How We Count Visits
Exactly what counts toward your monthly visit allowance, what doesn't, worked examples, and why our number differs from Google Analytics.
Every hosting plan includes a monthly visit allowance. This is exactly how we count it, so you can check any number we show you. The plain-English explanation comes first. The exact rules, for developers, are at the end, along with a glossary of the technical terms.
The short version
- A visit is one internet address on one day, however many pages it opens.
- Search engines and bots that say who they are never count. Neither do images, login attacks or errors on our side.
- Your monthly total is every day's visitors added together, across the live sites on that plan.
Is it a visit?
Every request to your site goes through the same four questions, in this order. It becomes a visit only if the answer to all four is yes.
- Did it reach our servers? Anything answered somewhere else first, such as a CDN cache you've set up yourself, never reaches us and isn't counted.
- Did your site answer it? Your site has to have built the page, or handed back a copy it built earlier. Images and other files we send back directly, requests we turned away, and errors on our side don't count.
- Is it a person, or something that looks like one? Search engines and other bots that say who they are don't count.
- Is this the first time we've seen that address today? If it is, that's a visit. Anything else it does that day is part of the same visit.
How a visit is counted
We count from the records our own servers keep of every request your site answers. The day runs from midnight to midnight UTC.
Some examples:
| What happened | Visits |
|---|---|
| A reader opens five posts this morning | 1 |
| The same reader comes back tomorrow | 1 more |
| Someone reads on their office wifi, then on their phone's mobile data | 2, because those are two different addresses |
| Ten people in one office share an internet connection and all read your site | 1, because they share one address |
| You log in to WordPress and edit posts for an hour | 1 for that day |
| A bot hiding behind an ordinary browser opens one page | 1 |
| Googlebot crawls 3,000 pages | 0 |
| An email security service checks the link to your new post from 2,000 addresses without opening it | 0 |
What counts
| Counts | Examples |
|---|---|
| Opening anything your site builds | Pages, posts, search results, category and tag pages, a 404 "page not found" your site shows |
| Reading your feeds and data | RSS feeds, and the WordPress API that apps and other sites read your posts through |
| Things your site does while someone is on it | Contact forms, comments, carts and checkout, live search, background updates in the WordPress editor |
| Your own work in WordPress | Editing posts and pages, changing settings |
| Automated traffic that presents itself as a normal browser | Scrapers and bots that hide what they are. Nothing in our records tells them apart from a person, and your site does the same work to serve them |
What doesn't count
| Doesn't count | Why |
|---|---|
| Search engines and bots that identify themselves | Google, Bing, Apple, DuckDuckGo, AI crawlers like GPTBot and ClaudeBot, SEO tools like Ahrefs and Semrush, ad-network checkers, social media link previews, uptime monitors |
| Anything that asks for robots.txt | Only automated tools ask for it, so that address isn't counted at all that day, whatever it claims to be |
| Link checks that don't open the page | Email security services and link checkers ask whether a page exists without reading it, often from thousands of addresses at once when a newsletter goes out |
| Images, stylesheets, scripts, fonts, videos and PDFs | They come with a page someone already opened |
| Requests turned away | Blocked or rate-limited addresses, and pages that need a login the visitor didn't have |
| Errors on our side | If your site fails to answer, that's on us |
| The WordPress login page and xmlrpc.php | Attacks hammer these from thousands of addresses, and none of them would be a reader |
| Your site's scheduled tasks and our monitoring | That's your site and our servers talking to themselves |
| Redirects our servers give on their own | Sending someone from http to https, or to your www address. The page they land on is what counts |
| Anything answered before it reaches our servers | For example a page served from a CDN cache you've set up yourself |
| Staging copies | Only live sites on your plan count |
Where to see your visits
The Websites page lists each site under its plan with its visits so far this month, and the plan's total against its allowance. The numbers update every few minutes.
If you have more than one plan, each plan has its own allowance and visits don't pool between them. See Understanding Your Plan and Usage Limits.
Why our number is higher than Google Analytics
Google Analytics and similar tools only count browsers that run their tracking script and, in many places, agree to the cookie banner. They miss:
- visitors using ad blockers or privacy browsers, which block the script
- visitors who decline cookies
- feed readers, apps and other tools that read your site without running scripts
- automated traffic, most of which never runs the script
We count every visitor your site serves, so our number is usually higher. Google Analytics is the better tool for understanding your readers. Ours is what your site actually had to answer.
Automated traffic
Bots that announce themselves never count toward your visits, however many pages they read. Bots that pretend to be a normal browser do count, because your site serves them exactly like a person.
We automatically block addresses that keep trying to log in to your site and other known attack patterns, and those requests don't count either.
Bot protection, on your website's page, turns away SEO tools and AI training crawlers. That keeps your site fast for real visitors, but it won't lower your visit count, since those bots already identify themselves and are never counted.
If you go over
Nothing is shut off or slowed down. Visits over your allowance are billed as overage after the month ends. Understanding Your Plan and Usage Limits has the prices and how they're charged.
If you're over most months, an add-on block usually costs less than overage. Add-On Blocks: Expand Your Plan Limits and Save helps you work out which is cheaper for you.
Exact rules, for developers
Visits are counted from the web server's access log on the server your site runs on, read every five minutes. A visit is a unique client IP address per UTC day, after the filters below. The monthly figure is the sum of the daily figures, so one address on 30 days is 30 visits.
A request makes its address a visit for the day only if all of these hold:
| Rule | Detail |
|---|---|
| Client address | The real client IP, recovered from Cloudflare's headers when the site is behind Cloudflare. The server's own addresses never count |
| Answered by WordPress | PHP built the response, or the page cache returned one PHP built earlier (cache status HIT, STALE, UPDATING or REVALIDATED). Static files the web server returns itself never reach PHP and never count |
| Method | Any method except HEAD and OPTIONS |
| Status code | Not 401, 403, 429, 444, 451 or 499, and not any 5xx. 2xx, 3xx and other 4xx responses count, including a 404 WordPress rendered |
| Path | Not /wp-login.php, /xmlrpc.php or /wp-cron.php |
| User agent | Present, and not a self-declared automated client. That means any user agent containing words like bot, crawl, spider, scrape, fetcher or monitor, plus named tools that don't use those words, such as curl, python-requests, Go-http-client, ad verification services, ads.txt checkers and vulnerability scanners |
| robots.txt | The address didn't request /robots.txt that UTC day. If it did, none of its requests that day count |
Plan usage is the sum across every live, non-deleted site attached to the plan. Staging copies aren't attached to a plan.
Glossary
Internet address (IP address). The number that identifies the network a request came from. A home or office connection usually has one, shared by everyone on it. A phone on mobile data has a different one.
Bot. Software that requests pages automatically, such as a search engine indexing your site or a tool copying it.
User agent. A short line of text every request carries saying what sent it, such as a particular browser or "Googlebot". Honest bots name themselves here. Dishonest ones copy a browser's.
UTC. Coordinated Universal Time, the time zone our day boundary uses. Midnight UTC is 8pm Eastern or 5pm Pacific during daylight saving time, and 7pm or 4pm in winter.
Page cache. A ready-made copy of a page your site keeps so it doesn't have to build it from scratch for every visitor. A page served from it still counts as a visit.
CDN. A content delivery network, a service that keeps copies of your pages on servers around the world. A request it answers from its own copy never reaches us.