Title: BaseCloud UTM Tracker
Author: BaseCloud
Published: <strong>16 de septiembre de 2025</strong>
Last modified: 23 de septiembre de 2026

---

Buscar plugins

![](https://ps.w.org/basecloud-utm-tracker/assets/banner-772x250.jpg?rev=3375855)

![](https://ps.w.org/basecloud-utm-tracker/assets/icon-256x256.png?rev=3375855)

# BaseCloud UTM Tracker

 Por [BaseCloud](https://profiles.wordpress.org/basecloud/)

[Descargar](https://downloads.wordpress.org/plugin/basecloud-utm-tracker.4.4.0.zip)

 * [Detalles](https://es-do.wordpress.org/plugins/basecloud-utm-tracker/#description)
 * [Valoraciones](https://es-do.wordpress.org/plugins/basecloud-utm-tracker/#reviews)
 *  [Instalación](https://es-do.wordpress.org/plugins/basecloud-utm-tracker/#installation)
 * [Desarrollo](https://es-do.wordpress.org/plugins/basecloud-utm-tracker/#developers)

 [Soporte](https://wordpress.org/support/plugin/basecloud-utm-tracker/)

## Descripción

**BaseCloud UTM Tracker** is the ultimate UTM tracking and webhook management solution
for WordPress. Replace Gravity Forms webhook add-on with unlimited custom webhooks,
full merge tag support, and automatic UTM injection for the "Big 4″ form plugins.

#### NEW in 4.4: visits, leads beyond Gravity Forms and keyword insights

Everything new is part of the Blog Post Conversion Tracker. Visit counting and the
BaseCloud Forms bridge are on by default while the tracker is on, also on sites 
that already use it, so they start after the update without any action (both are
first-party, follow the tracker’s consent setting and can be switched off in the
Tracker section). Every other new feature is off until you switch it on. The UTM
tracker is unchanged apart from two fixes (see the changelog).

 * **Visits and channels** – first-party visit counts per landing page and channel(
   search, social, AI assistants, email, paid, campaign, referral, direct), conversion
   rates per channel, and an organic comparison of plugin visits, Search Console
   clicks and, optionally, Google Analytics 4 sessions, with the likely reason for
   each gap.
 * **BaseCloud Forms bridge** – BaseCloud CRM forms embedded on your pages receive
   the visitor’s source, landing page and journey as extra fields, and confirmed
   submissions are recorded as leads.
 * **WhatsApp and call tracking** – a reference code in the pre-filled WhatsApp 
   message, WhatsApp and phone clicks recorded with their journey, an inbound API
   that lets your CRM, WATI or phone provider (for example Twilio) match chats and
   calls back to the visit, and tracking numbers per source or from a per-visitor
   pool.
 * **Keyword insights** – Search Console rhythm by weekday and month, brand and 
   non-brand searches separately, the searches each page really appears for next
   to its focus keyphrase, striking-distance queries, pages competing for the same
   query, and suspected automated queries set aside.
 * **AI visibility** – AI crawler hits split into training, search index and user-
   triggered fetches, human visits from AI assistants, and the missing pages AI 
   crawlers ask for.
 * **How it works** – a guide inside the plugin that explains where every number
   comes from and how accurate it is, with a live setup checklist.
 * **Reports** now include traffic, leads and Search Console insights.

#### NEW in 4.3: search keywords, AI visibility and reports

Everything new is part of the Blog Post Conversion Tracker and is off by default.
The UTM tracker is unchanged.

 * **Search keywords** – connect Google Search Console with a service account to
   see the queries that sent clicks to the landing page of each organic Google conversion,
   flagged against your target keywords (read from Yoast SEO, Rank Math, All in 
   One SEO and SEOPress, plus your own list). These are the likely keywords, not
   the visitor’s exact search: Google does not share that, and Search Console data
   is 2-3 days behind.
 * **AI visibility** – conversions referred by AI assistants (ChatGPT, Perplexity,
   Gemini, Copilot, Claude and others), an AI crawler log per page with optional
   IP verification, a robots.txt check for AI crawlers, an llms.txt generator, and
   AI answer citations from the Ahrefs API.
 * **Reports** – daily, weekly, monthly and half-yearly JSON reports of your best
   converting posts, channels, forms, keywords and AI visibility, sent to report
   webhooks with an optional PDF attachment, plus previews and PDF downloads for
   any date range.
 * **Secure by design** – API keys, service account keys and report webhook URLs
   are encrypted and write-only, requests go only to fixed service hosts or validated
   https webhooks, and reports contain no personal data.

#### NEW in 4.2: Blog Post Conversion Tracker

See which blog post a visitor was reading right before they filled in your Gravity
Form. Turn it on under **UTM Tracker > Blog Post Conversion Tracker** (it is off
by default).

 * **Journey tracking** – the browser keeps first and last touch, the first and 
   last post read and the most recent pages in localStorage, with a compact first-
   party cookie (`bc_blog_attr`, under 2 KB) as a backup. Gravity Forms submissions
   carry the full journey in a hidden field. Cache-safe, size-safe and consent-aware(
   Google Consent Mode regions respected).
 * **Entry columns** – "Blog: Converted From Post" (Yes, Yes (unverified) or No)
   and "Blog: Source Post" on Gravity Forms entries, plus minutes to convert, same
   visit, pages viewed after the post and an optional attribution window.
 * **Clean webhooks** – a readable JSON payload (form, entry, contact, fields, conversion,
   visitor, journey) with ISO 8601 times, sent after the visitor’s response so forms
   stay fast. UTM parameters are left to the UTM tracker.
 * **Secure by design** – webhook URLs and secrets are encrypted (AES-256-GCM, with
   an optional `BASECLOUD_BPCT_KEY` constant), HTTPS only with private-network blocking,
   never shown again after saving, and requests can be HMAC-signed.
 * **Top Converting Posts** and recent conversions in the dashboard.
 * Fully separate from the UTM tracker: its settings, cookies and webhooks are untouched.
   Deleting the plugin removes only the Blog Post Conversion Tracker data.

#### 🎯 THE COLLECTOR: Advanced Cookie Tracking

Automatically captures and stores UTM parameters from your marketing campaigns in
secure, persistent cookies.

#### 📦 THE COURIER: Automated Webhook Injection

**Game Changer!** Automatically injects UTM data into ALL form webhook submissions–
works with Gravity Forms, Elementor Pro, WPForms, and Contact Form 7!

#### The "Big 4″ Form Support

 * **Gravity Forms** – Full integration with async webhook support
 * **Elementor Pro Forms** – Webhook injection for page builder forms
 * **WPForms** – Complete webhook automation
 * **Contact Form 7** – Classic form plugin support

#### Key Features

 * **🚀 Zero Manual Configuration** – Works automatically after activation
 * **🎯 COLLECTOR System** – Advanced cookie-based tracking for 8 parameters
 * **📦 COURIER System** – Automatic webhook injection for all major form plugins
 * **⚡ Async Webhook Support** – Works with background processing (critical for
   Gravity Forms)
 * **🔄 Real-Time Diagnostics** – Animated status dashboard shows system health
 * **📊 Entry Meta Storage** – UTM data saved with each Gravity Forms submission
 * **🎨 Beautiful Dashboard** – Modern, animated interface with live status indicators
 * **🔒 Privacy Compliant** – Secure cookies with proper SameSite and HTTPS support
 * **📱 iOS 14+ Support** – Tracks gbraid and wbraid for enhanced Apple privacy 
   tracking

#### Tracked Parameters (8 Total)

 1. **referrer** – Previous page URL
 2. **utm_source** – Campaign source (Google, Facebook, etc.)
 3. **utm_medium** – Marketing medium (CPC, email, social)
 4. **utm_campaign** – Campaign name
 5. **utm_term** – Campaign keywords
 6. **gclid** – Google Click ID
 7. **gbraid** – Google Brand Engagement (iOS 14+)
 8. **wbraid** – Web to App Brand Engagement (iOS 14+)

#### How THE COURIER Works

 1. Visitor arrives with UTM parameters in URL
 2. COLLECTOR captures and stores data in cookies
 3. Visitor submits a Gravity Form
 4. COURIER automatically injects all UTM data into webhook payload
 5. Your CRM receives complete attribution data – automatically!

