{"id":248935,"date":"2025-09-16T06:04:26","date_gmt":"2025-09-16T06:04:26","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/basecloud-utm-tracker\/"},"modified":"2026-09-23T14:11:30","modified_gmt":"2026-09-23T14:11:30","slug":"basecloud-utm-tracker","status":"publish","type":"plugin","link":"https:\/\/es-do.wordpress.org\/plugins\/basecloud-utm-tracker\/","author":23342161,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"4.4.0","stable_tag":"4.4.0","tested":"7.1.2","requires":"5.0","requires_php":"7.4","requires_plugins":null,"header_name":"BaseCloud UTM Tracker","header_author":"BaseCloud Team","header_description":"Track UTM parameters and GCLID from marketing campaigns. Automatically stores UTM data in cookies and populates Gravity Forms fields for better campaign attribution and lead tracking.","assets_banners_color":"3d5b7b","last_updated":"2026-09-23 14:11:30","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"https:\/\/www.basecloudglobal.com\/plugins\/utm-tracker","header_author_uri":"https:\/\/www.basecloudglobal.com\/","rating":5,"author_block_rating":0,"active_installs":100,"downloads":2035,"num_ratings":2,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"1.0.0":{"tag":"1.0.0","author":"basecloud","date":"2025-09-16 06:04:49","revision":3362224},"1.0.1":{"tag":"1.0.1","author":"basecloud","date":"2025-09-16 06:49:59","revision":3362244},"1.1.2":{"tag":"1.1.2","author":"basecloud","date":"2025-10-09 09:46:59","revision":3375614},"1.1.3":{"tag":"1.1.3","author":"basecloud","date":"2025-10-09 09:57:47","revision":3375628},"1.1.4":{"tag":"1.1.4","author":"basecloud","date":"2025-10-09 13:26:03","revision":3375762},"1.1.5":{"tag":"1.1.5","author":"basecloud","date":"2025-10-09 15:27:18","revision":3375855},"1.1.6":{"tag":"1.1.6","author":"basecloud","date":"2025-11-04 20:43:32","revision":3389962},"1.2.0":{"tag":"1.2.0","author":"basecloud","date":"2025-11-04 20:56:45","revision":3389969},"1.2.1":{"tag":"1.2.1","author":"basecloud","date":"2025-11-04 21:18:07","revision":3389980},"1.2.2":{"tag":"1.2.2","author":"basecloud","date":"2025-11-24 15:15:31","revision":3401960},"2.0.0":{"tag":"2.0.0","author":"basecloud","date":"2025-11-26 21:43:28","revision":3403672},"2.2.0":{"tag":"2.2.0","author":"basecloud","date":"2025-11-26 22:19:42","revision":3403676},"2.3.0":{"tag":"2.3.0","author":"basecloud","date":"2025-11-26 22:29:13","revision":3403682},"2.3.1":{"tag":"2.3.1","author":"basecloud","date":"2026-01-12 16:48:44","revision":3437959},"2.3.2":{"tag":"2.3.2","author":"basecloud","date":"2026-01-19 10:24:49","revision":3442413},"2.3.3":{"tag":"2.3.3","author":"basecloud","date":"2026-01-19 10:34:06","revision":3442422},"3.0.0":{"tag":"3.0.0","author":"basecloud","date":"2026-02-12 10:20:56","revision":3459784},"3.0.1":{"tag":"3.0.1","author":"basecloud","date":"2026-02-12 14:14:58","revision":3460013},"3.0.2":{"tag":"3.0.2","author":"basecloud","date":"2026-02-12 14:24:44","revision":3460030},"3.0.3":{"tag":"3.0.3","author":"basecloud","date":"2026-02-12 15:14:37","revision":3460077},"3.0.4":{"tag":"3.0.4","author":"basecloud","date":"2026-06-15 13:35:06","revision":3573228},"4.0.0":{"tag":"4.0.0","author":"basecloud","date":"2026-06-15 13:59:38","revision":3573258},"4.1.0":{"tag":"4.1.0","author":"basecloud","date":"2026-06-18 06:59:41","revision":3576694},"4.1.1":{"tag":"4.1.1","author":"basecloud","date":"2026-06-18 07:26:34","revision":3576727},"4.1.2":{"tag":"4.1.2","author":"basecloud","date":"2026-06-18 07:37:16","revision":3576740},"4.2.0":{"tag":"4.2.0","author":"basecloud","date":"2026-09-11 07:38:05","revision":3690993},"4.3.0":{"tag":"4.3.0","author":"basecloud","date":"2026-09-14 09:53:15","revision":3694923},"4.4.0":{"tag":"4.4.0","author":"basecloud","date":"2026-09-23 14:11:30","revision":3709482}},"upgrade_notice":{"4.4.0":"<p>Visit counting and the BaseCloud Forms bridge are ON by default, also on sites already running the Blog Post Conversion Tracker (switch off under Tracker). Adds WhatsApp and call tracking, keyword insights and a &quot;How it works&quot; guide. Purge your page cache after updating.<\/p>","4.3.0":"<p>Adds search keywords, AI visibility and reports to the Blog Post Conversion Tracker (all off by default). The UTM tracker and conversion webhooks are unchanged apart from new channel labels.<\/p>","4.2.0":"<p>Adds the Blog Post Conversion Tracker tab (off by default). The UTM tracker, its cookies and its webhooks are unchanged.<\/p>","1.0.0":"<p>Initial release of BaseCloud UTM Tracker. Install now to start tracking your marketing campaign performance!<\/p>"},"ratings":{"1":0,"2":0,"3":0,"4":0,"5":2},"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3375855,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3375855,"resolution":"256x256","location":"assets","locale":"","width":257,"height":256}},"assets_banners":{"banner-1544x500.jpg":{"filename":"banner-1544x500.jpg","revision":3375855,"resolution":"1544x500","location":"assets","locale":"","width":1545,"height":501},"banner-772x250.jpg":{"filename":"banner-772x250.jpg","revision":3375855,"resolution":"772x250","location":"assets","locale":"","width":773,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["1.0.0","1.0.1","1.1.2","1.1.3","1.1.4","1.1.5","1.1.6","1.2.0","1.2.1","1.2.2","2.0.0","2.2.0","2.3.0","2.3.1","2.3.2","2.3.3","3.0.0","3.0.1","3.0.2","3.0.3","3.0.4","4.0.0","4.1.0","4.1.1","4.1.2","4.2.0","4.3.0","4.4.0"],"block_files":[],"assets_screenshots":[],"screenshots":{"1":"<strong>Plugin Settings<\/strong> - Clean, professional admin interface for configuring UTM tracking","2":"<strong>Gravity Forms Integration<\/strong> - UTM data automatically populates form fields","3":"<strong>Dashboard Menu<\/strong> - Easy access with custom BaseCloud branding","4":"<strong>Cookie Storage<\/strong> - Secure storage of UTM parameters for attribution"}},"plugin_section":[],"plugin_tags":[232,601,456,550,24188],"plugin_category":[36,55],"plugin_contributors":[246295],"plugin_business_model":[],"class_list":["post-248935","plugin","type-plugin","status-publish","hentry","plugin_tags-analytics","plugin_tags-forms","plugin_tags-marketing","plugin_tags-tracking","plugin_tags-utm","plugin_category-analytics","plugin_category-seo-and-marketing","plugin_contributors-basecloud","plugin_committers-basecloud"],"banners":{"banner":"https:\/\/ps.w.org\/basecloud-utm-tracker\/assets\/banner-772x250.jpg?rev=3375855","banner_2x":"https:\/\/ps.w.org\/basecloud-utm-tracker\/assets\/banner-1544x500.jpg?rev=3375855","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/basecloud-utm-tracker\/assets\/icon-128x128.png?rev=3375855","icon_2x":"https:\/\/ps.w.org\/basecloud-utm-tracker\/assets\/icon-256x256.png?rev=3375855","generated":false},"screenshots":[],"raw_content":"<!