Automattic

Automattic

Automated WordPress.com hosting platform and parent company of brands including WooCommerce, Jetpack, and Tumblr. The Jetpack script (widely used on self-hosted WordPress sites) adds site statistics, related posts, and security features. Also loads sharing buttons and embeds that may set tracking cookies.

Overview

Automattic is the company behind WordPress.com, WooCommerce, Jetpack, Tumblr, Akismet, and Day One. Its most significant presence on third-party websites is through Jetpack, a plugin installed on tens of millions of self-hosted WordPress sites that bundles analytics, security, performance, and content features into a single package.

What This Script Does

Jetpack's behavior varies by which modules are enabled. Each module has distinct tracking, data collection, and cookie behavior.

Jetpack Site Stats Module

  • A 1x1 tracking pixel loaded from pixel.wp.com fires on every page view.
  • The pixel passes: blog ID, page URL, referrer, and a visitor hash derived from IP and user agent.
  • Data is processed on WordPress.com servers and displayed in the Jetpack stats dashboard.
  • Sets tk_or cookie — Tracks whether the visitor is a referral from WordPress.com. Persists for 1 year.
  • Sets tk_ai cookie — Anonymized visitor identifier used for unique visitor counting. Persists for 6 months.

Jetpack Related Posts

  • Script: jetpack.js loaded from c0.wp.com CDN.
  • Makes an API call to public-api.wordpress.com/rest/v1/sites/{id}/posts/{id}/related/ to fetch related post recommendations.
  • No additional cookies set beyond site stats.

Social Sharing and Embeds

  • When social sharing buttons are enabled, Jetpack loads social platform scripts (Twitter/X, Facebook, LinkedIn) which set their own third-party cookies.
  • WordPress embeds (oEmbed) load content from external WordPress.com posts, which may set third-party cookies.

Jetpack Security Module (Protect)

  • Monitors failed login attempts and blocks suspicious IP ranges.
  • API calls to api.akismet.com for spam detection on comments.
  • No client-side cookies set by the security module.

Akismet (Comment Spam)

  • Akismet collects comment content and submits it to rest.akismet.com for spam classification.
  • Comment content, IP, email, and user agent are sent with each classification request.

WooCommerce Scripts

  • woocommerce.js manages cart state, checkout flows, and product page interactions.
  • Sets woocommerce_cart_hash, woocommerce_items_in_cart — Session cookies for cart state. Expire on browser close or session end.
  • Sets wp_woocommerce_session_* — Session data cookie. Expires in 2 days.

Domains Contacted

  • pixel.wp.com — Stats tracking pixel
  • c0.wp.com, s0.wp.com, s1.wp.com, s2.wp.com — WordPress.com CDNs
  • public-api.wordpress.com — Related posts API
  • api.akismet.com, rest.akismet.com — Spam filtering
  • jetpack.wordpress.com — Jetpack activation and licensing

Consent & Compliance

Consent category: Analytics / Functional (split by module)

  • GDPR/ePrivacy: The Jetpack Stats pixel and visitor tracking cookies (tk_or, tk_ai) require consent under ePrivacy as they track user behavior. Social sharing buttons that load third-party scripts (Facebook, Twitter) require consent for those platforms' cookies. Security and spam filtering modules can operate under legitimate interest. WooCommerce session cookies are strictly necessary for e-commerce functionality.
  • CCPA/CPRA: Visitor tracking via stats pixel and visitor ID cookies constitutes collection of personal information. Social embed tracking represents data sharing with social platforms.
  • Automattic Privacy Policy: Automattic is a US company headquartered in San Francisco. It participates in the EU-US Data Privacy Framework and offers SCCs. Automattic's GDPR commitments are documented in their privacy policy and DPA.

Should You Block This Without Consent?

Conditional. Jetpack's security modules (Protect, Akismet) can load without consent as they serve legitimate security interests. The stats module and social sharing scripts should be blocked until analytics consent is granted. WooCommerce session cookies are strictly necessary for e-commerce and exempt from consent. Configure Jetpack to disable the stats module server-side until consent is obtained.