#### Perfect For

 * **Digital Marketing Agencies** – Complete campaign attribution without manual
   setup
 * **E-commerce Sites** – Track ROI from every marketing channel
 * **Lead Generation** – Automatic UTM data in your CRM
 * **SaaS Companies** – Understand customer acquisition sources
 * **PPC Campaigns** – Full Google Ads and Facebook Ads tracking

#### What’s NEW in v2.0.0?

 * 🎯 **COLLECTOR System** – Advanced cookie tracking engine
 * 📦 **COURIER System** – Automatic webhook injection (no manual fields!)
 * 🎨 **Animated Dashboard** – Real-time system diagnostics with animations
 * 📊 **Entry Meta Storage** – UTM data saved with each form submission
 * 🔧 **Excluded Webhooks** – Option to exclude specific webhook URLs
 * ✨ **iOS 14+ Support** – gbraid and wbraid parameter tracking
 * 🚀 **Zero Configuration** – Works automatically after activation

#### Gravity Forms Integration (THE COURIER)

**🚀 No Manual Field Creation Required!**

The COURIER system automatically injects all UTM data into Gravity Forms webhook
submissions. Simply:

 1. Enable "Gravity Forms Integration" in plugin settings
 2. Set up your Gravity Forms webhooks as normal
 3. The COURIER automatically adds UTM data to every webhook request

**Optional:** You can still create visible fields with parameter names (referrer,
utm_source, etc.) if you want users to see the data. The COLLECTOR will populate
them automatically.

**Excluded Webhooks:** Configure specific webhook URLs to exclude from UTM injection(
useful for internal notifications).

#### Technical Features

 * **Lightweight** – Minimal impact on site performance
 * **Standards Compliant** – Follows WordPress coding standards
 * **Secure** – Proper data sanitization and validation
 * **Translatable** – Ready for internationalization
 * **Mobile Friendly** – Works across all devices and browsers
 * **Entry Meta Storage** – UTM data stored with each Gravity Forms entry
 * **Webhook Automation** – Zero configuration webhook injection
 * **Animated UI** – Real-time system status with smooth animations

#### Use Cases

**Marketing Attribution**: Track which campaigns generate the most leads and sales–
automatically!

**CRM Integration**: UTM data flows seamlessly to your CRM via Gravity Forms webhooks.

**A/B Testing**: Compare performance between different campaign variations.

**ROI Analysis**: Calculate return on investment for different marketing channels.

**Customer Journey**: Understand how visitors discover and interact with your site.

### External services

The plugin’s server never sends data to BaseCloud. The services below are contacted
only when you switch the related Blog Post Conversion Tracker feature on and save
the credentials it needs. Conversion, lead and report webhooks send data only to
the https URLs you enter yourself. The inbound API for chats and calls only receives
requests; it contacts no one.

#### Google OAuth 2.0 and Google Search Console API

Used by Search keywords to read Search Console query data for your own site.

 * Hosts: `oauth2.googleapis.com` (access token) and `www.googleapis.com` (Search
   Console API).
 * When: only while Search keywords is enabled and a service account key is saved:
   the initial backfill of your Search Console history runs about every 5 minutes
   until it is complete, then a daily sync, plus "Test connection" and "Sync now".
 * Data sent: a JWT signed with your service account key (the service account email
   and a read-only scope) and the Search Console property with date ranges. Data
   received: query, page, click and impression rows. No visitor data is sent.
 * Google APIs Terms of Service: https://developers.google.com/terms
 * Google Privacy Policy: https://policies.google.com/privacy

#### Google Analytics Data API (optional)

Used by the organic comparison to read Google Analytics 4 sessions per landing page.

 * Hosts: `oauth2.googleapis.com` (access token) and `analyticsdata.googleapis.com`(
   GA4 Data API).
 * When: only while GA4 is switched on in the Search keywords section and a service
   account key is saved: a daily report, plus "Test connection".
 * Data sent: a JWT signed with your service account key (the service account email
   and the read-only `analytics.readonly` scope) and the GA4 property ID with a 
   date range. Data received: sessions per landing page and channel group, and sessions
   from AI assistant sources. No visitor data is sent.
 * Google APIs Terms of Service: https://developers.google.com/terms
 * Google Privacy Policy: https://policies.google.com/privacy

#### BaseCloud CRM forms (BaseCloud Forms bridge)

The plugin’s server does not contact BaseCloud. When your pages embed BaseCloud 
CRM forms, each form sends its submissions from the visitor’s browser to your BaseCloud
CRM at `api.basecloudglobal.com`. While the tracker and the bridge are on, the plugin
adds the attribution fields listed under "What is sent to BaseCloud Forms?" to that
request. Nothing is added on pages without a BaseCloud form, when the bridge is 
switched off, or before consent when consent mode is on. The allowed CRM hosts can
be changed in the Tracker section.

 * BaseCloud Privacy Policy: https://www.basecloudglobal.com/privacy-policy/

#### OpenAI, Perplexity and Anthropic crawler IP ranges

Used by the AI crawler log to check that requests claiming to come from these companies'
crawlers come from the IP ranges they publish.

 * Hosts: `openai.com`, `www.perplexity.ai` and `claude.com`.
 * When: only while the AI crawler log and IP verification are both on: one GET 
   request for each vendor’s public IP-range file about once a week, or when you
   click "Refresh crawler IP ranges" (which also needs both settings on).
 * Data sent: nothing beyond the request itself.
 * OpenAI Terms of Use: https://openai.com/policies/terms-of-use and Privacy Policy:
   https://openai.com/policies/privacy-policy
 * Perplexity Terms of Service: https://www.perplexity.ai/hub/legal/terms-of-service
   and Privacy Policy: https://www.perplexity.ai/hub/legal/privacy-policy
 * Anthropic Privacy Policy: https://www.anthropic.com/legal/privacy

#### Ahrefs API v3

Used by AI answer citations to read how often AI answers cite your pages (Ahrefs
Brand Radar).

 * Host: `api.ahrefs.com`.
 * When: only while the Ahrefs feature is enabled and an API key is saved: a weekly
   sync (one request plus one for each selected AI platform), plus "Test connection"
   and "Sync now". Calls use Ahrefs API units from your Ahrefs subscription.
 * Data sent: your API key, the target domain, the selected AI platforms and the
   optional country.
 * Ahrefs Terms of Service: https://ahrefs.com/legal/terms
 * Ahrefs Privacy Policy: https://ahrefs.com/legal/privacy-policy

### Privacy Policy

BaseCloud UTM Tracker uses first-party cookies and browser storage for campaign 
and content attribution. Its server never sends data to BaseCloud. Data only leaves
your site through integrations you configure yourself: your form, lead and report
webhooks, the Meta Conversions API, the BaseCloud Forms bridge (which adds attribution
to BaseCloud CRM forms already embedded on your pages), and the Search Console, 
Google Analytics, Ahrefs and crawler IP-range services described under External 
services, each only if you enable it.