--section=description-->\n<p><strong>BaseCloud UTM Tracker<\/strong> is the ultimate UTM tracking and webhook management solution for WordPress. Replace Gravity Forms webhook add-on with unlimited custom webhooks, full merge tag support, and automatic UTM injection for the \"Big 4\" form plugins.<\/p>\n\n<h4>NEW in 4.4: visits, leads beyond Gravity Forms and keyword insights<\/h4>\n\n<p>Everything new is part of the Blog Post Conversion Tracker. Visit counting and the BaseCloud Forms bridge are on by default while the tracker is on, also on sites that already use it, so they start after the update without any action (both are first-party, follow the tracker's consent setting and can be switched off in the Tracker section). Every other new feature is off until you switch it on. The UTM tracker is unchanged apart from two fixes (see the changelog).<\/p>\n\n<ul>\n<li><strong>Visits and channels<\/strong> - first-party visit counts per landing page and channel (search, social, AI assistants, email, paid, campaign, referral, direct), conversion rates per channel, and an organic comparison of plugin visits, Search Console clicks and, optionally, Google Analytics 4 sessions, with the likely reason for each gap.<\/li>\n<li><strong>BaseCloud Forms bridge<\/strong> - BaseCloud CRM forms embedded on your pages receive the visitor's source, landing page and journey as extra fields, and confirmed submissions are recorded as leads.<\/li>\n<li><strong>WhatsApp and call tracking<\/strong> - a reference code in the pre-filled WhatsApp message, WhatsApp and phone clicks recorded with their journey, an inbound API that lets your CRM, WATI or phone provider (for example Twilio) match chats and calls back to the visit, and tracking numbers per source or from a per-visitor pool.<\/li>\n<li><strong>Keyword insights<\/strong> - Search Console rhythm by weekday and month, brand and non-brand searches separately, the searches each page really appears for next to its focus keyphrase, striking-distance queries, pages competing for the same query, and suspected automated queries set aside.<\/li>\n<li><strong>AI visibility<\/strong> - AI crawler hits split into training, search index and user-triggered fetches, human visits from AI assistants, and the missing pages AI crawlers ask for.<\/li>\n<li><strong>How it works<\/strong> - a guide inside the plugin that explains where every number comes from and how accurate it is, with a live setup checklist.<\/li>\n<li><strong>Reports<\/strong> now include traffic, leads and Search Console insights.<\/li>\n<\/ul>\n\n<h4>NEW in 4.3: search keywords, AI visibility and reports<\/h4>\n\n<p>Everything new is part of the Blog Post Conversion Tracker and is off by default. The UTM tracker is unchanged.<\/p>\n\n<ul>\n<li><strong>Search keywords<\/strong> - connect Google Search Console with a service account to see the queries that sent clicks to the landing page of each organic Google conversion, flagged against your target keywords (read from Yoast SEO, Rank Math, All in One SEO and SEOPress, plus your own list). These are the likely keywords, not the visitor's exact search: Google does not share that, and Search Console data is 2-3 days behind.<\/li>\n<li><strong>AI visibility<\/strong> - conversions referred by AI assistants (ChatGPT, Perplexity, Gemini, Copilot, Claude and others), an AI crawler log per page with optional IP verification, a robots.txt check for AI crawlers, an llms.txt generator, and AI answer citations from the Ahrefs API.<\/li>\n<li><strong>Reports<\/strong> - daily, weekly, monthly and half-yearly JSON reports of your best converting posts, channels, forms, keywords and AI visibility, sent to report webhooks with an optional PDF attachment, plus previews and PDF downloads for any date range.<\/li>\n<li><strong>Secure by design<\/strong> - API keys, service account keys and report webhook URLs are encrypted and write-only, requests go only to fixed service hosts or validated https webhooks, and reports contain no personal data.<\/li>\n<\/ul>\n\n<h4>NEW in 4.2: Blog Post Conversion Tracker<\/h4>\n\n<p>See which blog post a visitor was reading right before they filled in your Gravity Form. Turn it on under <strong>UTM Tracker &gt; Blog Post Conversion Tracker<\/strong> (it is off by default).<\/p>\n\n<ul>\n<li><strong>Journey tracking<\/strong> - the browser keeps first and last touch, the first and last post read and the most recent pages in localStorage, with a compact first-party cookie (<code>bc_blog_attr<\/code>, under 2 KB) as a backup. Gravity Forms submissions carry the full journey in a hidden field. Cache-safe, size-safe and consent-aware (Google Consent Mode regions respected).<\/li>\n<li><strong>Entry columns<\/strong> - \"Blog: Converted From Post\" (Yes, Yes (unverified) or No) and \"Blog: Source Post\" on Gravity Forms entries, plus minutes to convert, same visit, pages viewed after the post and an optional attribution window.<\/li>\n<li><strong>Clean webhooks<\/strong> - a readable JSON payload (form, entry, contact, fields, conversion, visitor, journey) with ISO 8601 times, sent after the visitor's response so forms stay fast. UTM parameters are left to the UTM tracker.<\/li>\n<li><strong>Secure by design<\/strong> - webhook URLs and secrets are encrypted (AES-256-GCM, with an optional <code>BASECLOUD_BPCT_KEY<\/code> constant), HTTPS only with private-network blocking, never shown again after saving, and requests can be HMAC-signed.<\/li>\n<li><strong>Top Converting Posts<\/strong> and recent conversions in the dashboard.<\/li>\n<li>Fully separate from the UTM tracker: its settings, cookies and webhooks are untouched. Deleting the plugin removes only the Blog Post Conversion Tracker data.<\/li>\n<\/ul>\n\n<h4>\ud83c\udfaf THE COLLECTOR: Advanced Cookie Tracking<\/h4>\n\n<p>Automatically captures and stores UTM parameters from your marketing campaigns in secure, persistent cookies.