August offer$29/yrfor one siteSave $10Ends Aug 31

Release history

SlimStat ships from the WordPress plugin directory, where the current version is 5.5.0, released June 24, 2026. Every release since the VeronaLabs handover is below, newest first. Security fixes are named rather than folded into "various improvements", because a plugin that logs your visitors owes you that.

Updating takes one click from Plugins in your WordPress admin. The complete version-by-version record, including patch releases not listed here, is published on wordpress.org .

  1. 5.5.0

    Goals and funnels, and a stored-XSS fix for Cloudflare geolocation.

    • Goals: track a signup, a checkout or a key pageview, with unique visitors, total conversions and conversion rate, calculated back over the full visit history.
    • Funnels: chain two to five steps and see where visitors drop out, with ready-made templates for WooCommerce checkout and signups. Funnels are a Pro feature; one goal is free.
    • Security: a crafted CF-IPCountry header could be stored as a visitor country and run script when an administrator opened a report. Country codes are now validated to two letters before storage and escaped everywhere they render. Reported via WPScan.
    • Google Discover and other android-app:// referrers are recorded again, instead of being dropped as "direct" since 5.4.0.
    • The "is empty" and "is not empty" report filters work again, and survive pagination and date changes.
  2. 5.4.0

    Real-time moved into the admin bar, and consent was rebuilt around external CMPs.

    • Live site stats in the WordPress admin bar: online visitors, pageviews and top pages, with a per-minute chart for the last 30 minutes.
    • Consent architecture rebuilt: SlimStat now integrates with Consent Management Platforms through the WP Consent API rather than running its own competing banner logic, with a GDPR Compliance Mode toggle.
    • Salted-hash IP addresses with daily salt rotation, and conditional fingerprint storage that only collects when PII is allowed.
    • Geolocation refactored across all three providers — DB-IP as the default, MaxMind with a free licence key, and Cloudflare headers.
    • Default data retention set to 420 days, which is 14 months.
    • Breaking for add-on developers: legacy internal REST and tracker APIs changed.
  3. 5.3.0

    Redesigned charts, and a tracking method that survives ad blockers.

    • Tracking Request Method setting: REST API, Admin-AJAX, or an Ad-Blocker Bypass transport for visits that would otherwise never reach the server.
    • Line charts redesigned, with hourly, daily, weekly, monthly and yearly granularities and totals printed above the graph.
    • Three more date ranges: last two weeks, previous month, this month.
    • Compatibility with the WordPress Interactivity API.
  4. 5.2.11

    A dashboard readable at a glance, and WordPress 6.8 support.

    • Country flags and language tags in the access log, so a row identifies its visitor without being decoded.
    • Every deprecated hook replaced for WordPress 6.8, multilingual sites included.
    • Hardened input checks, leaner SQL on heavy reports, and flatter memory use during traffic spikes.
    • Fixes: notes filters, email reports with unusual metadata, and the date picker freezing on same-day ranges.
  5. 5.2

    MaxMind geolocation without a licence key.

    • GeoIP data can be loaded from jsDelivr, so geolocation works without registering for a MaxMind licence.
    • Fixed the reset-to-factory-settings bug.
    • Fixed a deprecation warning by setting the referrer before parsing the URL.
    • Vendor libraries autoloaded and cleaned up.
  6. 5.1

    The first release after the VeronaLabs acquisition: a rebuilt interface, and the add-ons back as Pro.

    • Interface redesigned, with a softer palette and a clearer report layout.
    • The legacy add-ons returned, collected into a single product called SlimStat Pro. Anyone who had bought an individual add-on received Pro free for a year.
    • PHP 8.2 compatibility, and IP anonymisation moved onto WordPress core’s own wp_privacy_anonymize_ip().

Reporting a security issue

Security reports go to the maintainers through the plugin's GitHub security page , and confirmed issues are named in the release that fixes them, as 5.5.0 does above.

SlimStat Pro — one site $29/yr, $10 off