**UTM tracker**

 * Stores UTM parameters, click IDs, the referrer and the landing page in first-
   party, SameSite cookies (duration configurable)
 * Adds them to form submissions and to the webhooks you configure
 * Meta Conversions API (off by default) sends SHA-256 hashed email and phone, IP
   address and user agent to Meta

**Blog Post Conversion Tracker (off by default)**

 * Keeps the pages and blog posts a visitor viewed on your site, their first and
   latest visit source, and visit counts in the browser’s localStorage, with a compact
   first-party cookie (`bc_blog_attr`) as a backup
 * When a Gravity Form is submitted, adds that journey to the submission as a hidden
   field, saves it on the entry and sends it, with the form fields and contact details
   you choose, to the webhooks you configure
 * Optional consent mode waits for your consent cookie or Google Consent Mode before
   tracking

**Search keywords, AI visibility and reports (off by default)**

 * Store aggregated data only: Search Console query, page, click and impression 
   counts; AI crawler hits per page and bot (no IP addresses); AI citation counts
   from Ahrefs; and one row per conversion with post IDs, channel labels, the landing
   path and dates. No names, email addresses, IP addresses or form values are added.
 * Contact Google, Ahrefs, OpenAI, Perplexity and Anthropic only as described under
   External services, and send reports only to the report webhooks you configure.

**Visits, leads and the BaseCloud Forms bridge (4.4.0)**

 * Visit counting and the BaseCloud Forms bridge are on by default while the tracker
   runs (after consent when consent mode is on). The browser sends one small request
   per visit to your own site with the landing page and the channel of the visit.…

## Instalación

#### Automatic Installation

 1. Log in to your WordPress admin panel
 2. Navigate to Plugins > Add New
 3. Search for "BaseCloud UTM Tracker"
 4. Click "Install Now" and then "Activate"
 5. Done! The COLLECTOR and COURIER are now active.

#### Manual Installation

 1. Download the plugin ZIP file
 2. Log in to your WordPress admin panel
 3. Navigate to Plugins > Add New > Upload Plugin
 4. Choose the ZIP file and click "Install Now"
 5. Activate the plugin

#### Configuration

 1. Navigate to **UTM Tracker** in your WordPress admin menu
 2. Verify the **System Status** shows COLLECTOR and COURIER as Active
 3. (Optional) Adjust cookie duration (default: 7 days)
 4. (Optional) Add webhook URLs to exclude from UTM injection
 5. Save settings

**That’s it!** The plugin works automatically – no manual field creation needed.

## FAQ

### Do I need to create hidden fields in my Gravity Forms?

**No!** That’s the magic of v2.0. The COURIER system automatically injects UTM data
into webhook submissions. You don’t need to create any fields.

### What UTM parameters are tracked?

All 8 parameters:
 * referrer – Previous page URL * utm_source – Campaign source*
utm_medium – Marketing medium * utm_campaign – Campaign name * utm_term – Keywords*
gclid – Google Click ID * gbraid – Google Brand Engagement (iOS 14+) * wbraid – 
Web to App tracking (iOS 14+)

### How long are UTM parameters stored?

UTM data is stored in cookies for the duration you specify in settings (1-365 days,
default is 7 days).

### Does this work with other form plugins besides Gravity Forms?

The COURIER system is specifically designed for Gravity Forms webhooks. The COLLECTOR(
cookie tracking) works with any form plugin, but automatic webhook injection requires
Gravity Forms.

### Is the plugin GDPR compliant?

The plugin uses functional cookies necessary for tracking campaign attribution. 
You should include UTM tracking in your privacy policy and cookie notice.

### Can I exclude certain webhooks from UTM injection?

Yes! In the plugin settings, add webhook URLs (one per line) to the "Excluded Webhook
URLs" field. This is useful for internal notifications or universal webhooks.

### Does this affect site performance?

No! The plugin is optimized for performance with minimal JavaScript and efficient
server-side processing.

### Blog Post Conversion Tracker: why do some visitors have no journey?

The tracker runs in the visitor’s browser, so pages must include its script: purge
your page cache (and any CDN or JavaScript optimisation cache) after enabling it.
Safari caps storage written by scripts (cookies and localStorage) at about 7 days,
so Safari visitors who come back after a longer gap start a new journey.

### Blog Post Conversion Tracker: consent mode with a GTM consent-template banner

Cookie banners built on Google Tag Manager consent templates set consent through
GTM’s own API, not through `window.dataLayer`, so the tracker cannot see that consent.
On those sites have the banner run `document.dispatchEvent(new Event('bc-consent-
granted'))` once analytics consent is given, or use the "Consent cookie name" setting.
Consent granted after a page has loaded starts tracking on the next pageview, unless
the banner dispatches `bc-consent-granted`.

Only use "Consent cookie name" for a cookie that holds a simple value (`true`, `
1`, `yes`, `granted` or `allow`). Any other value counts as an explicit refusal,
which stops tracking and deletes the visitor’s stored journey. Many consent platforms
store a structured value (for example `consentid:…,analytics:yes`); for those, leave
the setting blank and rely on Google Consent Mode or the `bc-consent-granted` event.

### Search keywords: are these the exact keywords a visitor searched?

No. Google does not share individual searches. These are the Search Console queries
that sent clicks to the landing page on the visit day (give or take a day). The 
data is 2-3 days delayed, rare or anonymised queries are missing, and only visits
from Google organic search are matched. Conversions that landed before the synced
Search Console period (set by "Days of history on first sync", at most about 16 
months) are counted as out of range, not as having no query data.

### Search keywords: can I see AI Overviews or AI Mode clicks separately?

No. Search Console reports them inside Web search results with no filter. Use the
Ahrefs AI answer citations in the AI visibility section to see AI answer visibility.

### Search keywords: how do I connect Google Search Console?

 1. In the Google Cloud console, create or select a project and enable the Google Search
    Console API.
 2. Create a service account and download a JSON key for it.
 3. In Search Console, open Settings > Users and permissions and add the service account’s
    email address (Restricted permission is enough).
 4. Under UTM Tracker > Blog Post Conversion Tracker > Search keywords, paste the JSON
    key and the property (`sc-domain:example.com` or `https://www.example.com/`), save,
    then click Test connection.

### AI visibility: why are AI crawler counts low or unverified?

Hits are logged only when WordPress runs, so pages served from a page cache or CDN
are missed. IP verification uses the connecting IP address, so behind a proxy or
CDN hits show as unverified. No IP addresses are stored.

### AI visibility: when is llms.txt served?

Only while "Serve /llms.txt" is on and no real llms.txt file or other plugin already
provides one. It is not served while search engines are discouraged (Settings > 
Reading > Search engine visibility), or when the `basecloud_bpct_llms_txt_allowed`
filter returns false, which maintenance, coming-soon or login-wall setups can use.
Page descriptions come only from the SEO meta description or the post’s own excerpt,
never from the post content.

### Reports: why did a scheduled report arrive late?

Scheduled reports run on WP-Cron, which only fires when someone visits the site.
On quiet sites, add `define('DISABLE_WP_CRON', true);` to wp-config.php and run 
wp-cron.php from a real server cron every 5-15 minutes. Each report is sent once
per period at or after its send hour, and a failed delivery is retried on the next
hourly runs (up to three attempts).

### How accurate are the numbers?

Each source counts something different, so they never match exactly. Search Console
counts clicks on Google results, Google Analytics counts the sessions its script
can measure, and this plugin counts the visits its own first-party tracker sees.
For organic search, Search Console clicks are usually highest, GA4 organic sessions
lower, and the plugin’s organic visits often lowest. Common reasons:

 * A Search Console domain property includes clicks to your other subdomains, for
   example a CRM or app login site, which WordPress never sees.
 * Google Business Profile links with UTM tags count as a campaign in the plugin
   and GA4, but as Google clicks in Search Console.
 * Visitors who refuse consent (when consent mode is on), block scripts or leave
   before the page loads are not counted, and bots are left out on purpose.
 * Many apps strip the referrer, so those visits count as Direct.
 * Search Console days run on US Pacific time and the data is 2-3 days behind.

As a rough guide, not a guarantee: once subdomain and tagged-link clicks are set
aside, the figures are often within 20-30% of each other. Compare periods of 28 
days or more. The "How it works" section in the plugin explains every number and
shows a setup checklist.