<\/p>\n\n<h4>\ud83d\udce6 THE COURIER: Automated Webhook Injection<\/h4>\n\n<p><strong>Game Changer!<\/strong> Automatically injects UTM data into ALL form webhook submissions - works with Gravity Forms, Elementor Pro, WPForms, and Contact Form 7!<\/p>\n\n<h4>The \"Big 4\" Form Support<\/h4>\n\n<ul>\n<li><strong>Gravity Forms<\/strong> - Full integration with async webhook support<\/li>\n<li><strong>Elementor Pro Forms<\/strong> - Webhook injection for page builder forms<\/li>\n<li><strong>WPForms<\/strong> - Complete webhook automation<\/li>\n<li><strong>Contact Form 7<\/strong> - Classic form plugin support<\/li>\n<\/ul>\n\n<h4>Key Features<\/h4>\n\n<ul>\n<li><strong>\ud83d\ude80 Zero Manual Configuration<\/strong> - Works automatically after activation<\/li>\n<li><strong>\ud83c\udfaf COLLECTOR System<\/strong> - Advanced cookie-based tracking for 8 parameters<\/li>\n<li><strong>\ud83d\udce6 COURIER System<\/strong> - Automatic webhook injection for all major form plugins<\/li>\n<li><strong>\u26a1 Async Webhook Support<\/strong> - Works with background processing (critical for Gravity Forms)<\/li>\n<li><strong>\ud83d\udd04 Real-Time Diagnostics<\/strong> - Animated status dashboard shows system health<\/li>\n<li><strong>\ud83d\udcca Entry Meta Storage<\/strong> - UTM data saved with each Gravity Forms submission<\/li>\n<li><strong>\ud83c\udfa8 Beautiful Dashboard<\/strong> - Modern, animated interface with live status indicators<\/li>\n<li><strong>\ud83d\udd12 Privacy Compliant<\/strong> - Secure cookies with proper SameSite and HTTPS support<\/li>\n<li><strong>\ud83d\udcf1 iOS 14+ Support<\/strong> - Tracks gbraid and wbraid for enhanced Apple privacy tracking<\/li>\n<\/ul>\n\n<h4>Tracked Parameters (8 Total)<\/h4>\n\n<ol>\n<li><strong>referrer<\/strong> - Previous page URL<\/li>\n<li><strong>utm_source<\/strong> - Campaign source (Google, Facebook, etc.)<\/li>\n<li><strong>utm_medium<\/strong> - Marketing medium (CPC, email, social)<\/li>\n<li><strong>utm_campaign<\/strong> - Campaign name<\/li>\n<li><strong>utm_term<\/strong> - Campaign keywords<\/li>\n<li><strong>gclid<\/strong> - Google Click ID<\/li>\n<li><strong>gbraid<\/strong> - Google Brand Engagement (iOS 14+)<\/li>\n<li><strong>wbraid<\/strong> - Web to App Brand Engagement (iOS 14+)<\/li>\n<\/ol>\n\n<h4>How THE COURIER Works<\/h4>\n\n<ol>\n<li>Visitor arrives with UTM parameters in URL<\/li>\n<li>COLLECTOR captures and stores data in cookies<\/li>\n<li>Visitor submits a Gravity Form<\/li>\n<li>COURIER automatically injects all UTM data into webhook payload<\/li>\n<li>Your CRM receives complete attribution data - automatically!<\/li>\n<\/ol>\n\n<h4>Perfect For<\/h4>\n\n<ul>\n<li><strong>Digital Marketing Agencies<\/strong> - Complete campaign attribution without manual setup<\/li>\n<li><strong>E-commerce Sites<\/strong> - Track ROI from every marketing channel<\/li>\n<li><strong>Lead Generation<\/strong> - Automatic UTM data in your CRM<\/li>\n<li><strong>SaaS Companies<\/strong> - Understand customer acquisition sources<\/li>\n<li><strong>PPC Campaigns<\/strong> - Full Google Ads and Facebook Ads tracking<\/li>\n<\/ul>\n\n<h4>What's NEW in v2.0.0?<\/h4>\n\n<ul>\n<li>\ud83c\udfaf <strong>COLLECTOR System<\/strong> - Advanced cookie tracking engine<\/li>\n<li>\ud83d\udce6 <strong>COURIER System<\/strong> - Automatic webhook injection (no manual fields!)<\/li>\n<li>\ud83c\udfa8 <strong>Animated Dashboard<\/strong> - Real-time system diagnostics with animations<\/li>\n<li>\ud83d\udcca <strong>Entry Meta Storage<\/strong> - UTM data saved with each form submission<\/li>\n<li>\ud83d\udd27 <strong>Excluded Webhooks<\/strong> - Option to exclude specific webhook URLs<\/li>\n<li>\u2728 <strong>iOS 14+ Support<\/strong> - gbraid and wbraid parameter tracking<\/li>\n<li>\ud83d\ude80 <strong>Zero Configuration<\/strong> - Works automatically after activation<\/li>\n<\/ul>\n\n<h4>Gravity Forms Integration (THE COURIER)<\/h4>\n\n<p><strong>\ud83d\ude80 No Manual Field Creation Required!<\/strong><\/p>\n\n<p>The COURIER system automatically injects all UTM data into Gravity Forms webhook submissions. Simply:<\/p>\n\n<ol>\n<li>Enable \"Gravity Forms Integration\" in plugin settings<\/li>\n<li>Set up your Gravity Forms webhooks as normal<\/li>\n<li>The COURIER automatically adds UTM data to every webhook request<\/li>\n<\/ol>\n\n<p><strong>Optional:<\/strong> You can still create visible fields with parameter names (referrer, utm_source, etc.) if you want users to see the data. The COLLECTOR will populate them automatically.<\/p>\n\n<p><strong>Excluded Webhooks:<\/strong> Configure specific webhook URLs to exclude from UTM injection (useful for internal notifications).<\/p>\n\n<h4>Technical Features<\/h4>\n\n<ul>\n<li><strong>Lightweight<\/strong> - Minimal impact on site performance<\/li>\n<li><strong>Standards Compliant<\/strong> - Follows WordPress coding standards<\/li>\n<li><strong>Secure<\/strong> - Proper data sanitization and validation<\/li>\n<li><strong>Translatable<\/strong> - Ready for internationalization<\/li>\n<li><strong>Mobile Friendly<\/strong> - Works across all devices and browsers<\/li>\n<li><strong>Entry Meta Storage<\/strong> - UTM data stored with each Gravity Forms entry<\/li>\n<li><strong>Webhook Automation<\/strong> - Zero configuration webhook injection<\/li>\n<li><strong>Animated UI<\/strong> - Real-time system status with smooth animations<\/li>\n<\/ul>\n\n<h4>Use Cases<\/h4>\n\n<p><strong>Marketing Attribution<\/strong>: Track which campaigns generate the most leads and sales - automatically!<\/p>\n\n<p><strong>CRM Integration<\/strong>: UTM data flows seamlessly to your CRM via Gravity Forms webhooks.<\/p>\n\n<p><strong>A\/B Testing<\/strong>: Compare performance between different campaign variations.<\/p>\n\n<p><strong>ROI Analysis<\/strong>: Calculate return on investment for different marketing channels.<\/p>\n\n<p><strong>Customer Journey<\/strong>: Understand how visitors discover and interact with your site.<\/p>\n\n<h3>External services<\/h3>\n\n<p>The plugin's server never sends data to BaseCloud. The services below are contacted only when you switch the related Blog Post Conversion Tracker feature on and save the credentials it needs. Conversion, lead and report webhooks send data only to the https URLs you enter yourself. The inbound API for chats and calls only receives requests; it contacts no one.