Clicky Analytics
Version 1.1.0
September 25, 2026
Critical
If your Sitekey is in a variable named
CLICKY_SITEKEY, Craft has been writing it to your logs. Generate a new Sitekey in Clicky, rename the variable toCLICKY_SITE_KEY, and delete your old logs instorage/logs.
Security
- Craft now masks the Clicky Sitekey in logged request details and the control panel's variable suggestions.
- Errors from Clicky no longer carry the Sitekey.
- The shipped config file refers to the Sitekey by variable, so its value no longer appears on the settings screen.
- Clicky widgets, the Page Stats field and the country drilldown now need the view permission, however the widget was added.
- Test connection only resolves the saved variables or ones named
CLICKY_. - Visitors' IP addresses, hostnames and coordinates are no longer cached.
- Links to referrers and landing pages now open with
noreferrer.
Added
- Give each Craft site its own Clicky Site ID and Sitekey with the
sitesconfig setting. - Dashboard widgets have a Clicky site setting, for reporting on a site with its own Site ID and Sitekey.
craft.clickyAnalytics.pageStats()accepts an entry or a full URL.
Changed
- The "Add Clicky Analytics dashboard widgets" permission is now "View Clicky Analytics data",
clicky-analytics:view-analytics. Existing grants are moved over. - Date ranges now follow your Clicky site's time zone rather than Craft's.
- Calendar months now cover the whole month.
- The Page Stats field defaults to Last 28 days.
- Visitors online is cached for 30 seconds rather than fetched on every page.
- Requests to Clicky time out after 5 seconds, unless
config/guzzle.phpsets a timeout. - After a failed request, calls to Clicky pause for a minute.
- Report widgets are titled with their metric alone.
- Uninstalling the plugin removes its dashboard widgets.
Fixed
- The Page Stats field no longer shows up in GraphQL schemas, where it could only ever return null.
- A wrong Sitekey no longer passes Test connection.
- A Clicky outage no longer breaks front-end pages that use
craft.clickyAnalytics. - The Page Stats field can no longer be made required, which stopped every save.
- The Page Stats field skips unpublished drafts.
- Pages with non-ASCII characters in their URL now match their Clicky stats.
- Two line charts on one dashboard no longer share a colour.
- Line charts in one-column widgets have readable axis labels.
- "1 visitors online now" and "1 views" now read correctly.
- Rows without a drilldown in Top Countries line up with the rest.
- Screen readers now hear which country a drilldown button opens.
- The drilldown's loading and error messages can now be translated.
- Invalid Site IDs, date ranges, colour schemes and Report widget options are now rejected.
- Modules can now add validation rules to the widgets.
- The "Open in Clicky" links now show when they have keyboard focus, not just on hover.
- The visitors chart now has a text version for screen readers.
- The country drilldown toggle now meets the minimum touch target size.
- The live visitors pulse no longer animates when reduced motion is requested.
Version 1.0.2
September 22, 2026
Critical
Security
- Failed Clicky requests no longer write your Sitekey to the logs or show it on screen. If it may have been logged, generate a new one in Clicky.
Fixed
- The noscript setting now says it only applies while tracking code is injected.
- Site IDs and Sitekeys from environment variables are now trimmed.
- Modules can now add validation rules to the plugin settings.
Version 1.0.1
July 8, 2026
Fixed
- The Page Stats field now shows each entry's own figures, not site-wide ones. Clicky keeps per-page data for about 30 days.
Version 1.0.0
July 5, 2026
Added
- 21 dashboard widgets, each with its own date range and row limit.
- A Report widget that draws any metric as a counter, line, bar or pie.
- A Live Visitors widget with a new, returning or both filter.
- A cities and regions drilldown on the Top Countries widget.
- An option to merge browser and OS versions into one row.
- A Page Stats field that shows an entry's own analytics in the editor.
- Self-hosted flags and browser, OS and search engine logos.
- Five colour schemes, a compact density and a slim bar style.
- Optional tracking code injection, skipped in
devModeand previews. - A settings screen with Test connection, and a
config/clicky-analytics.phpconfig file. - "Open in Clicky" links on every ranked row.
- A
craft.clickyAnalyticsTwig variable. - A permission for adding Clicky widgets.
- Response caching with a duration you set.