### Where does the AI data come from?

From three separate sources, shown separately because they measure different things:

 * **AI assistant visits**: people who clicked a link to your site in ChatGPT, Perplexity,
   Gemini, Copilot, Claude or another assistant, recognised by the referrer or `
   utm_source`. These are real visits, but a minimum: many AI apps send no referrer,
   so those visits count as Direct.
 * **AI crawler hits**: requests from AI bots that reach WordPress, recognised by
   user agent and optionally verified against the IP ranges OpenAI, Perplexity and
   Anthropic publish. They are split by purpose: training (for example GPTBot, ClaudeBot),
   search index (OAI-SearchBot, PerplexityBot) and user-triggered fetches (ChatGPT-
   User, Claude-User), where a person asked an assistant something and it fetched
   your page. Verified and unverified hits are shown separately. Posts and pages
   are logged under their own address, other requests under fixed labels such as/
   feed/ or /other/, and missing pages under the address asked for (with daily row
   limits). Bots are not people, and pages served from a page cache or CDN are not
   logged.
 * **AI answer citations**: from the Ahrefs API (Brand Radar, optional), a sample
   of AI answers that cited your pages.

Clicks from Google AI Overviews and AI Mode are part of Google organic search. Neither
Search Console nor this plugin can separate them.

### How does WhatsApp tracking work without the customer typing anything?

When a visitor clicks a WhatsApp link on your site (wa.me, api.whatsapp.com, web.
whatsapp.com or whatsapp://), the plugin adds a short reference line such as "Ref:
BC-7K2M9Q" to the pre-filled message, after your own text or after a greeting you
choose, and records the click with the visitor’s source and journey. The visitor
only presses Send. When your CRM or WhatsApp tool (for example WATI) forwards incoming
messages to the plugin’s inbound API, the reference code links the chat to the click
and the API returns the attribution. If the visitor deletes the reference line, 
or starts a chat without your site’s link (a saved contact or a QR code), the chat
cannot be matched. WhatsApp and call tracking is off by default.

### How do call tracking numbers work?

You need extra phone numbers from a telephony provider (for example Twilio); the
plugin does not supply numbers. There are two modes:

 * **Per source**: each channel shows its own number (for example Google Ads visitors
   see one number and organic search visitors another). Calls are attributed to 
   the source, not to an individual visit.
 * **Per-visitor pool**: each visitor is shown a number from a pool while they are
   active (30 minutes by default). When your provider reports a call to the inbound
   API, the number called and the time identify the visitor and their journey. When
   every pool number is in use, a new visitor gets no pool number: the page shows
   the per-source number if you set source rules, otherwise your normal number. 
   Make the pool large enough for the number of visitors on the site at the same
   time.

Numbers are swapped in phone links and visible text in the visitor’s browser, so
this works with cached pages. People who saved a number earlier are attributed to
whoever had that number at the time. Clicks on phone links are recorded in both 
modes; they are reported by the visitor’s browser, so treat them as intent, not 
as calls.

### What is sent to BaseCloud Forms?

Only when a BaseCloud CRM form is embedded on your page and the visitor submits 
it. The plugin adds attribution fields to the request the form already sends from
the visitor’s browser to your BaseCloud CRM (api.basecloudglobal.com). A field is
added only when the form did not send it already, so form fields, `utm_*` values,
the referrer and click IDs are never changed. The fields are a reference code (`
bc_lead_ref`), random visitor and session IDs, the first and latest source (channel,
source, medium, campaign, landing page, referrer host and date), the number of visits
and pageviews, the first and last post read, the journey as page paths and the current
page. Values are plain text (tags removed, at most 300 characters) and are added
to the form’s own request text without rewriting it. Form field values are never
read. When the CRM confirms the submission, the plugin also records a "browser-reported"
lead, even with WhatsApp & calls switched off. The bridge is on by default while
the tracker is on, can be switched off in the Tracker section, and with consent 
mode on runs only after consent.

### What personal data does the plugin store?

Visit, keyword, crawler and report tables hold counts, page paths, channel labels
and dates: no names, email addresses, IP addresses or user agents. Leads (WhatsApp
and call clicks, BaseCloud Forms submissions) store a reference code, random visitor
and session IDs, the source, landing page and journey. Phone numbers are stored 
in full only when they are your own business numbers (listed under WhatsApp & calls,
or used as tracking numbers). Callers, WhatsApp senders and any other number are
stored only as a keyed pseudonym (so repeat contacts can be recognised) plus the
last 3 digits. Message text is never stored. IP addresses are never stored; a keyed
hash is used for rate limits and, with a number pool, kept with each lease until
retention deletes it. Gravity Forms entries keep what Gravity Forms stores. Retention
settings delete old rows automatically.

### Why is my visit count lower than Google Analytics?

The plugin counts a visit only when its own tracker runs in the visitor’s browser
and reports it. It does not count visitors who refuse consent (when consent mode
is on), block scripts or the request, or leave before the page loads, and it leaves
out bots and automated browsers on purpose. A session is counted once, even if its
request is repeated within 24 hours, and a new visit starts only after 30 minutes
without activity. Behind a proxy or CDN without the trusted proxy setting, counting
also stops after about 30 visits an hour (see the next question). GA4 has its own
consent handling, bot rules and data thresholds, so some gap is normal (often 10-
30%, as a rough guide rather than a guarantee). Check the setup checklist under "
How it works" if the gap is much larger.

### My site is behind Cloudflare, a load balancer or another proxy. What should I set?

Rate limits of the visit and lead endpoints work per visitor address. Behind a proxy
that is not configured, every visitor seems to come from the proxy’s address, so
the limit is reached after about 30 visits an hour and further visits are not counted.
In the Tracker section choose the header your proxy sets (Cloudflare: CF-Connecting-
IP; many load balancers: X-Forwarded-For) under "Trusted proxy header". The header
is only trusted when the connection comes from a private or loopback address or 
from the proxy networks you list (for Cloudflare, add its published IP ranges), 
so visitors cannot fake it. The plugin detects a proxy it is not configured for 
and warns in the Tracker and Traffic & sources sections and in the "How it works"
checklist. Addresses are only used as a keyed hash and never stored.

### Will this work with Elementor popups?

Yes! The COLLECTOR includes special support for Elementor popup forms with automatic
field population after popup opens.

### Can I see the UTM data somewhere?

UTM data is stored in cookies and automatically populates Gravity Forms fields. 
You can view this data in your form submissions or integrate with analytics tools.

## Reseñas

![](https://secure.gravatar.com/avatar/db56c73b0fd1a419d01e3009da9ac70d01c14eeb844c6ebad13c08618da0b3fb?
s=60&d=retro&r=g)

### 󠀁[Versatile](https://wordpress.org/support/topic/versatile-60/)󠁿

 [ontrck](https://profiles.wordpress.org/ontrck/) 14 de mayo de 2026

I was just typing in "BaseCloud" got surprised by a few of them! Looks clean and
professional and a lot of features presented.

![](https://secure.gravatar.com/avatar/4636c8dea9c0dc990b34e107b96be6631365f7a985efbd40ae3dcc3efe47d44f?
s=60&d=retro&r=g)

### 󠀁[Great Plugin](https://wordpress.org/support/topic/great-plugin-41492/)󠁿

 [iceshade](https://profiles.wordpress.org/iceshade/) 14 de mayo de 2026

Great Plugin for BaseCloud CRM clients to track UTM Tags for their forms.

 [ Leer todas las 2 reseñas ](https://wordpress.org/support/plugin/basecloud-utm-tracker/reviews/)

## Colaboradores y desarrolladores

"BaseCloud UTM Tracker" es un software de código abierto. Las siguientes personas
han colaborado con este plugin.