<\/p>\n\n<h4>Google OAuth 2.0 and Google Search Console API<\/h4>\n\n<p>Used by Search keywords to read Search Console query data for your own site.<\/p>\n\n<ul>\n<li>Hosts: <code>oauth2.googleapis.com<\/code> (access token) and <code>www.googleapis.com<\/code> (Search Console API).<\/li>\n<li>When: only while Search keywords is enabled and a service account key is saved: the initial backfill of your Search Console history runs about every 5 minutes until it is complete, then a daily sync, plus \"Test connection\" and \"Sync now\".<\/li>\n<li>Data sent: a JWT signed with your service account key (the service account email and a read-only scope) and the Search Console property with date ranges. Data received: query, page, click and impression rows. No visitor data is sent.<\/li>\n<li>Google APIs Terms of Service: https:\/\/developers.google.com\/terms<\/li>\n<li>Google Privacy Policy: https:\/\/policies.google.com\/privacy<\/li>\n<\/ul>\n\n<h4>Google Analytics Data API (optional)<\/h4>\n\n<p>Used by the organic comparison to read Google Analytics 4 sessions per landing page.<\/p>\n\n<ul>\n<li>Hosts: <code>oauth2.googleapis.com<\/code> (access token) and <code>analyticsdata.googleapis.com<\/code> (GA4 Data API).<\/li>\n<li>When: only while GA4 is switched on in the Search keywords section and a service account key is saved: a daily report, plus \"Test connection\".<\/li>\n<li>Data sent: a JWT signed with your service account key (the service account email and the read-only <code>analytics.readonly<\/code> scope) and the GA4 property ID with a date range. Data received: sessions per landing page and channel group, and sessions from AI assistant sources. No visitor data is sent.<\/li>\n<li>Google APIs Terms of Service: https:\/\/developers.google.com\/terms<\/li>\n<li>Google Privacy Policy: https:\/\/policies.google.com\/privacy<\/li>\n<\/ul>\n\n<h4>BaseCloud CRM forms (BaseCloud Forms bridge)<\/h4>\n\n<p>The plugin's server does not contact BaseCloud. When your pages embed BaseCloud CRM forms, each form sends its submissions from the visitor's browser to your BaseCloud CRM at <code>api.basecloudglobal.com<\/code>. While the tracker and the bridge are on, the plugin adds the attribution fields listed under \"What is sent to BaseCloud Forms?\" to that request. Nothing is added on pages without a BaseCloud form, when the bridge is switched off, or before consent when consent mode is on. The allowed CRM hosts can be changed in the Tracker section.<\/p>\n\n<ul>\n<li>BaseCloud Privacy Policy: https:\/\/www.basecloudglobal.com\/privacy-policy\/<\/li>\n<\/ul>\n\n<h4>OpenAI, Perplexity and Anthropic crawler IP ranges<\/h4>\n\n<p>Used by the AI crawler log to check that requests claiming to come from these companies' crawlers come from the IP ranges they publish.<\/p>\n\n<ul>\n<li>Hosts: <code>openai.com<\/code>, <code>www.perplexity.ai<\/code> and <code>claude.com<\/code>.<\/li>\n<li>When: only while the AI crawler log and IP verification are both on: one GET request for each vendor's public IP-range file about once a week, or when you click \"Refresh crawler IP ranges\" (which also needs both settings on).<\/li>\n<li>Data sent: nothing beyond the request itself.<\/li>\n<li>OpenAI Terms of Use: https:\/\/openai.com\/policies\/terms-of-use and Privacy Policy: https:\/\/openai.com\/policies\/privacy-policy<\/li>\n<li>Perplexity Terms of Service: https:\/\/www.perplexity.ai\/hub\/legal\/terms-of-service and Privacy Policy: https:\/\/www.perplexity.ai\/hub\/legal\/privacy-policy<\/li>\n<li>Anthropic Privacy Policy: https:\/\/www.anthropic.com\/legal\/privacy<\/li>\n<\/ul>\n\n<h4>Ahrefs API v3<\/h4>\n\n<p>Used by AI answer citations to read how often AI answers cite your pages (Ahrefs Brand Radar).<\/p>\n\n<ul>\n<li>Host: <code>api.ahrefs.com<\/code>.<\/li>\n<li>When: only while the Ahrefs feature is enabled and an API key is saved: a weekly sync (one request plus one for each selected AI platform), plus \"Test connection\" and \"Sync now\". Calls use Ahrefs API units from your Ahrefs subscription.<\/li>\n<li>Data sent: your API key, the target domain, the selected AI platforms and the optional country.<\/li>\n<li>Ahrefs Terms of Service: https:\/\/ahrefs.com\/legal\/terms<\/li>\n<li>Ahrefs Privacy Policy: https:\/\/ahrefs.com\/legal\/privacy-policy<\/li>\n<\/ul>\n\n<h3>Privacy Policy<\/h3>\n\n<p>BaseCloud UTM Tracker uses first-party cookies and browser storage for campaign and content attribution. Its server never sends data to BaseCloud. Data only leaves your site through integrations you configure yourself: your form, lead and report webhooks, the Meta Conversions API, the BaseCloud Forms bridge (which adds attribution to BaseCloud CRM forms already embedded on your pages), and the Search Console, Google Analytics, Ahrefs and crawler IP-range services described under External services, each only if you enable it.<\/p>\n\n<p><strong>UTM tracker<\/strong><\/p>\n\n<ul>\n<li>Stores UTM parameters, click IDs, the referrer and the landing page in first-party, SameSite cookies (duration configurable)<\/li>\n<li>Adds them to form submissions and to the webhooks you configure<\/li>\n<li>Meta Conversions API (off by default) sends SHA-256 hashed email and phone, IP address and user agent to Meta<\/li>\n<\/ul>\n\n<p><strong>Blog Post Conversion Tracker (off by default)<\/strong><\/p>\n\n<ul>\n<li>Keeps the pages and blog posts a visitor viewed on your site, their first and latest visit source, and visit counts in the browser's localStorage, with a compact first-party cookie (<code>bc_blog_attr<\/code>) as a backup<\/li>\n<li>When a Gravity Form is submitted, adds that journey to the submission as a hidden field, saves it on the entry and sends it, with the form fields and contact details you choose, to the webhooks you configure<\/li>\n<li>Optional consent mode waits for your consent cookie or Google Consent Mode before tracking<\/li>\n<\/ul>\n\n<p><strong>Search keywords, AI visibility and reports (off by default)<\/strong><\/p>\n\n<ul>\n<li>Store aggregated data only: Search Console query, page, click and impression counts; AI crawler hits per page and bot (no IP addresses); AI citation counts from Ahrefs; and one row per conversion with post IDs, channel labels, the landing path and dates. No names, email addresses, IP addresses or form values are added.