If you run a WordPress site and you are looking for a Google Analytics alternative, the real question is usually not "which dashboard looks nicest". It is how the tool identifies visitors, where the data lives, and how much work it is to keep working through caching and optimisation plugins. This article covers all three, and ends with an installation you can follow step by step.
Quick answer
Cookieless analytics for WordPress means a tracker that does not set cookies to recognise visitors, so it adds no analytics cookie to your site. You do not need a dedicated plugin: Atriqo is not a WordPress plugin, and you add one script tag to the site's <head> through a header plugin such as WPCode. We tested that route on WordPress 7.1.3 with the WPCode free plugin (v2.4.0) and the pageview reached Atriqo. If a new install shows nothing, check these first: a page cache serving old HTML, a plugin that rewrites or proxies scripts, and testing in a browser with Do Not Track enabled. Whether your site needs a consent banner depends on your whole stack and your data protection authority's guidance, not on the analytics tool alone.
Key takeaways
- Two kinds of tools are sold to WordPress owners: self-hosted analytics plugins that store data in your WordPress database, and hosted services where you add a script tag. They have different trade-offs in maintenance, database load and hosting location.
- Atriqo is a hosted service, hosted in the EU, with a tracker that sets no cookies. Installation is one script tag through a header plugin.
- Only add the tracker one way. Do not also add it through your theme or Google Tag Manager.
- After installing, clear every cache layer and check the page source as a logged-out visitor.
- Cache, script-optimisation and consent plugins can change what visitors load. Check the first event instead of assuming.
- The free plan covers 10,000 billable events per month, with no credit card and no expiry.
Definitions
Cookieless analytics: analytics that does not set cookies. The term says nothing on its own about other identifiers (local storage, fingerprinting), so check what each tool does. Atriqo's tracker writes nothing to the browser and does not fingerprint; the visitor identifier is a hash computed on the server from the IP address, user agent and a salt that rotates daily. The IP address is discarded after that privacy hash. See how identification works.
Billable event: the quota unit, not "pageviews". It covers pageviews, outbound clicks, file downloads, 404 events (opt-in, off by default) and custom events; the internal page-exit signal does not count.
GDPR-native by design: a positioning statement about how the product was designed. It is not a certification, and it does not make your WordPress site compliant on its own.
What "cookieless" means on a WordPress site
Atriqo is a privacy-first, cookieless web analytics tool, hosted in the EU (Germany), built as a GDPR-native-by-design alternative to Google Analytics.
In concrete terms, for a WordPress site this means:
- Atriqo's tracker sets no cookies.
- There is no cross-site tracking: each site is a silo.
- There is no fingerprinting.
- The IP address is discarded after the privacy hash is computed.
One precision matters for the consent conversation. The tracker does read one key from the browser's local storage (atriqo_opt_out) so that a visitor can opt out. Under Article 5(3) of the ePrivacy Directive, the rules apply to storing information on, or accessing information from, a user's device (Directive 2002/58/EC). So "no cookies" is accurate, but "touches nothing on the device" would not be. Whether a given site needs consent for its analytics depends on its full stack and on the guidance of its own data protection authority. This article does not answer that for you.
Your WordPress stack has other parts too: forms, embeds, fonts, ad pixels, a comments system. Switching the analytics layer does not change what those do.
Choosing a Google Analytics alternative for WordPress
When you compare options, these are the questions that matter for a WordPress site.
Where does the data live? Self-hosted analytics plugins store their data in your WordPress database and run on your hosting. That keeps the data on your own server; the plugin runs on your hosting and you keep it updated. Hosted services keep the data off your WordPress server. Atriqo is hosted in the EU, with analytics infrastructure in Germany (Hetzner Falkenstein).
How is the visitor identified? Ask whether the tool sets cookies, and what it reads from the device. A tool that sets no cookies leaves one fewer item in your cookie inventory.
What do you give up compared with GA4? Atriqo does not follow an individual across days, and it has no native Google Ads or Search Console connection. The GA4 migration guide covers the metric differences in detail.
How is it priced? Atriqo's free plan includes 10,000 billable events per month, with no credit card and no expiry. Paid plans start at €4/month for 100,000 billable events. You can evaluate it with real traffic on the free plan.
If you want the background on why teams look for a Google Analytics alternative in the first place, see Google Analytics, GDPR and the DPF. For the general concept, see the cookieless analytics guide.
How to install privacy-friendly analytics on WordPress
The canonical, kept-up-to-date steps live in the WordPress installation reference. What follows is the same procedure with the detail we saw while testing it.
What we tested: WordPress 7.1.3 in a local Docker setup, the Twenty Twenty-Five theme, and WPCode – Insert Headers and Footers (free, v2.4.0), on 2026-10-09.