Colaboradores

 *   [ BaseCloud ](https://profiles.wordpress.org/basecloud/)

[Traduce "BaseCloud UTM Tracker" a tu idioma.](https://translate.wordpress.org/projects/wp-plugins/basecloud-utm-tracker)

### ¿Interesado en el desarrollo?

[Revisa el código](https://plugins.trac.wordpress.org/browser/basecloud-utm-tracker/),
echa un vistazo al [repositorio SVN](https://plugins.svn.wordpress.org/basecloud-utm-tracker/)
o suscríbete al [registro de desarrollo](https://plugins.trac.wordpress.org/log/basecloud-utm-tracker/)
por [RSS](https://plugins.trac.wordpress.org/log/basecloud-utm-tracker/?limit=100&mode=stop_on_copy&format=rss).

## Registro de cambios

#### 4.4.0

**Visits, leads beyond Gravity Forms, keyword insights and a "How it works" guide**

 * NEW: First-party visit counting (on by default while the tracker is on, also 
   on existing sites): one request per visit to the site’s own REST endpoint, stored
   as daily counts per landing page and channel. Bots, automated browsers and repeats
   of a session within 24 hours are left out, and consent mode applies.
 * NEW: Trusted proxy setting for sites behind Cloudflare, a load balancer or another
   proxy, with automatic detection when it is missing.
 * NEW: Traffic & sources section: visits by channel compared with the previous 
   period, human visits from AI assistants, top landing pages with their channel
   split, conversion rates per channel, and an organic comparison of plugin visits,
   Search Console clicks and (optional) GA4 sessions with the likely reason for 
   each gap.
 * NEW: BaseCloud Forms bridge (on by default while the tracker is on, also on existing
   sites): embedded BaseCloud CRM forms receive the visitor’s source, landing page
   and journey as extra `bc_*` fields, and confirmed submissions are recorded as
   browser-reported leads.
 * NEW: WhatsApp & calls section (off by default): reference codes in pre-filled
   WhatsApp messages, WhatsApp and phone click tracking with the journey, an inbound
   API for your CRM, WATI or Twilio to match chats and calls, tracking numbers per
   source or from a per-visitor pool, an optional lead webhook (form leads and matches
   by default) and a live feed. Leads whose session had no counted visit are marked"
   unverified session".
 * NEW: Keyword insights in Search keywords, calculated after each daily refresh
   or with "Recalculate": brand and non-brand searches (brand terms detected from
   the site name and domain, editable), weekday and monthly rhythm with 480 days
   of page history, focus keyphrase vs the searches each page really gets, striking-
   distance queries, cannibalisation, suspected automated queries set aside, and
   an optional GA4 connection.
 * NEW: AI visibility: crawler hits by purpose (training, search index, user-triggered
   fetch) with verified and unverified hits separately, human AI assistant visits,
   and a list of missing pages AI crawlers requested.
 * NEW: Minified front-end scripts (the sources are used with `SCRIPT_DEBUG`).
 * NEW: "How it works" section: where every number comes from, how accurate it is,
   and a live setup checklist.
 * NEW: Reports include traffic, leads and Search Console insights (additive keys;
   the JSON schema version stays 1).
 * CHANGED: Visit counting and the BaseCloud Forms bridge are on by default after
   the update, also where the Blog Post Conversion Tracker already runs; switch 
   them off in the Tracker section if you do not want them.
 * CHANGED: A link with only an `fbclid` now counts as social, not paid Meta ads(
   Facebook adds it to ordinary shares). Google Ads `gbraid` / `wbraid` clicks now
   count as paid. Page-builder post types such as Elementor floating buttons and
   templates can no longer be tracked.
 * FIXED: The UTM tracker’s `referrer` value could be set to the site’s own URL 
   after internal navigation; only external referrers are stored now.
 * FIXED: Settings fields for Search Console retention and backfill and for the 
   llms.txt post limit now show the limits that are actually applied.
 * SECURITY: The legacy `basecloud_utm_diagnostics` AJAX action now requires a nonce
   and the `manage_options` capability.
 * SECURITY: The new public endpoints accept only small, whitelisted, sanitised 
   payloads, check the origin, filter bots, are rate-limited per address and per
   network, and are never cached (`no-store, private`). The inbound API needs a 
   secret key that is stored only as a hash.
 * SECURITY: Daily caps per site-local day for visits (100,000), new unverified 
   landing addresses (200, then grouped as "/(other)"), browser-reported leads (
   300 form leads, 1,000 WhatsApp and 1,000 call clicks) and unverified-session 
   leads (50 per kind); lead webhooks at most 120 an hour. A full number pool gives
   no number instead of sharing one, with at most 3 active leases per address.
 * SECURITY: Phone numbers are stored in full only for your configured business 
   numbers; everyone else only as a pseudonym plus the last 3 digits. Twilio callbacks
   for outgoing calls are ignored. Message text is never stored. The BaseCloud Forms
   bridge strips tags from values and no longer rewrites the CRM request body.
 * SECURITY: The AI crawler log caps missing-page and non-post rows per day and 
   uses fixed labels for non-post requests; keyword insights are memory-bounded 
   and never calculated while a report is built.

#### 4.3.0

**Search keywords, AI visibility and reports** (all off by default)

 * NEW: The Blog Post Conversion Tracker tab has four sections: Tracker, Search 
   keywords, AI visibility and Reports. Each section saves its own settings.
 * NEW: Search keywords from Google Search Console for organic Google conversions,
   flagged against target keywords from Yoast SEO, Rank Math, All in One SEO, SEOPress
   and a manual list. These are the likely keywords for the landing page, 2-3 days
   delayed, not the visitor’s exact search.
 * NEW: AI visibility: AI assistant referrals as a channel, an AI crawler log with
   optional IP verification, a robots.txt AI access check, an llms.txt generator
   and AI answer citations from the Ahrefs API.
 * NEW: Reports: daily, weekly, monthly and half-yearly `blog_post_conversion_report`
   JSON to up to 10 report webhooks, with an optional PDF attachment, "Send now"
   for any date range, and preview and PDF download in the admin.
 * NEW: A conversion data store (`{prefix}bpct_conversions`, no personal data) with
   a one-time import of existing entries and daily retention.
 * NEW: Conversion webhook payloads include `visitor.first_touch.channel` and `visitor.
   last_touch.channel` labels (additive, still schema version 1, never UTM values).
 * Security: encrypted, write-only keys and webhook secrets; a fixed host allowlist
   for service requests; SSRF checks, forced TLS and HMAC signatures for report 
   webhooks; nonce and capability checks on every action; redirects and unsafe URLs
   pinned off for all Blog Post Conversion Tracker requests.
 * Security: the development scripts update-release.php and version-helper.php now
   refuse to run outside the command line and, with the internal release notes, 
   are no longer included in the plugin package.
 * Bundles FPDF 1.86 for PDF reports, loaded only while a PDF is generated.
 * The UTM tracker, its cookies and its webhooks are unchanged. Deleting the plugin
   also removes the new tables, options and scheduled events.