<\/li>\n<li>Contact Google, Ahrefs, OpenAI, Perplexity and Anthropic only as described under External services, and send reports only to the report webhooks you configure.<\/li>\n<\/ul>\n\n<p><strong>Visits, leads and the BaseCloud Forms bridge (4.4.0)<\/strong><\/p>\n\n<ul>\n<li>Visit counting and the BaseCloud Forms bridge are on by default while the tracker runs (after consent when consent mode is on). The browser sends one small request per visit to your own site with the landing page and the channel of the visit.  &hellip;<\/li>\n<\/ul>\n\n<!--section=installation-->\n<h4>Automatic Installation<\/h4>\n\n<ol>\n<li>Log in to your WordPress admin panel<\/li>\n<li>Navigate to Plugins &gt; Add New<\/li>\n<li>Search for \"BaseCloud UTM Tracker\"<\/li>\n<li>Click \"Install Now\" and then \"Activate\"<\/li>\n<li>Done! The COLLECTOR and COURIER are now active.<\/li>\n<\/ol>\n\n<h4>Manual Installation<\/h4>\n\n<ol>\n<li>Download the plugin ZIP file<\/li>\n<li>Log in to your WordPress admin panel<\/li>\n<li>Navigate to Plugins &gt; Add New &gt; Upload Plugin<\/li>\n<li>Choose the ZIP file and click \"Install Now\"<\/li>\n<li>Activate the plugin<\/li>\n<\/ol>\n\n<h4>Configuration<\/h4>\n\n<ol>\n<li>Navigate to <strong>UTM Tracker<\/strong> in your WordPress admin menu<\/li>\n<li>Verify the <strong>System Status<\/strong> shows COLLECTOR and COURIER as Active<\/li>\n<li>(Optional) Adjust cookie duration (default: 7 days)<\/li>\n<li>(Optional) Add webhook URLs to exclude from UTM injection<\/li>\n<li>Save settings<\/li>\n<\/ol>\n\n<p><strong>That's it!<\/strong> The plugin works automatically - no manual field creation needed.<\/p>\n\n<!--section=faq-->\n<dl>\n<dt id=\"do%20i%20need%20to%20create%20hidden%20fields%20in%20my%20gravity%20forms%3F\"><h3>Do I need to create hidden fields in my Gravity Forms?<\/h3><\/dt>\n<dd><p><strong>No!<\/strong> That's the magic of v2.0. The COURIER system automatically injects UTM data into webhook submissions. You don't need to create any fields.<\/p><\/dd>\n<dt id=\"what%20utm%20parameters%20are%20tracked%3F\"><h3>What UTM parameters are tracked?<\/h3><\/dt>\n<dd><p>All 8 parameters:\n* referrer - Previous page URL\n* utm_source - Campaign source\n* utm_medium - Marketing medium<br \/>\n* utm_campaign - Campaign name\n* utm_term - Keywords\n* gclid - Google Click ID\n* gbraid - Google Brand Engagement (iOS 14+)\n* wbraid - Web to App tracking (iOS 14+)<\/p><\/dd>\n<dt id=\"how%20long%20are%20utm%20parameters%20stored%3F\"><h3>How long are UTM parameters stored?<\/h3><\/dt>\n<dd><p>UTM data is stored in cookies for the duration you specify in settings (1-365 days, default is 7 days).<\/p><\/dd>\n<dt id=\"does%20this%20work%20with%20other%20form%20plugins%20besides%20gravity%20forms%3F\"><h3>Does this work with other form plugins besides Gravity Forms?<\/h3><\/dt>\n<dd><p>The COURIER system is specifically designed for Gravity Forms webhooks. The COLLECTOR (cookie tracking) works with any form plugin, but automatic webhook injection requires Gravity Forms.<\/p><\/dd>\n<dt id=\"is%20the%20plugin%20gdpr%20compliant%3F\"><h3>Is the plugin GDPR compliant?<\/h3><\/dt>\n<dd><p>The plugin uses functional cookies necessary for tracking campaign attribution. You should include UTM tracking in your privacy policy and cookie notice.<\/p><\/dd>\n<dt id=\"can%20i%20exclude%20certain%20webhooks%20from%20utm%20injection%3F\"><h3>Can I exclude certain webhooks from UTM injection?<\/h3><\/dt>\n<dd><p>Yes! In the plugin settings, add webhook URLs (one per line) to the \"Excluded Webhook URLs\" field. This is useful for internal notifications or universal webhooks.<\/p><\/dd>\n<dt id=\"does%20this%20affect%20site%20performance%3F\"><h3>Does this affect site performance?<\/h3><\/dt>\n<dd><p>No! The plugin is optimized for performance with minimal JavaScript and efficient server-side processing.<\/p><\/dd>\n<dt id=\"blog%20post%20conversion%20tracker%3A%20why%20do%20some%20visitors%20have%20no%20journey%3F\"><h3>Blog Post Conversion Tracker: why do some visitors have no journey?<\/h3><\/dt>\n<dd><p>The tracker runs in the visitor's browser, so pages must include its script: purge your page cache (and any CDN or JavaScript optimisation cache) after enabling it. Safari caps storage written by scripts (cookies and localStorage) at about 7 days, so Safari visitors who come back after a longer gap start a new journey.<\/p><\/dd>\n<dt id=\"blog%20post%20conversion%20tracker%3A%20consent%20mode%20with%20a%20gtm%20consent-template%20banner\"><h3>Blog Post Conversion Tracker: consent mode with a GTM consent-template banner<\/h3><\/dt>\n<dd><p>Cookie banners built on Google Tag Manager consent templates set consent through GTM's own API, not through <code>window.dataLayer<\/code>, so the tracker cannot see that consent. On those sites have the banner run <code>document.dispatchEvent(new Event('bc-consent-granted'))<\/code> once analytics consent is given, or use the \"Consent cookie name\" setting. Consent granted after a page has loaded starts tracking on the next pageview, unless the banner dispatches <code>bc-consent-granted<\/code>.<\/p>\n\n<p>Only use \"Consent cookie name\" for a cookie that holds a simple value (<code>true<\/code>, <code>1<\/code>, <code>yes<\/code>, <code>granted<\/code> or <code>allow<\/code>). Any other value counts as an explicit refusal, which stops tracking and deletes the visitor's stored journey. Many consent platforms store a structured value (for example <code>consentid:\u2026,analytics:yes<\/code>); for those, leave the setting blank and rely on Google Consent Mode or the <code>bc-consent-granted<\/code> event.<\/p><\/dd>\n<dt id=\"search%20keywords%3A%20are%20these%20the%20exact%20keywords%20a%20visitor%20searched%3F\"><h3>Search keywords: are these the exact keywords a visitor searched?<\/h3><\/dt>\n<dd><p>No. Google does not share individual searches. These are the Search Console queries that sent clicks to the landing page on the visit day (give or take a day). The data is 2-3 days delayed, rare or anonymised queries are missing, and only visits from Google organic search are matched. Conversions that landed before the synced Search Console period (set by \"Days of history on first sync\", at most about 16 months) are counted as out of range, not as having no query data.