Google Analytics will tell you how many users visited your website and where they came from. But when you ask why half of them abandon a form at the third field, or what exactly a user did before reporting a bug, there is an awkward silence. This is exactly the gap PostHog fills: an open source product analytics platform that combines event analysis, session recordings, heatmaps, feature flags, A/B tests and surveys in a single tool. In this article we show how to implement it and which features bring the most value from day one.
PostHog: analytics that shows what users really do
17.09.2026 | Author: Marcin Wiercioch
How is PostHog different from GA4?
They are tools from different worlds that partly overlap. GA4 grew out of marketing: campaigns, traffic sources, ad conversions. PostHog grew out of product work: what users do inside an application or a store and where we lose them. The most important differences from our experience:
- Raw events instead of aggregates: every event can be viewed, filtered and combined into a funnel or a retention analysis, with no sampling and no waiting a day for the data to be processed,
- session replay: you play back a video of a user’s visit: mouse movements, clicks, console errors; invaluable for debugging and UX research,
- feature flags and experiments in the same tool: you can see straight away how an enabled feature affects your metrics,
- control over data: a cloud with servers in the EU (the eu.posthog.com region) or full self-hosting on your own infrastructure; under GDPR this is a completely different conversation than with GA,
- autocapture: clicks, form submissions and navigation are collected automatically, without tagging every button separately.
Does PostHog replace GA4? In many projects it does, but the two tools can also happily live side by side: GA4 for marketing and media, PostHog for the product team and developers.
Implementation in 10 minutes
We create an account (choosing the EU region) and then paste the snippet before the closing </head> tag, or install the library from npm:
npm install posthog-js
import posthog from "posthog-js";
posthog.init("phc_TwojKluczProjektu", {
api_host: "https://eu.i.posthog.com",
defaults: "2025-05-24",
capture_exceptions: true
});
From then on, autocapture records page views, clicks and form submissions. In WordPress, the easiest way to add the snippet is with a small custom plugin or in the theme, and if you use our technical support, we do it for you together with the cookie consent configuration.
Custom events and user identity
Autocapture is a start, but the real power comes with domain events, named the way your business talks:
posthog.capture("add_to_cart", {
product_id: "SKU-1234",
price: 249.99,
currency: "PLN"
});
// after login, link the anonymous history to the account
posthog.identify("user_8721", {
plan: "premium",
city: "Wroclaw"
});
Thanks to identify, the user’s earlier anonymous activity is attached to their account, and the “visit → sign-up → first purchase” funnel suddenly becomes complete. Events can also be sent from the backend (there are libraries for PHP, Python and Node), for example when an order is paid, which makes key metrics independent of ad blockers.
Session replay: see what the user saw
Session recordings are switched on with a single toggle in the project settings. Two things need attention:
- data masking: PostHog masks form fields by default; it is worth adding the
ph-no-captureclass to elements with sensitive data (addresses, order numbers) so that they are blurred in recordings, - consent: we start replay only after the user has consented, linking it to the cookie banner (PostHog has an opt-in mode:
opt_out_capturing_by_defaultplus a call toposthog.opt_in_capturing()after acceptance).
In practice we most often watch recordings with the filter “sessions with a console error” or “sessions with a rage click”; it is the shortest path from a report that “something does not work” to the exact line that does not work.
Feature flags and A/B tests
A flag in PostHog is a switch that can apply to a percentage of traffic or to a specific group of users:
if (posthog.isFeatureEnabled("new-cart")) {
renderNewCart();
} else {
renderOldCart();
}
An experiment is the same flag plus a goal metric: PostHog splits the traffic itself, counts conversions in both variants and tells you when the result is statistically significant. For online stores it is a natural tool for testing the product page layout, button copy or checkout steps, without external tools and without the page flickering.
How much does it cost?
The model is usage-based, with a generous free tier every month: 1 million events, several thousand session recordings and a million flag checks. Small and medium-sized websites often never go beyond the free tier. Above it, you pay for the data actually collected, and billing limits protect you from surprises. For organisations with strict compliance requirements there is the self-hosting option (a Docker image, the hobby version): 100% of the data on your own server, at the cost of maintaining it yourself.
Pitfalls worth avoiding
- autocapture without an event naming plan ends in chaos, so agree on a dictionary of domain events at the start,
- sending personal data in event properties is asking for trouble; keep identifiers there, not email addresses,
- replay on pages with medical or financial data requires particularly careful masking,
- with high traffic it is worth limiting recordings to a sample of sessions; 10% is usually enough to draw conclusions.
Summary
PostHog shortens the distance between the question “why do users drop off?” and a data-backed answer, and it does so in one tool instead of five separate subscriptions. Combined with the European data region, it is also simply easier to defend legally than American alternatives. We implement it for our clients together with consent configuration and an event dictionary; write to us if you finally want to see what is really happening in your store. In the next and final article of the series: Cloudflare Turnstile, or how to say goodbye to annoying CAPTCHAs without opening the door to bots.



