Skip to content

Add Crustat to your website

Copy one line from your dashboard, paste it into the head of every page, and your first visit shows up about a minute later.

Your line

Every site in Crustat has its own tracking line. You’ll find it under Site settings → Install, in the card Your tracking code. When you add a new site, Crustat takes you straight there.

It looks like this:

<script defer src="https://stats.crustat.com/script.js" data-site="YOUR-SITE-ID"></script>

Click Copy the line to copy yours. Don’t copy the example above: the data-site part is what tells Crustat which site a visit belongs to, and yours is different.

Your site ID

The site ID is the 16-character code inside data-site, made of letters, digits, - and _. It’s shown on the same page as Site ID, with a Copy ID button. The WordPress plugin and the Astro and Next.js packages ask for this ID instead of the whole line. It never changes, so you can paste it once and forget about it.

Where to paste it

Put the line in the <head> of every page you want to track. “Head” is the hidden top part of a web page, where scripts and settings go before the visible content.

  • One shared template. If all your pages use the same layout or header file, paste it there once and every page is covered.
  • A site builder. Look for a setting for custom code in the site header. It’s often called “header code”, “custom code”, “code injection” or “tracking codes”. Paste the line there, site-wide.
  • The body works too. If your builder only lets you add code to the page body, that’s fine. Crustat works the same way in either place, the first page view is just sent a moment later.

Add the line once per page. Two copies on the same page would record each view twice.

Using a platform? There are step-by-step guides for WordPress, Shopify, Astro and Next.js. You can also hand the job to an AI coding agent.

Two settings some sites need

  • Cloudflare Rocket Loader, or a plugin that combines or delays scripts. Add data-cfasync="false" to the line, or exclude it from that plugin. The line in your dashboard doesn’t include it, so add it yourself if you need it. See Rocket Loader and script combiners.
  • A Content-Security-Policy. This is a security header some sites send that lists which outside addresses the page may load from. If your site has one, allow https://stats.crustat.com in both script-src (to load the script) and connect-src (to send visits).

Check that it works

  1. Publish the change.
  2. Open your live site in a normal browser window. Not on localhost: Crustat skips local addresses on purpose.
  3. Wait about a minute, then open your site in Crustat.

Until the first visit arrives, your site’s page says Waiting for your first visit. As soon as it lands, your stats take its place. The page checks every 30 seconds, so you don’t need to refresh. (On Site settings → Install, the badge next to your line changes from No visits yet to Working since and the day, too.)

If nothing arrives after a few minutes, work through visits aren’t showing up.

What it doesn’t need

No cookie banner, no consent pop-up before it can record a visit, no extra privacy plugin. Crustat sets no cookies and stores nothing on your visitors’ devices. See do I need a cookie banner for Crustat? and what we collect.

Still stuck? Write to hello@crustat.com.

All articles
The mascot waiting

Almost ready

We're opening to everyone soon.

Crustat is in its final checks before we open sign-ups. Leave your email and we'll write once, the day it opens, with your 14 days free waiting.

One email when we open. No newsletter. See our privacy page.