<\/p><\/dd>\n<dt id=\"search%20keywords%3A%20can%20i%20see%20ai%20overviews%20or%20ai%20mode%20clicks%20separately%3F\"><h3>Search keywords: can I see AI Overviews or AI Mode clicks separately?<\/h3><\/dt>\n<dd><p>No. Search Console reports them inside Web search results with no filter. Use the Ahrefs AI answer citations in the AI visibility section to see AI answer visibility.<\/p><\/dd>\n<dt id=\"search%20keywords%3A%20how%20do%20i%20connect%20google%20search%20console%3F\"><h3>Search keywords: how do I connect Google Search Console?<\/h3><\/dt>\n<dd><ol>\n<li>In the Google Cloud console, create or select a project and enable the Google Search Console API.<\/li>\n<li>Create a service account and download a JSON key for it.<\/li>\n<li>In Search Console, open Settings &gt; Users and permissions and add the service account's email address (Restricted permission is enough).<\/li>\n<li>Under UTM Tracker &gt; Blog Post Conversion Tracker &gt; Search keywords, paste the JSON key and the property (<code>sc-domain:example.com<\/code> or <code>https:\/\/www.example.com\/<\/code>), save, then click Test connection.<\/li>\n<\/ol><\/dd>\n<dt id=\"ai%20visibility%3A%20why%20are%20ai%20crawler%20counts%20low%20or%20unverified%3F\"><h3>AI visibility: why are AI crawler counts low or unverified?<\/h3><\/dt>\n<dd><p>Hits are logged only when WordPress runs, so pages served from a page cache or CDN are missed. IP verification uses the connecting IP address, so behind a proxy or CDN hits show as unverified. No IP addresses are stored.<\/p><\/dd>\n<dt id=\"ai%20visibility%3A%20when%20is%20llms.txt%20served%3F\"><h3>AI visibility: when is llms.txt served?<\/h3><\/dt>\n<dd><p>Only while \"Serve \/llms.txt\" is on and no real llms.txt file or other plugin already provides one. It is not served while search engines are discouraged (Settings &gt; Reading &gt; Search engine visibility), or when the <code>basecloud_bpct_llms_txt_allowed<\/code> filter returns false, which maintenance, coming-soon or login-wall setups can use. Page descriptions come only from the SEO meta description or the post's own excerpt, never from the post content.<\/p><\/dd>\n<dt id=\"reports%3A%20why%20did%20a%20scheduled%20report%20arrive%20late%3F\"><h3>Reports: why did a scheduled report arrive late?<\/h3><\/dt>\n<dd><p>Scheduled reports run on WP-Cron, which only fires when someone visits the site. On quiet sites, add <code>define('DISABLE_WP_CRON', true);<\/code> to wp-config.php and run wp-cron.php from a real server cron every 5-15 minutes. Each report is sent once per period at or after its send hour, and a failed delivery is retried on the next hourly runs (up to three attempts).<\/p><\/dd>\n<dt id=\"how%20accurate%20are%20the%20numbers%3F\"><h3>How accurate are the numbers?<\/h3><\/dt>\n<dd><p>Each source counts something different, so they never match exactly. Search Console counts clicks on Google results, Google Analytics counts the sessions its script can measure, and this plugin counts the visits its own first-party tracker sees. For organic search, Search Console clicks are usually highest, GA4 organic sessions lower, and the plugin's organic visits often lowest. Common reasons:<\/p>\n\n<ul>\n<li>A Search Console domain property includes clicks to your other subdomains, for example a CRM or app login site, which WordPress never sees.<\/li>\n<li>Google Business Profile links with UTM tags count as a campaign in the plugin and GA4, but as Google clicks in Search Console.<\/li>\n<li>Visitors who refuse consent (when consent mode is on), block scripts or leave before the page loads are not counted, and bots are left out on purpose.<\/li>\n<li>Many apps strip the referrer, so those visits count as Direct.<\/li>\n<li>Search Console days run on US Pacific time and the data is 2-3 days behind.<\/li>\n<\/ul>\n\n<p>As a rough guide, not a guarantee: once subdomain and tagged-link clicks are set aside, the figures are often within 20-30% of each other. Compare periods of 28 days or more. The \"How it works\" section in the plugin explains every number and shows a setup checklist.<\/p><\/dd>\n<dt id=\"where%20does%20the%20ai%20data%20come%20from%3F\"><h3>Where does the AI data come from?<\/h3><\/dt>\n<dd><p>From three separate sources, shown separately because they measure different things:<\/p>\n\n<ul>\n<li><strong>AI assistant visits<\/strong>: people who clicked a link to your site in ChatGPT, Perplexity, Gemini, Copilot, Claude or another assistant, recognised by the referrer or <code>utm_source<\/code>. These are real visits, but a minimum: many AI apps send no referrer, so those visits count as Direct.<\/li>\n<li><strong>AI crawler hits<\/strong>: requests from AI bots that reach WordPress, recognised by user agent and optionally verified against the IP ranges OpenAI, Perplexity and Anthropic publish. They are split by purpose: training (for example GPTBot, ClaudeBot), search index (OAI-SearchBot, PerplexityBot) and user-triggered fetches (ChatGPT-User, Claude-User), where a person asked an assistant something and it fetched your page. Verified and unverified hits are shown separately. Posts and pages are logged under their own address, other requests under fixed labels such as \/feed\/ or \/other\/, and missing pages under the address asked for (with daily row limits). Bots are not people, and pages served from a page cache or CDN are not logged.<\/li>\n<li><strong>AI answer citations<\/strong>: from the Ahrefs API (Brand Radar, optional), a sample of AI answers that cited your pages.<\/li>\n<\/ul>\n\n<p>Clicks from Google AI Overviews and AI Mode are part of Google organic search. Neither Search Console nor this plugin can separate them.<\/p><\/dd>\n<dt id=\"how%20does%20whatsapp%20tracking%20work%20without%20the%20customer%20typing%20anything%3F\"><h3>How does WhatsApp tracking work without the customer typing anything?