address, only that one figure saying whether the visit came from your own site. Nothing goes to us or to any other party either, because the plugin makes no outgoing request at all.

The number that keeps a page view together is new every time

So two visits from the same person are two separate sets of rows with nothing in common. That's the trade-off: you can't track anyone across your site, and in exchange, there's nothing to track.

The plugin sets no cookie and writes nothing to your visitor's storage

That removes the reason a heatmap tool usually needs a cookie banner. Whether you need no consent at all in your own situation is for you and your own legal adviser to decide: Article 11.7a of the Dutch Telecommunications Act covers anything placed on or read from a device, not just cookies, and the EDPB guidelines of 7 October 2024 also count instructions telling the browser to send information back as falling within that scope.

Among other things, this plugin sends along the width and height of the screen

What you put in your own privacy notice beyond that remains your own call, and the settings screen from FIG.01 shows literally what's in the table and how many rows there are, so you can show that to a customer or to a Data Protection Officer. Why we draw that line is explained in our cookie policy.

If an older version was already running on your site, the update to 2.0.0 removes two columns of visitor data from the table, including everything that was already in them

That's deliberately irreversible.

DOC.06

Using heatmap and scrollmap data for SEO, conversion and AI

For SEO, you use the data to see whether visitors actually reach the most important information. You spot the parts of a page where people get stuck, move content to positions that get more attention, and back up SEO changes with visual data instead of assumptions.

For conversion, you check whether your call-to-action buttons are placed logically

You compare variants with a different order of blocks, use scrollmap data to make the case about the length of a form, and link the insights to A/B testing.

The tool can also be combined with protecting your content against being scraped by AI

You use the heatmap and scrollmap data to work out which blocks on a page get the most attention, and are therefore most worth protecting.

Would you rather work step by step? Use this action plan:

  • The most important insight from the heatmap
  • The most important insight from the scrollmap
  • The change you're going to test straight away
  • The page where you want to take a second measurement
  • How this ties into your wider SEO and AI strategy
DOC.07

Checklist for a good start

Work through these points before you draw your first conclusions.

  • You've installed and activated UX Heatmap and Scrollmap
  • You've selected at least one page to measure
  • You've written down beforehand what you want to learn
  • You've compared the first patterns with your expectations
  • You've planned at least one change
  • You've thought about how this fits your wider SEO and AI strategy
DOC.08

Frequently asked questions

What does this cost in speed?

The front-end script is a 17.7 KB file with no dependencies, roughly 5.3 KB compressed over the wire, it loads in the footer, it doesn't block the page from rendering, and it sends a maximum of 250 events per page view. We can't promise more than that, because the rest of your load time is about your site, not about this plugin.

Do I need an external account or a separate cookie banner?

Neither. It runs inside WordPress, sets no cookie and writes nothing to your visitor's storage, so the reason a tool like this usually needs a cookie banner falls away. Whether that means you need no consent at all remains your own call, made with your own legal adviser: Article 11.7a of the Dutch Telecommunications Act covers anything placed on or read from a device, not just cookies. What actually gets recorded is set out above under DOC.05.

Does it work with a caching plugin?

Yes. Nothing in the page ever expires, so a page served from the cache keeps measuring. The admin screen itself is never cached by WordPress.

Does the plugin work alongside our other tools?

Yes, and with your existing analytics too. It doesn't replace anything, it just tells you something about a page that a table can't. The other two free plugins are the AI snippet previewer and the llms.txt generator.

Can I safely use the plugin on client sites?

Yes. The data stays inside that client's own WordPress, nothing goes to us, and the settings screen shows literally what's been kept and how many rows that is. You can show that to a client or to a Data Protection Officer.

What happens if I remove the plugin?

Then the table and the settings disappear. Deactivating doesn't do that: it just stops the daily clean-up task, and your measurements stay in place, so switching a plugin off for a while doesn't cost anyone their figures.

09 · Next step

Next step

The quickest route is the button at the top: download, activate, switch on, and let a day's traffic come in. The map view and the reading guide with the four common patterns are on the product page of the heatmap and scrollmap plugin. Torn between this plugin and an external tool like Hotjar or Clarity? That comparison is set out in the heatmap tool comparison. And if you're after the other free plugins, they're in the register of tools and plugins.

Want to know how this plugin fits your site and your wider online strategy? Book a call and we'll look together at where the biggest wins are for you.

Section · Next step24/7 reachable · sales@theseo.nl
Book a call ↗
Written by GianlucaFounder. Building visibility for Dutch businesses since 2017, in Google and in AI answers. More about the institute.