The tag and its attributes
Everything starts with a tag, pasted into the <head> of every page:
<script defer src="https://stats.example.com/a.js" data-site="s_arvordemo001"></script>/a.js is a script of a few kilobytes, with no dependencies, served by the eodia analytics
API (cached for one hour, with an ETag). Each site’s Installation tab gives the tag with
its key and the collection address (COLLECT_URL) already filled in.
Attributes
Section titled “Attributes”| Attribute | Role |
|---|---|
data-site | the site’s public key, s_ followed by twelve characters. Required |
data-identity | a signed-in visitor: an HS256 JWT signed by your server with the site secret. See the signed-in visitor |
data-spa | address changes without a reload: history (default), hash, or off. See single-page applications |
data-auto="false" | no automatic page view: the page calls EodiaAnalytics.page() itself |
data-preview | allows preview mode: the heatmap drawn on the real page, at the request of eodia insights |
<script defer src="https://stats.example.com/a.js" data-site="s_arvordemo001" data-spa="history" data-identity="eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9…" data-preview></script>What it measures
Section titled “What it measures”- page views, including address changes without a reload; a prerendered page
(
document.prerendering) is counted only once it is displayed; - the referrer and campaign parameters, including
in the fragment (
#utm_source=…); - your events (
EodiaAnalytics.track), see the page API; - the automatic measurements the site has enabled: outbound links, downloads, site search, forms, videos;
- when leaving the page: the engagement time (page displayed in the foreground) and the maximum scroll depth;
- clicks: a stable selector of the clicked element (its
id,data-eodia-zoneordata-testid, otherwise a tag path of at most five levels) and the click position within the element, from 0 to 1, independent of screen size; at most 100 clicks per page; - zones (
data-eodia-zone): their visibility time.
What it never does
Section titled “What it never does”- It never reads an entered value or selected text.
- It sets nothing other than the
_eoameasurement cookie, and only if the server asks it to (site in cookie mode), and the opt-out marker (optOut()), stored inlocalStorage. - It sends nothing if the visitor has opted out (
optOut()), if the browser sends the Global Privacy Control signal, or if it is driven by a bot (navigator.webdriver).
How it sends
Section titled “How it sends”The first page view is sent with fetch (with keepalive) in order to read the response: the
cookie to set and the automatic measurements to start. Subsequent sends use
navigator.sendBeacon, batched by 50 at most. The body is always JSON sent as text/plain: no
CORS preflight request. The collection endpoint checks that the page belongs to the site’s
domains, then returns its origin in Access-Control-Allow-Origin.
Where to put it
Section titled “Where to put it”- In the
<head>, withdefer: it does not delay rendering. - Once per page. A second load is ignored.
- Behind a tag manager: a custom HTML tag containing the same line works.
document.currentScriptmust point to it: no loading througheval.
eodia analytics is free software by Eodia.