<\/h3><\/dt>\n<dd><p>When a visitor clicks a WhatsApp link on your site (wa.me, api.whatsapp.com, web.whatsapp.com or whatsapp:\/\/), the plugin adds a short reference line such as \"Ref: BC-7K2M9Q\" to the pre-filled message, after your own text or after a greeting you choose, and records the click with the visitor's source and journey. The visitor only presses Send. When your CRM or WhatsApp tool (for example WATI) forwards incoming messages to the plugin's inbound API, the reference code links the chat to the click and the API returns the attribution. If the visitor deletes the reference line, or starts a chat without your site's link (a saved contact or a QR code), the chat cannot be matched. WhatsApp and call tracking is off by default.<\/p><\/dd>\n<dt id=\"how%20do%20call%20tracking%20numbers%20work%3F\"><h3>How do call tracking numbers work?<\/h3><\/dt>\n<dd><p>You need extra phone numbers from a telephony provider (for example Twilio); the plugin does not supply numbers. There are two modes:<\/p>\n\n<ul>\n<li><strong>Per source<\/strong>: each channel shows its own number (for example Google Ads visitors see one number and organic search visitors another). Calls are attributed to the source, not to an individual visit.<\/li>\n<li><strong>Per-visitor pool<\/strong>: each visitor is shown a number from a pool while they are active (30 minutes by default). When your provider reports a call to the inbound API, the number called and the time identify the visitor and their journey. When every pool number is in use, a new visitor gets no pool number: the page shows the per-source number if you set source rules, otherwise your normal number. Make the pool large enough for the number of visitors on the site at the same time.<\/li>\n<\/ul>\n\n<p>Numbers are swapped in phone links and visible text in the visitor's browser, so this works with cached pages. People who saved a number earlier are attributed to whoever had that number at the time. Clicks on phone links are recorded in both modes; they are reported by the visitor's browser, so treat them as intent, not as calls.<\/p><\/dd>\n<dt id=\"what%20is%20sent%20to%20basecloud%20forms%3F\"><h3>What is sent to BaseCloud Forms?<\/h3><\/dt>\n<dd><p>Only when a BaseCloud CRM form is embedded on your page and the visitor submits it. The plugin adds attribution fields to the request the form already sends from the visitor's browser to your BaseCloud CRM (api.basecloudglobal.com). A field is added only when the form did not send it already, so form fields, <code>utm_*<\/code> values, the referrer and click IDs are never changed. The fields are a reference code (<code>bc_lead_ref<\/code>), random visitor and session IDs, the first and latest source (channel, source, medium, campaign, landing page, referrer host and date), the number of visits and pageviews, the first and last post read, the journey as page paths and the current page. Values are plain text (tags removed, at most 300 characters) and are added to the form's own request text without rewriting it. Form field values are never read. When the CRM confirms the submission, the plugin also records a \"browser-reported\" lead, even with WhatsApp &amp; calls switched off. The bridge is on by default while the tracker is on, can be switched off in the Tracker section, and with consent mode on runs only after consent.<\/p><\/dd>\n<dt id=\"what%20personal%20data%20does%20the%20plugin%20store%3F\"><h3>What personal data does the plugin store?<\/h3><\/dt>\n<dd><p>Visit, keyword, crawler and report tables hold counts, page paths, channel labels and dates: no names, email addresses, IP addresses or user agents. Leads (WhatsApp and call clicks, BaseCloud Forms submissions) store a reference code, random visitor and session IDs, the source, landing page and journey. Phone numbers are stored in full only when they are your own business numbers (listed under WhatsApp &amp; calls, or used as tracking numbers). Callers, WhatsApp senders and any other number are stored only as a keyed pseudonym (so repeat contacts can be recognised) plus the last 3 digits. Message text is never stored. IP addresses are never stored; a keyed hash is used for rate limits and, with a number pool, kept with each lease until retention deletes it. Gravity Forms entries keep what Gravity Forms stores. Retention settings delete old rows automatically.<\/p><\/dd>\n<dt id=\"why%20is%20my%20visit%20count%20lower%20than%20google%20analytics%3F\"><h3>Why is my visit count lower than Google Analytics?<\/h3><\/dt>\n<dd><p>The plugin counts a visit only when its own tracker runs in the visitor's browser and reports it. It does not count visitors who refuse consent (when consent mode is on), block scripts or the request, or leave before the page loads, and it leaves out bots and automated browsers on purpose. A session is counted once, even if its request is repeated within 24 hours, and a new visit starts only after 30 minutes without activity. Behind a proxy or CDN without the trusted proxy setting, counting also stops after about 30 visits an hour (see the next question). GA4 has its own consent handling, bot rules and data thresholds, so some gap is normal (often 10-30%, as a rough guide rather than a guarantee). Check the setup checklist under \"How it works\" if the gap is much larger.<\/p><\/dd>\n<dt id=\"my%20site%20is%20behind%20cloudflare%2C%20a%20load%20balancer%20or%20another%20proxy.%20what%20should%20i%20set%3F\"><h3>My site is behind Cloudflare, a load balancer or another proxy. What should I set?<\/h3><\/dt>\n<dd><p>Rate limits of the visit and lead endpoints work per visitor address. Behind a proxy that is not configured, every visitor seems to come from the proxy's address, so the limit is reached after about 30 visits an hour and further visits are not counted. In the Tracker section choose the header your proxy sets (Cloudflare: CF-Connecting-IP; many load balancers: X-Forwarded-For) under \"Trusted proxy header\". The header is only trusted when the connection comes from a private or loopback address or from the proxy networks you list (for Cloudflare, add its published IP ranges), so visitors cannot fake it. The plugin detects a proxy it is not configured for and warns in the Tracker and Traffic &amp; sources sections and in the \"How it works\" checklist. Addresses are only used as a keyed hash and never stored.<\/p><\/dd>\n<dt id=\"will%20this%20work%20with%20elementor%20popups%3F\"><h3>Will this work with Elementor popups?