#### 4.2.0

**Blog Post Conversion Tracker**

 * NEW: **Blog Post Conversion Tracker** tab (off by default). Shows which blog 
   post a visitor read right before submitting a Gravity Form.
 * Journey storage: the full journey (first/last touch, first/last post read, recent
   pages) lives in localStorage. A compact first-party `bc_blog_attr` cookie, capped
   at 2 KB so the site’s Cookie header stays small, is the backup, and Gravity Forms
   submissions carry the full journey in a hidden `bcpct_record` field. Cache-safe
   and size-safe.
 * Optional consent mode: waits for a consent cookie, a `bc-consent-granted` event
   or Google Consent Mode granting `analytics_storage`. Regional consent defaults
   are respected.
 * Last touch changes only for a campaign visit that did not come from internal 
   navigation, or a new session from an external site.
 * Gravity Forms entry columns "Blog: Converted From Post" (Yes, Yes (unverified)
   or No) and "Blog: Source Post", plus minutes to convert, same visit (by visit
   number), pages viewed after the post, posts read (verified posts only) and an
   optional attribution window. Source posts and journey titles are verified server-
   side.
 * Webhooks with a clean, readable JSON payload (form, entry, contact, fields, conversion,
   visitor, journey) and ISO 8601 times. No UTM parameters or click IDs. Sent after
   the visitor’s response, within a 10-second budget and without retrying timeouts.
   Per-webhook target forms, "only blog-post conversions" option, contact toggle,
   send test and delivery log.
 * Security: webhook URLs and secrets are encrypted at rest (AES-256-GCM, optional`
   BASECLOUD_BPCT_KEY` constant so salt rotation does not break them), HTTPS only,
   SSRF-protected for IPv4 and IPv6, TLS verification forced, write-only in the 
   admin, and requests can be HMAC-SHA256 signed.
 * Top Converting Posts and Recent Conversions panels. Uninstalling removes only
   the Blog Post Conversion Tracker data.
 * The UTM tracker is unchanged. The new feature uses its own settings, cookie, 
   webhooks and entry meta. Its cookie is named `bc_blog_attr` so it never collides
   with other attribution scripts that use `bc_attr`.

#### 4.1.2

 * IMPROVED: Advanced Name field parts can now be mapped individually instead of
   returning the full name. {Name} or {First Name} returns the first name only, 
   and {Surname} or {Last Name} returns the last name only. {Middle Name}, {Prefix},
   and {Suffix} are also supported, and {Full Name} returns the complete name.
 * Address and other multi-input fields can be mapped by their sub-field labels,
   for example {City} or {Postal Code}.

#### 4.1.1

 * FIXED: Advanced Name field (and other multi-input Gravity Forms fields) returned
   empty when used as a merge tag like {Name} in Select Fields mode. These fields
   store their data in sub-inputs, so a direct lookup missed them. They are now 
   resolved with Gravity Forms' export formatter, the same method used by "All Fields"
   mode.
 * Applies to merge tags by label ({Name}) and by field ID ({Name:1}).

#### 4.1.0

**Per-Form Webhook Targeting**

 * **Target Form selector** – Each webhook can now be scoped to a specific Gravity
   Form, or left as "All Forms" to fire on every submission. The dropdown lists 
   every form on the site automatically.
 * **Form-aware field picker** – When a form is selected, the "Load My Form Fields"
   picker shows only that form’s fields, making "Select Fields" mapping faster and
   more accurate.
 * Works with both "All Fields" and "Select Fields" body modes, scoped to the chosen
   form.
 * Fully backward compatible – existing webhooks default to "All Forms" and behave
   exactly as before.

#### 4.0.0

**🚀 MAJOR UPDATE — Close the Loop: Conversion Intelligence**

 * 🎯 **Meta Conversions API (CAPI)** – Send server-side conversion events to Meta
   on every Gravity Forms submission. Email & phone are SHA-256 hashed, with _fbc/
   _fbp and fbclid support, event de-duplication, and a Test Event Code for validation.
   Beats browser-only pixels against ad-blockers and iOS.
 * **Multi-Channel Click ID Capture** – Now tracks Meta (fbclid), Microsoft/Bing(
   msclkid), TikTok (ttclid) and LinkedIn (li_fat_id) click IDs alongside Google’s
   gclid/gbraid/wbraid – plus the previously missing utm_content.
 * **Full Attribution Journey** – Captures first-touch AND last-touch source/medium/
   campaign, landing page, first-visit timestamp, and visit count – all forwarded
   to your webhooks/CRM.
 * **Webhook Delivery Log + Auto-Retry** – Every webhook and CAPI call is logged(
   status, time, response) with an automatic single retry on failure, viewable right
   in the admin.
 * **Consent Mode (GDPR)** – Optional consent gating: tracking cookies are only 
   set after a named consent cookie is granted or Google Consent Mode allows storage.
   Off by default.
 * All new features are additive or off-by-default – existing setups are unaffected
   until enabled.

#### 3.0.4

 * 🎯 **Fixed "All Fields" Webhooks** – The "All Fields" body option now correctly
   includes Form Title, Form ID, Entry ID, Entry Date, Source URL and User IP – 
   no more missing form titles and entry metadata
 * **Complete Field Capture** – Multi-input Gravity Forms fields (Name, Address,
   Checkboxes, Multi-select, List) are now resolved with Gravity Forms' own export
   formatter instead of being silently dropped
 * **NEW: Extra Fields in "All Fields" Mode** – You can now add custom/extra field
   mappings even when "All Fields" is selected, so anything missing can be added
   manually
 * **NEW: Load My Form Fields** – Browse the real fields from all your Gravity Forms
   inside the webhook editor and click any field to add it instantly
 * FIXED: Empty values no longer cause a field to disappear from the payload in "
   All Fields" mode

#### 3.0.3

 * 🎯 **Smart Field Matching** – Enhanced merge tag parser with intelligent field
   detection and normalization
 * **Field Aliases** – Automatic mapping for common field variations (phone = telephone/
   mobile/contact number)
 * **Special Character Support** – Properly handles ampersands, hyphens in field
   labels like "Name & Surname"
 * **Better Empty Handling** – Unmatched merge tags replaced with empty string instead
   of showing literal {FieldName}
 * **3-Tier Matching** – Exact match  Partial match  Alias-based matching for maximum
   compatibility
 * FIXED: Merge tags like {Phone} now properly match fields named "Contact Number","
   Telephone", "Mobile"
 * FIXED: Complex field labels with special characters (& – .) now match simple 
   merge tags

#### 3.0.2

 * FIXED: Webhook Edit/Delete buttons causing page reload – Added type="button" 
   attribute to prevent form submission
 * IMPROVED: Webhook management stability and user experience

#### 3.0.1

 * Enhanced save button styling with border accent
 * Simplified version management (removed unnecessary constant)
 * Improved code maintainability and deployment infrastructure
 * Updated changelog formatting for better readability

#### 3.0.0

 * Complete rewrite with modern architecture
 * Enhanced visual effects with improved logo glow and pulse animation
 * Fixed entry date merge tags to display actual submission timestamps
 * Improved field detection with smart label matching
 * Added email tracking for notification success monitoring
 * Enhanced merge tag parser for entry properties and UTM data
 * Modern glassmorphism UI design
 * Webhook management with intuitive inline editor

#### 2.3.3

**🔧 Critical Fixes + 🎨 Futuristic UI Upgrade**

• **FIXED: Entry Date Merge Tag** – Now properly displays actual submission timestamp
instead of literal text
 • **FIXED: Field Detection** – Use simple merge tags like{
Name}, {Email}, {Phone} instead of field IDs • **FIXED: Smart Field Matching** –
Intelligent partial matching for field labels (e.g., "Name & Surname" matches {Name})•**
NEW: Email Tracking** – Track if email notifications were successfully sent to client
inbox • **NEW: Email Data in Webhook** – Includes email_sent (boolean), email_count,
and email_notifications array • **NEW: Email Notification Details** – Shows recipient,
subject, timestamp, and success status for each email • **IMPROVED: Merge Tag Parser**–
Enhanced to recognize Entry Properties: {Entry Date}, {Entry ID}, {User IP}, {Source
URL}, {Form Title} • **IMPROVED: Field Label Support** – Use exact field names from
your forms – no more guessing field IDs! • **UI: Glassmorphism Design** – Beautiful
frosted glass effect with backdrop blur on all containers • **UI: Animated Glow 
Effects** – Pulsing borders and glow animations on active webhooks • **UI: Shimmer
Animations** – Sweeping light effects across containers • **UI: Floating Logo** –
Animated logo with glow drop shadow • **UI: Gradient Buttons** – Enhanced buttons
with hover shine effects and smooth transitions • **UI: In-Form Help** – Added helpful
merge tag documentation directly in the webhook editor • **UI: Enhanced Shadows**–
Improved depth with multi-layer shadows and lighting effects • **UI: Smooth Transitions**–
Cubic-bezier easing for professional animations

