SMF·LUCKY-ORANGE
Can a prompt replace Lucky Orange?
Analytics — web and product analytics
Exhibit tracking slip
Verdict
A click and scroll heatmap for one site is a weekend of work: collect coordinates, bucket them, draw them over a screenshot. The catch is that heatmaps are the cheap quarter of the product. Session replay needs a DOM-recording pipeline and storage that grows fast, and doing it without leaking passwords, card numbers and customer names into your own logs is a privacy engineering problem, not a rendering one. That part is not a weekend.
Exhibit A — The prompt
Received on31.07.2026Build a self-hosted click and scroll heatmap for a site you own.
Two parts.
Collector: a small JavaScript file (target under 5 KB, no dependencies) served from the same origin as the site. On each page it records click events as a CSS selector path plus a percentage offset within that element's bounding box, never as raw viewport pixels, so the data stays valid when the layout reflows on a different screen size. It also records the deepest scroll position reached, as a percentage of document height, sampled on unload. It sends a single batched beacon per page view. It records nothing at all until a consent flag is set by the host page, and it never reads input values, text content, or the clipboard.
Dashboard: a small server that ingests those beacons, stores them in PostgreSQL keyed by page path plus device bucket (mobile / tablet / desktop), and renders two overlays on a screenshot of the page the user uploads or that a headless browser captures: a click density map, and a horizontal line marking where each decile of visitors stopped scrolling. Filter by date range and device bucket. Show the raw per-selector click counts in a table underneath, because the table is what you act on and the picture is what you show other people.
Strip IP addresses to a country code at ingest and discard the rest. Do not set a cookie; count sessions with a rotating daily salt hashed against the user agent.
Out of scope, and say so plainly in the README: session replay and any form of DOM recording, live chat, surveys, and funnels. A replay pipeline that has not been audited for what it captures is a data breach waiting to happen, and it is not something to add casually to a personal build.
Opening prefills the prompt — press enter to run it.
Exhibit B — What you lose
- B.1 session replay of what a visitor actually did
- B.2 automatic redaction of passwords, card fields and personal data
- B.3 the live chat widget and on-site surveys
- B.4 conversion funnels and form-abandonment analysis
Prior art
Exhibit C — Why people still pay: data pipeline reliability and analytical depth
Because the recordings are what convince people. Watching a real visitor fail to find the checkout button ends an argument that a heatmap only starts, and nobody wants to be the one storing that footage.
Questions
Can I bring my Lucky Orange history across?
No, and not because of the export format. Lucky Orange's heatmaps are aggregates computed over recordings it holds; there is no per-click export to import. You start collecting from zero on the day you install this.
Will the heatmaps look the same as Lucky Orange's?
Broadly, on desktop. Where they will differ is on pages with dynamic content: because this build anchors clicks to element selectors instead of pixels, a carousel or a personalised block produces cleaner data than pixel maps do, but a page that changes its markup between deploys will split its history across two selectors.
What does it cost to run?
A small VPS and a PostgreSQL database, so on the order of five to ten dollars a month at low traffic. Click data is tiny. The cost only becomes interesting if you later add replay, which is exactly where hosted pricing comes from.
What is the one thing you genuinely cannot rebuild here?
Watching the session. Replay is the feature people buy this category for, and doing it responsibly means masking every input, every data attribute and every third-party iframe by default, then storing the result somewhere it cannot leak. That is a compliance job, not a coding job, and it is why this entry is a no.
Related tools
Receipt