Is Automattic GDPR compliant?

Automattic typically loads analytics and functional trackers, which are not strictly necessary for your site to work. Under the GDPR and the ePrivacy Directive, non-essential cookies and trackers must stay blocked until a visitor gives clear opt-in consent. So Automattic can be fully GDPR compliant, but only if your site holds its scripts until consent is granted and lets visitors decline just as easily. Compliance depends on how your site loads Automattic, not on Automattic itself.

Visit website

Consent Categories

Also Known As

JetpackWordPress.comWooCommerceAkismetAutomatticJetpack statsWordPress tracking

Industries

Computers Electronics and TechnologyProgramming and Developer Software

Tracked Domains (3)

Automattic's trackers are common, seen on about 3% of the sites ConsentStack has scanned. Scan your own site to see which of these are firing before consent.

wp.comAnalytics

wp.com is an analytics domain operated by Automattic, used to measure visits, sessions, and on-site behavior. Seen on about 3% of scanned sites.

gravatar.comEssential

gravatar.com is an essential domain operated by Automattic, used to keep the site working, including security, load balancing, and sessions. Seen on about 2% of scanned sites.

wordpress.comEssential

wordpress.com is an essential domain operated by Automattic, used to keep the site working, including security, load balancing, and sessions. Seen on under 1% of scanned sites.

Cookies Automattic Sets (4)

wordpress_test_cookie

WordPress test-cookie probe. Set on every visit to verify the browser accepts cookies before the platform attempts to set login or commenter state. Required for the site login flow to work.

wordpress_logged_in_

WordPress logged-in authentication cookie. Identifies the signed-in user during the wp-admin and front-end logged-in sessions. The hash suffix encodes the site auth secret.

wp-settings-Functional

WordPress wp-admin dashboard preferences (toolbar position, editor mode, color scheme). Stored per user; the suffix encodes the WordPress user ID. Only set in the logged-in admin context.

comment_author_Functional

WordPress commenter convenience cookie. Stores the commenter name, email, and URL after submitting a comment so the fields pre-populate on the next visit. Suffix encodes the site auth hash.

Frequently Asked Questions

Related Vendors

Bombora
Bombora
Intent data and audience building platform that identifies companies researching relevant topics online. Bombora's Company Surge data is surfaced to B2B marketers via scripts that fire on publisher sites within the Bombora data co-op, collecting behavioral signals in exchange for access to aggregated intent signals.
Reddit
Reddit
Embedding and social sharing platform primarily known for Reddit's comment embed and advertising pixel. The Reddit Pixel tracks page views, custom events, and purchase conversions on advertiser sites to enable retargeting and lookalike audience building on Reddit's ad platform.
Crazy Egg
Crazy Egg
Heatmap, scroll map, and session recording tool used by product and UX teams to understand how visitors interact with pages. The Crazy Egg script records mouse movements, clicks, and scroll depth, then renders aggregated heatmaps in the dashboard. Also includes A/B testing capabilities that inject page variants for conversion experiments.
DoubleVerify
DoubleVerify
Ad measurement and verification platform that evaluates ad viewability, fraud, and brand suitability. The DV script runs alongside ad tags and reports impression-level data on whether ads were viewable, whether the page is brand-safe, and whether the traffic appears human.
The Nielsen Company
The Nielsen Company
Audience intelligence and addressable advertising platform from Nielsen. Scripts measure digital audience demographics and validate that campaigns reach their intended audiences. Used by publishers for audience measurement and by advertisers for campaign performance reporting.
New Relic
New Relic
Application performance monitoring and error tracking platform for engineering teams. The New Relic browser agent collects real-user monitoring (RUM) data — page load times, AJAX calls, JavaScript errors — and sends it to New Relic's observability platform. Does not track user behavior for advertising or retargeting.

Manage consent for Automattic

ConsentStack automatically detects and manages Automattic trackers so your site stays compliant with global privacy regulations.