**Available Merge Tags:**
 – **Entry Properties:** {Entry Date}, {Entry ID}, {User
IP}, {Source URL}, {Form Title} – **Field Names:** {Name}, {Email}, {Phone}, {Surname},{
Message} – use any field label from your form! – **UTM Parameters:** {utm_source},{
utm_campaign}, {utm_medium}, {utm_term}, {gclid}, {referrer}, {gbraid}, {wbraid}

**Email Tracking Example:**
 `json { "email_sent": true, "email_count": 2, "email_notifications":[{"
success": true, "to": "client@example.com", "subject": "New Form Submission", "timestamp":"
2026-02-12 14:30:00" } ] }

#### 3.0.0

**🚀 WEBHOOK MANAGEMENT REVOLUTION – Complete Gravity Forms Webhook Replacement**

• **NEW: Custom Webhook Builder** – Replace Gravity Forms webhook add-on with unlimited
custom webhooks
 • **NEW: Merge Tag Support** – Full Gravity Forms merge tag integration({
Name:1}, {Email:6}, {entry_id}, etc.) • **NEW: Dynamic Field Mapping** – Select 
specific fields or send all form data automatically • **NEW: Two-Column Dashboard**–
Professional layout with settings on left, webhooks on right • **NEW: Unlimited 
Webhooks** – Add as many webhooks as needed for each form submission • **NEW: Request
Method Selection** – Support for GET, POST, PUT, PATCH, DELETE methods • **NEW: 
Individual Webhook Toggle** – Enable/disable webhooks without deleting configuration•**
NEW: In-Place Editing** – Edit webhook configurations inline with smooth animations•**
NEW: BaseCloud Logo** – Professional branding with icon instead of Lottie animation•**
IMPROVED: Webhook System** – Complete webhook management replaces need for Gravity
Forms webhook add-on • **IMPROVED: UTM Injection** – All custom webhooks automatically
include UTM parameters • **IMPROVED: UI/UX** – Wider layout (1400px) with responsive
grid design • **REMOVED: Denied Webhooks** – Exclusion list removed in favor of 
individual webhook control

**Webhook Features:**
 – Unlimited custom webhooks per installation – Full Gravity
Forms merge tag support – All Fields or Select Fields body options – Automatic UTM
parameter injection – GET, POST, PUT, PATCH, DELETE methods – JSON request format–
Enable/disable individual webhooks – In-place editing with live preview

**Supported Merge Tags:**
 {FieldLabel:ID}, {entry_id}, {entry_date}, {form_id},{
form_title}, {utm_source}, {utm_campaign}, {gclid}, {referrer}, and more!

**Breaking Changes:** None – Fully backward compatible with v2.x

#### 2.3.3

**Lottie Logo Fix**

• Fixed Lottie player script loading order to display logo properly
 • Changed script
loading from footer to header for immediate availability • Resolved warning icon
display issue on page load

#### 2.3.2

**Animated Logo Addition**

• Added animated BaseCloud Lottie logo to settings page header
 • Enhanced brand
presence with looping logo animation • Improved visual consistency with BaseCloud
brand identity

#### 2.3.1

**API Endpoint Update**

• **UPDATED: Default Webhook URL** – Migrated from legacy portal.basecloudglobal.
com to new api.basecloudglobal.com endpoint
 • **IMPROVED: URL Format** – New webhook
URLs use /webhook/ path structure for better API organization • **ENHANCED: Security**–
Updated default excluded webhook to new API endpoint (https://api.basecloudglobal.
com/webhook/92b3163196af061b6d009264) • **BACKWARD COMPATIBLE** – No impact on existing
installations or custom excluded URLs

**Technical Changes:**
 • Default denied URL updated to api.basecloudglobal.com 
domain • Activation hook updated with new default webhook URL • Maintained full 
backward compatibility with existing configurations

#### 2.3.0

**🎨 DARK THEME UI REDESIGN – BaseCloud Branding**

• **NEW: Dark Theme Interface** – Complete UI redesign with navy blue (#0f2c52) 
background and green (#4bc46a) accents
 • **NEW: Toggle Switches** – Modern toggle
switches replace checkboxes for cleaner interface • **NEW: Gradient Effects** – 
Beautiful gradient borders and hover effects throughout • **ENHANCED: BaseCloud 
Branding** – Professional color scheme matching BaseCloud Global identity • **IMPROVED:
Status Indicators** – Pulsing green status dots for active systems • **ADDED: Dark
Cards** – Settings sections now use elegant dark cards with subtle shadows • **REDESIGNED:
Button Styling** – Primary green buttons with hover effects and shadows • **UPDATED:
Typography** – Improved font hierarchy with better contrast on dark background •**
OPTIMIZED: Visual Hierarchy** – Better spacing and organization for improved UX •**
POLISHED: Animations** – Smooth transitions and hover effects for modern feel

**Design Elements:**
 • CSS variables for consistent theming (–bc-bg, –bc-card, –
bc-green, –bc-border) • Gradient borders on cards and input fields • Box shadows
for depth and dimension • Pulsing animations for status indicators • Modern toggle
switch component with smooth transitions

**Breaking Changes:**
 • None – fully backward compatible with v2.2.0

#### 2.2.0

**🚀 THE "BIG 4″ FORM AUTOMATOR – Multi-Plugin Support**

• **NEW: Elementor Pro Integration** – Automatic webhook injection for Elementor
forms
 • **NEW: WPForms Integration** – Complete webhook automation for WPForms •**
NEW: Contact Form 7 Integration** – Classic form plugin support with data injection•**
CRITICAL: Async Webhook Support** – Fixed Gravity Forms background processing (Priority
1 save) • **ENHANCED: Database Storage** – UTM data now saved to database BEFORE
async webhook queue • **IMPROVED: Multi-Plugin Dashboard** – Real-time status for
all 4 form plugins • **FIXED: Cookie Availability in Async** – Reads from database
when cookies unavailable • **ADDED: Form Plugin Detection** – Automatic detection
of installed form plugins • **OPTIMIZED: Webhook Injection Logic** – Universal injection
method for all form types • **UPDATED: Settings Panel** – Individual toggles for
each form plugin integration

**Technical Improvements:**
 • Priority 1 execution for `gform_after_submission`(
runs before async queue at Priority 10) • Force database read in `inject_gf_webhook`
for reliable async operation • Added `is_url_denied()` helper method for cleaner
deny list checking • Support for JSON and array body formats in webhooks • Elementor
filter: `elementor_pro/forms/webhook/request_args` • WPForms filter: `wpforms_webhooks_request_args`•
CF7 filter: `wpcf7_posted_data`

**Breaking Changes:**
 • None – fully backward compatible with v2.0.0

#### 2.0.0

**🚀 GAME CHANGER: Complete Automation Revolution**

• **NEW: THE COURIER System** – Automatic UTM injection into Gravity Forms webhooks–
NO manual fields needed!
 • **NEW: THE COLLECTOR System** – Advanced cookie-based
tracking engine with enhanced reliability • **NEW: Animated Dashboard** – Real-time
system diagnostics with smooth animations and status indicators • **NEW: Entry Meta
Storage** – UTM data automatically saved with each Gravity Forms submission • **
NEW: Excluded Webhooks** – Configure specific webhook URLs to bypass UTM injection•**
NEW: System Health Monitor** – Live COLLECTOR and COURIER status with animated feedback•**
ENHANCED: iOS 14+ Support** – Full gbraid and wbraid parameter tracking for Apple
privacy • **IMPROVED: Zero Configuration** – Works automatically after activation–
no setup required • **ADDED: Webhook Automation** – All 8 parameters auto-injected
into webhook payloads • **REDESIGNED: Modern UI** – Beautiful gradient designs, 
hover effects, and smooth transitions • **REMOVED: Manual Field Creation** – No 
longer needed! COURIER handles everything automatically • **OPTIMIZED: Performance**–
Streamlined code for faster page loads • **UPDATED: Cookie Names** – Standardized
naming (removed bc_ prefix) for better CRM compatibility

