Frequently asked questions

The capture and the data

How does the capture work without a browser extension?

The plugin draws the chosen section into an image, directly in the visitor’s browser, from the content of the page and the styles applied to it. It is not a pixel-perfect screenshot: a font or an image hosted on another domain that forbids cross-origin access may be missing. The report always carries the URL of the page, the CSS selector and the position of the section, so that you find the element again even if the image is incomplete.

What exactly does a capture contain?

A capture reproduces the page as it is displayed, form fields included: what a visitor typed into a field is part of the image. Glitchpin, in its free version, offers no way to mask part of a capture, neither automatically nor by hand. Automatic masking of passwords, card numbers and one-time codes, the data-octoscope-private and data-octoscope-ignore markers, the "mask every form field" option and manual black-out in the annotation editor are features of Glitchpin Pro. If your pages display personal data, take that into account before enabling the widget there.

What is stored about a visitor?

For every report: the URL and the title of the page, the context of your own site (WordPress version, environment, theme, PHP version), and that of the browser: name and major version, operating system, device type, screen size, pixel density, orientation, language, time zone, scroll position, and the referrer only when it comes from your site. No digital fingerprint is computed: no canvas, no font list, no plugin list, no hardware probing. The IP address is never stored in clear text: only a salted hash is kept, in order to apply the rate limit. An email address is stored only if the visitor entered one in order to be notified of the fix.

A public, anonymous form, isn’t that an invitation to spam?

The entry point is protected by a signed, time-limited token, a bot trap, a minimum delay before sending, a limit of 5 reports per IP address every 10 minutes and an overall cap of 200 reports per day. Captures are bounded in number, in weight and in resolution, and a report about a site other than yours is refused. All of that without imposing a captcha on the visitor.

Is it compatible with a page cache?

Yes. The anti-spam token is fetched when the visitor opens the widget, and not when the page loads: a page served from the cache is therefore no problem at all.

Is it compatible with my theme and my page builder?

The capture is produced from the real content of the page and the styles applied to it: it does not depend on any particular theme or builder. Two honest caveats: it is not a pixel-perfect screenshot, and a font or an image hosted on another domain that forbids cross-origin access may be missing from the image. In every case, the CSS selector and the position of the section make it possible to find the element again. The visitor widget is written in native JavaScript and CSS, with no dependency on a framework.

Glitchpin Pro and the licence

How does the Glitchpin Pro licence work?

Glitchpin Pro is sold outside the WordPress directory and its licence is handled by Freemius. It covers 1 site. Development and staging sites are not counted: the list of recognised domains is the Freemius one. You can release a site at any time and reuse its licence elsewhere.

What happens if I deactivate Pro, or if my licence expires?

Pro features stop, but nothing is deleted: tickets, occurrences, history, internal notes and settings remain in your database, and the free plugin keeps showing the reports. A ticket left in a Pro status is then displayed as "Pro · To do", "Pro · In progress" or "Pro · To review", is still counted under the "New" view, and can still be moved to "Done" or sent to the trash. Reactivate Pro and everything comes back.

Where do the updates come from?

Glitchpin updates will come from WordPress.org once the plugin is published, like any plugin in the directory. Glitchpin Pro updates are served by Freemius, through your licence. The two channels are independent and never interfere.

Installation and compliance

How do I answer a GDPR request?

With the native tools of WordPress. In Tools → Export Personal Data, a request concerning an email address returns every report where that address was given: the report, its date, the page, the description, the address, the notification request and the confirmation state. An address that was never confirmed is exported too, marked "Not confirmed". In Tools → Erase Personal Data, the same reports are anonymised: the address and the notification request disappear, the report stays. Glitchpin also offers a text for your privacy policy: it is in the WordPress Privacy Policy Guide, which the Glitchpin → Settings → Privacy & retention tab links to.

Does it work on a multisite?

Yes. Each site in the network has its own reports, its own settings and its own storage folder. Uninstalling cleans up every site in the network. Multisite is supported, but it has been less widely tested than ordinary installations. On the Pro licence side, each subsite counts as one activation.

And what if my host does not have the GD library?

Without GD, the plugin refuses image captures rather than storing files it cannot re-encode. The widget then falls back to a text mode: the visitor describes the problem in a field, and the report still carries the URL of the page, the viewport size and the browser. A warning is displayed on the plugin’s admin screens as long as GD is not enabled.

What is left if I uninstall the plugin?

Nothing. Uninstalling Glitchpin deletes everything: reports, captures, settings, per-user preferences and scheduled tasks. Deleting Glitchpin Pro on its own removes only its own options and its licence data: the reports, their history and the free plugin’s settings belong to Glitchpin and stay intact.

Coming soon to WordPress.org

One button, one capture, one useful report. That is all it took.

What you are interested in

A confirmation email, then one message on launch day. Unsubscribe in one click.

Thank you, your address is saved.

This address is already on the list.

Your sign-up could not be saved. Try again in a moment.