Step 1: Add your site in Atriqo
Create a free account and add your site. On the site's installation screen, copy the snippet. It looks like this, where SITE_ID is your own site identifier:
<script src="https://api.atriqo.com/track.js" data-site="SITE_ID" async></script>
Also confirm that the hostname your visitors use is registered for the site in Atriqo (see the installation checks). Events from an unregistered hostname are not accepted.
Step 2: Paste it with a header plugin
In the WordPress admin:
- Install and activate WPCode (Insert Headers and Footers).
- Open Code Snippets, then Header & Footer.
- Paste the snippet into the Header box. The screen says these scripts are printed in the
<head>section. - Replace
SITE_IDwith your identifier and click Save Changes.
In our test, the tag then appeared verbatim in the <head> of public pages for logged-out visitors, the browser loaded track.js, and the pageview was sent to https://api.atriqo.com/api/event.
Why a header plugin and not a theme edit? Block themes such as Twenty Twenty-Five have no header.php, so a header plugin avoids touching theme files at all. Editing theme files is not needed, and theme updates can overwrite edits made there. Do not edit header.php.
Use one installation path. Do not also add the same tracker through your theme or Google Tag Manager.
Step 3: Clear caches and check the page source
Page caches keep serving the old HTML until they are cleared. We tested WP Super Cache 3.1.4 with caching on. Saving through WPCode's Header & Footer screen shows the reminder "Please don't forget to clear the site cache if you are using a cache plugin", and in our test the cached page was regenerated after saving. If you change the header some other way, or if your cache sits at the host or a CDN, clear it manually.
The practical advice: after installing, clear every cache layer, then open the site in a private window and view the page source. Look for the Atriqo script tag in the <head>.
Step 4: Confirm the first event
Visit your published site on its registered hostname, then open the site's installation screen in Atriqo to check for the first event. Do not test on localhost. If nothing appears, work through the getting started checks.
Cache and optimisation plugins: what we tested
Optimisation plugins can rewrite how scripts load, so we tested one.
Autoptimize 3.1.16. With "Optimize JavaScript Code" and "Aggregate JS-files" enabled (also with "Also aggregate inline JS"), the external Atriqo tag was left untouched and not aggregated. With "Do not aggregate but defer", it rewrote async to defer and kept data-site; the tracker still loaded and sent the pageview.
Two things we did not test, so we cannot tell you what they do:
- Delay-JavaScript features in other optimisation plugins, such as "load JS on user interaction". They may delay or prevent pageviews from visitors who never interact with the page.
- Consent or cookie-banner plugins that hold scripts back until the visitor accepts. If one holds back the Atriqo tag, visits are only counted after acceptance. How to classify the tag is the site owner's decision, informed by their data protection authority's guidance.
If you visit your site and see nothing
Work through these in order.
- The tag is not in the source. Check the page source in a private window. If it is missing, a cache is probably serving old HTML. Clear every layer.
data-siteis missing or wrong. The tracker reads its configuration from its own script tag'sdata-siteattribute. Without it, it does nothing.- Your own browser is blocking the send. The tracker sends nothing when Do Not Track is enabled, on localhost or 127.0.0.1, or when the opt-out key is set. Test from a browser without Do Not Track, on the real hostname.
- The script was moved to your own domain. The tracker sends events to the origin it was loaded from. So a plugin that copies or proxies third-party scripts onto your domain would send events to your domain, where they are lost. Keep the
srcpointing athttps://api.atriqo.com/track.js. This comes from reading the tracker's code; we did not reproduce it with a specific plugin. - The hostname is not registered. Events are only accepted from the site's registered hostnames; see the installation checks.
Facts vs interpretation
Facts we verified: the install route, cache behaviour and Autoptimize results above were tested on 2026-10-09 on WordPress 7.1.3 with the named plugin versions. The tracker behaviours in the troubleshooting list come from the tracker's source code. Atriqo's tracker sets no cookies and reads one local-storage key for the opt-out.
Our interpretation: that a hosted, cookieless tool suits most WordPress sites better than a self-hosted plugin is Atriqo's commercial position. Self-hosted plugins keep data in your own database, which some teams prefer. Plugins and hosting setups vary, so test your own site.
Atriqo does not make your site compliant. Its tracker is designed to avoid cookies, fingerprinting, stored IP addresses and cross-site tracking; the full picture depends on every vendor and embed on your site.
Getting started with Atriqo
The free plan includes 10,000 billable events per month (billable events are pageviews, outbound clicks, file downloads, 404 events if you enable them, and custom events), with no credit card and no expiry. Installation is the one script tag described above.
This article describes how to install and test cookieless analytics on WordPress. It does not constitute legal advice. For guidance on consent and your site's vendor stack, consult a qualified legal professional familiar with EU data protection law.