**Breaking Changes:**
 • Removed auto_create_fields option (no longer needed with
COURIER system) • Removed tracked_parameters option (all 8 parameters now tracked
by default) • Changed gclid cookie from bc_gclid to gclid for CRM compatibility

#### 1.2.2

**Enhanced Secret Sauce – CRM/Webhook Integration Update**

• **NEW: Google Brand Engagement Tracking** – Added gbraid and wbraid parameters
for iOS 14+ tracking
 • **IMPROVED: GCLID Cookie Naming** – Changed from bc_gclid
to gclid for better CRM/webhook compatibility • **ENHANCED: Field Population** –
Streamlined secret sauce code with optimized field population • **UPDATED: Default
Parameters** – Now includes referrer, utm_source, utm_medium, utm_campaign, utm_term,
gclid, gbraid, wbraid • **IMPROVED: Event Triggering** – Added input and change 
events for better form integration • **OPTIMIZED: Label-Based Population** – Streamlined
field detection for text fields set to hidden visibility • **ENHANCED: Popup Integration**–
Improved Elementor popup support with better event handling

#### 1.2.1

**🔧 Critical Gravity Forms Integration Fix**

• **FIXED: Proper Field Creation** – Auto-created fields now use text fields with
hidden visibility (WordPress best practice)
 • **NEW: Server-Side Population** –
Added reliable server-side field population using Gravity Forms filters • **IMPROVED:
Dynamic Population** – Fields now properly support "Allow field to be populated 
dynamically" setting • **ENHANCED: Parameter Name Support** – Correct parameter 
names (gclid, utm_source, etc.) for dynamic population • **ADDED: Triple Population
Method** – Server-side + parameter matching + label fallback for 100% reliability•**
FIXED: Field Detection** – Smart field detection prevents overwriting existing data•**
IMPROVED: Form Compatibility** – Better compatibility with all Gravity Forms features
and add-ons

#### 1.2.0

**🚀 Major Feature Release – Enhanced Tracking & Automation**

• **NEW: Referrer Tracking** – Automatically captures and stores the previous page
URL (document.referrer)
 • **NEW: Auto-Create Hidden Fields** – Automatically adds
UTM hidden fields to new Gravity Forms • **Enhanced JavaScript Engine** – Improved"
secret sauce" code with modern ES6 features • **Smart Cookie Logic** – Only sets
cookies if they don’t exist, preventing data overwriting • **Advanced Popup Support**–
Enhanced integration with Elementor and other page builders • **Automatic Field 
Detection** – Intelligent field creation with duplicate prevention • **Form-Level
Settings** – Per-form control for UTM field creation in Gravity Forms admin • **
Updated Default Parameters** – Now includes referrer tracking by default • **Improved
Field Population** – Better support for multiple forms and popup scenarios • **Enhanced
Admin UI** – Added referrer field to the field reference guide

#### 1.1.6

**Major UI Enhancement**

• Modern dashboard layout with real-time status indicators
 • Enhanced admin interface
with responsive grid design • Added visual status cards showing tracking configuration
at-a-glance • Improved success messages and user feedback • Professional styling
with better visual hierarchy • Enhanced field reference guide with color-coded categories•
Added quick stats display for cookie duration and integrations • Mobile-responsive
admin interface • Better documentation integration and support links

#### 1.1.5

**Release Update**

• Bug fixes and improvements
 • Updated version for deployment

#### 1.1.4

**Release Update**

• Bug fixes and improvements
 • Updated version for deployment

#### 1.1.3

**GitHub Actions Deployment Trigger**

• Re-triggered automated deployment to WordPress.org
 • Ensure assets are properly
deployed via GitHub Actions • Force deployment pipeline activation • Test automated
SVN commit process

#### 1.1.2

**Assets and Deployment Fix**

• Added GitHub Actions workflow for automated WordPress.org deployment
 • Corrected
asset filenames to meet WordPress.org requirements • Fixed plugin branding assets(
banners and icons) • Established automated deployment pipeline matching Security
Manager

#### 1.1.1

**Deployment System Enhancement**

• Updated deployment script to use Git-based approach
 • Removed SVN dependencies
for cleaner deployment process • Added plugin network compatibility information •
Improved deployment workflow matching Security Manager

#### 1.1.0

**Admin Interface Enhancement**

• Updated admin menu title from "UTM Tracker" to "UTM Analytics"
 • Enhanced admin
interface terminology for better clarity • Improved user experience in WordPress
dashboard navigation • Minor version bump for interface improvements

#### 1.0.3

**Description Enhancement**

• Enhanced plugin description with improved clarity
 • Added emphasis on secure 
cookie storage • Improved analytics terminology for better user understanding • 
Minor text improvements for professional presentation

#### 1.0.2

**Assets Update**

 * Added professional plugin assets (banners and icons)
 * Enhanced WordPress.org directory presentation
 * Improved plugin branding and visual identity
 * Updated deployment workflow for assets

#### 1.0.1

**Minor Update & Testing**

 * Improved GitHub repository integration and documentation
 * Enhanced deployment workflow testing
 * Minor code optimizations for better performance
 * Updated repository links and branding consistency

#### 1.0.0

**Initial Release**

 * Complete UTM parameter tracking system
 * Gravity Forms integration for automatic field population
 * Configurable cookie duration (1-365 days)
 * Custom parameter tracking support
 * Professional admin interface with BaseCloud branding
 * HTTPS and security best practices
 * WordPress coding standards compliance
 * Translation ready

## Meta

 *  Version **4.4.0**
 *  Last updated **hace 1 día**
 *  Active installations **90+**
 *  WordPress version ** 5.0 o superior **
 *  Tested up to **7.1.2**
 *  PHP version ** 7.4 o superior **
 *  Language
 * [English (US)](https://wordpress.org/plugins/basecloud-utm-tracker/)
 * Tags
 * [analytics](https://es-do.wordpress.org/plugins/tags/analytics/)[forms](https://es-do.wordpress.org/plugins/tags/forms/)
   [marketing](https://es-do.wordpress.org/plugins/tags/marketing/)[tracking](https://es-do.wordpress.org/plugins/tags/tracking/)
   [UTM](https://es-do.wordpress.org/plugins/tags/utm/)
 *  [Vista avanzada](https://es-do.wordpress.org/plugins/basecloud-utm-tracker/advanced/)

## Valoraciones

 5 out of 5 stars.

 *  [  2 5-star reviews     ](https://wordpress.org/support/plugin/basecloud-utm-tracker/reviews/?filter=5)
 *  [  0 4-star reviews     ](https://wordpress.org/support/plugin/basecloud-utm-tracker/reviews/?filter=4)
 *  [  0 3-star reviews     ](https://wordpress.org/support/plugin/basecloud-utm-tracker/reviews/?filter=3)
 *  [  0 2-star reviews     ](https://wordpress.org/support/plugin/basecloud-utm-tracker/reviews/?filter=2)
 *  [  0 1-star reviews     ](https://wordpress.org/support/plugin/basecloud-utm-tracker/reviews/?filter=1)

[Your review](https://wordpress.org/support/plugin/basecloud-utm-tracker/reviews/#new-post)

[See all reviews](https://wordpress.org/support/plugin/basecloud-utm-tracker/reviews/)

## Colaboradores

 *   [ BaseCloud ](https://profiles.wordpress.org/basecloud/)

## Soporte

¿Tienes algo que decir? ¿Necesitas ayuda?

 [Ver el foro de soporte](https://wordpress.org/support/plugin/basecloud-utm-tracker/)