@mattab opened this Issue on January 15th 2011 Member

Few users are tracking all their websites (hundreds or even thousands) with Piwik. One problem is that all the JS codes have the URL of the Piwik server in it. It is then possible to search in a search engine, or using custom bot, all websites that are use this Piwik instance and guess all websites that belong to one user.

SEE FAQ that explains how to do this

@mattab commented on April 1st 2011 Member

Attachment: piwik.php proxy file to put on each tracked website

@mattab commented on April 1st 2011 Member

I have a beta version going now. See attached file.


0) Make sure your server runs at least PHP 5 as this trick requires PHP5

1) In the attached piwik.php file, put your "secret" piwik URL and your Super user token_auth

The token_auth is required so that the visitor IP can be overwritten (otherwise the IP would be set to the IP of your example.org server doing the request)

2) Upload the piwik.php file in http://example.org/ and all your other websites

3) Then modify the top part of the Piwik JS snippet to the following

    <script type="text/javascript">
    var pkBaseURL = (("https:" == document.location.protocol) ? "https://example.org/" : "http://example.org/");
    document.write(unescape("%3Cscript src='" + pkBaseURL + "piwik.php' type='text/javascript'%3E%3C/script%3E"));
    </script><script type="text/javascript">
    try {
    var piwikTracker = Piwik.getTracker(pkBaseURL + "piwik.php", 1);

Notice the absence of piwik.js, since the attached piwik.php will do a proxy to both the static JS file piwik.js, as well as redirect all tracking requests to the "secret" piwik.php

You will have to update the JS snippet on all your websites to point to the "proxy" piwik.php on this local website, that you just uploaded.

PLease test (I have done very small testing...) and report here. When all is working good, I will put up a FAQ or doc page on piwik.org

@mattab commented on April 4th 2011 Member

any feedback, is it working as expected? I got only one report that it is working so far. thx

@mattab commented on April 26th 2011 Member

Apparently this is working good! I think, that we can put this in core somehow... and document it in a FAQ?

@anonymous-piwik-user commented on April 27th 2011

I followed these directions, but it does not seem to be working...

For the Piwiik JS replacement code, I should replace example.org with the URL of the website I placed the piwik.php script on? Also, the original tracking code has:

<noscript><p><img src="http://myserver.com/piwik/piwik.php?idsite=1" style="border:0" alt="" /></p></noscript>

Can I remove that line since it has the URL of the Piwiki server I am trying to hide.

@anonymous-piwik-user commented on April 28th 2011

Tried on another website and still not working.

@robocoder commented on April 29th 2011 Contributor

In php.ini, you need:

allow_url_fopen = On
@mattab commented on May 1st 2011 Member

SupraTT followed up in the forum and it is working

@anonymous-piwik-user commented on June 5th 2011

Add local cache for .js file.
Why download it for each new user from piwik stats server.

And when there is timeout save visit info to temp file to send later?

@mattab commented on July 26th 2011 Member

(In [5049]) Fixes #2019

  • Added better doc in the script itself
  • added FAQ How to to point to this script
@mattab commented on July 26th 2011 Member
@anonymous-piwik-user commented on April 15th 2013

This is currently broken in 1.11.1 and the upstream GitHub version that was suppose to fix this problem does not solve the issue.

More details can be found in the thread I started initially. http://forum.piwik.org/read.php?2,102949

The errors I am seeing and I saw no change in the amount of errors after changing to the "updated" version

2013/04/13 15:51:54 [error] 2802<a href='/0'>#0</a>: *9 FastCGI sent in stderr: "PHP message: PHP Warning:  sprintf(): Too few arguments in /my/site/piwik.php on line 69" while reading response header from upstream, client:, server: , request: "GET /piwik.php?action_name=My%20Website%20Title!&idsite=978&rec=1&r=371635&h=11&m=51&s=52&url=http%3A%2F%2Fwww.mysite.com%2Fo%2Fgfg%2Fheater%2F1%2F&_id=b0686e49aa174610&_idts=1364004010&_idvc=23&_idn=0&_refts=1365868313&_viewts=1365860923&_ref=http%3A%2F%2Ffleshbot.com%2F&cookie=1&res=1280x800 HTTP/1.1", upstream: "fastcgi://", host: "mywebsite.com", referrer: "http://www.mywebsite.com/w/gfg/heater/1/"

All the errors currently are all very similar to the one listed above

Thanks and hopefully this is something that is an easy fix, I can post anything else you guys need for this as well.

@mattab commented on April 16th 2013 Member

In 37c6494c6ab1b015dc3d27373200d38b44c5da29: Fixes #2019 thanks for the report, fixing the regression

@anonymous-piwik-user commented on April 16th 2013

It got rid of the error but tracking goals is still hit and miss, it only triggered 5 times when I hit the goal 40 times. So there is still something going on I feel. Not sure where to look for info as to whats keeping the goals from triggering now.


@anonymous-piwik-user commented on April 16th 2013

Here was some errors that started up a little bit after trying new github version

2013/04/16 21:13:43 [error] 8125<a href='/0'>#0</a>: *426 FastCGI sent in stderr: "PHP message: PHP Warning:  file_get_contents(http://my.intermal.i.p/piwik.php?cip=end.user.i.p&token_auth=1234dc5cxdff61e70e76d7b8deb9cef65&action_name=My+Site+Title%21&idsite=1056&rec=1&r=878845&h=2&m=12&s=33&url=http%3A%2F%2Fwww.mysite.com%2F&_id=a42d0858ed9c82ea&_idts=1366146814&_idvc=1&_idn=1&_refts=0&_viewts=1366146814&pdf=1&qt=0&realp=0&wma=0&dir=0&fla=1&java=0&gears=0&ag=0&cookie=1&res=1024x768&): failed to open stream: HTTP request failed!  in /my/site/location/piwik.php on line 73" while reading response header from upstream, client: end.user.i.p, server: , request: "GET /piwik.php?action_name=My%20Site%20Title&idsite=1056&rec=1&r=878845&h=2&m=12&s=33&url=http%3A%2F%2Fwww.mysite.com%2F&_id=a42d0858ed9c82ea&_idts=1366146814&_idvc=1&_idn=1&_refts=0&_viewts=1366146814&pdf=1&qt=0&realp=0&wma=0&dir=0&fla=1&java=0&gears=0&ag=0&cookie=1&res=1024x768 HTTP/1.1", upstream: "fastcgi://", host: "mysite.com", referrer: "http://www.mysite.com/"


@mattab commented on April 16th 2013 Member

please ask in the forums with the bug description and steps to reproduce.

Note: make sure you wait 1-2 seconds before each goal conversion (max 1 per second)

@anonymous-piwik-user commented on April 17th 2013

its already in the forums

@mattab commented on April 17th 2013 Member

For your error, I have a feeling it may be caused by mod_security, make sure it's disabled and it might work. Otherwise see suggestions in the forum thread

@206siva commented on September 27th 2018

where to place the piwik tracking code in php websites.

This Issue was closed on April 17th 2013
Powered by GitHub Issue Mirror