<\/h3><\/dt>\n<dd><p>Yes! The COLLECTOR includes special support for Elementor popup forms with automatic field population after popup opens.<\/p><\/dd>\n<dt id=\"can%20i%20see%20the%20utm%20data%20somewhere%3F\"><h3>Can I see the UTM data somewhere?<\/h3><\/dt>\n<dd><p>UTM data is stored in cookies and automatically populates Gravity Forms fields. You can view this data in your form submissions or integrate with analytics tools.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>4.4.0<\/h4>\n\n<p><strong>Visits, leads beyond Gravity Forms, keyword insights and a \"How it works\" guide<\/strong><\/p>\n\n<ul>\n<li>NEW: First-party visit counting (on by default while the tracker is on, also on existing sites): one request per visit to the site's own REST endpoint, stored as daily counts per landing page and channel. Bots, automated browsers and repeats of a session within 24 hours are left out, and consent mode applies.<\/li>\n<li>NEW: Trusted proxy setting for sites behind Cloudflare, a load balancer or another proxy, with automatic detection when it is missing.<\/li>\n<li>NEW: Traffic &amp; sources section: visits by channel compared with the previous period, human visits from AI assistants, top landing pages with their channel split, conversion rates per channel, and an organic comparison of plugin visits, Search Console clicks and (optional) GA4 sessions with the likely reason for each gap.<\/li>\n<li>NEW: BaseCloud Forms bridge (on by default while the tracker is on, also on existing sites): embedded BaseCloud CRM forms receive the visitor's source, landing page and journey as extra <code>bc_*<\/code> fields, and confirmed submissions are recorded as browser-reported leads.<\/li>\n<li>NEW: WhatsApp &amp; calls section (off by default): reference codes in pre-filled WhatsApp messages, WhatsApp and phone click tracking with the journey, an inbound API for your CRM, WATI or Twilio to match chats and calls, tracking numbers per source or from a per-visitor pool, an optional lead webhook (form leads and matches by default) and a live feed. Leads whose session had no counted visit are marked \"unverified session\".<\/li>\n<li>NEW: Keyword insights in Search keywords, calculated after each daily refresh or with \"Recalculate\": brand and non-brand searches (brand terms detected from the site name and domain, editable), weekday and monthly rhythm with 480 days of page history, focus keyphrase vs the searches each page really gets, striking-distance queries, cannibalisation, suspected automated queries set aside, and an optional GA4 connection.<\/li>\n<li>NEW: AI visibility: crawler hits by purpose (training, search index, user-triggered fetch) with verified and unverified hits separately, human AI assistant visits, and a list of missing pages AI crawlers requested.<\/li>\n<li>NEW: Minified front-end scripts (the sources are used with <code>SCRIPT_DEBUG<\/code>).<\/li>\n<li>NEW: \"How it works\" section: where every number comes from, how accurate it is, and a live setup checklist.<\/li>\n<li>NEW: Reports include traffic, leads and Search Console insights (additive keys; the JSON schema version stays 1).<\/li>\n<li>CHANGED: Visit counting and the BaseCloud Forms bridge are on by default after the update, also where the Blog Post Conversion Tracker already runs; switch them off in the Tracker section if you do not want them.<\/li>\n<li>CHANGED: A link with only an <code>fbclid<\/code> now counts as social, not paid Meta ads (Facebook adds it to ordinary shares). Google Ads <code>gbraid<\/code> \/ <code>wbraid<\/code> clicks now count as paid. Page-builder post types such as Elementor floating buttons and templates can no longer be tracked.<\/li>\n<li>FIXED: The UTM tracker's <code>referrer<\/code> value could be set to the site's own URL after internal navigation; only external referrers are stored now.<\/li>\n<li>FIXED: Settings fields for Search Console retention and backfill and for the llms.txt post limit now show the limits that are actually applied.<\/li>\n<li>SECURITY: The legacy <code>basecloud_utm_diagnostics<\/code> AJAX action now requires a nonce and the <code>manage_options<\/code> capability.<\/li>\n<li>SECURITY: The new public endpoints accept only small, whitelisted, sanitised payloads, check the origin, filter bots, are rate-limited per address and per network, and are never cached (<code>no-store, private<\/code>). The inbound API needs a secret key that is stored only as a hash.<\/li>\n<li>SECURITY: Daily caps per site-local day for visits (100,000), new unverified landing addresses (200, then grouped as \"\/(other)\"), browser-reported leads (300 form leads, 1,000 WhatsApp and 1,000 call clicks) and unverified-session leads (50 per kind); lead webhooks at most 120 an hour. A full number pool gives no number instead of sharing one, with at most 3 active leases per address.<\/li>\n<li>SECURITY: Phone numbers are stored in full only for your configured business numbers; everyone else only as a pseudonym plus the last 3 digits. Twilio callbacks for outgoing calls are ignored. Message text is never stored. The BaseCloud Forms bridge strips tags from values and no longer rewrites the CRM request body.<\/li>\n<li>SECURITY: The AI crawler log caps missing-page and non-post rows per day and uses fixed labels for non-post requests; keyword insights are memory-bounded and never calculated while a report is built.<\/li>\n<\/ul>\n\n<h4>4.3.0<\/h4>\n\n<p><strong>Search keywords, AI visibility and reports<\/strong> (all off by default)<\/p>\n\n<ul>\n<li>NEW: The Blog Post Conversion Tracker tab has four sections: Tracker, Search keywords, AI visibility and Reports. Each section saves its own settings.<\/li>\n<li>NEW: Search keywords from Google Search Console for organic Google conversions, flagged against target keywords from Yoast SEO, Rank Math, All in One SEO, SEOPress and a manual list. These are the likely keywords for the landing page, 2-3 days delayed, not the visitor's exact search.<\/li>\n<li>NEW: AI visibility: AI assistant referrals as a channel, an AI crawler log with optional IP verification, a robots.txt AI access check, an llms.txt generator and AI answer citations from the Ahrefs API.<\/li>\n<li>NEW: Reports: daily, weekly, monthly and half-yearly <code>blog_post_conversion_report<\/code> JSON to up to 10 report webhooks, with an optional PDF attachment, \"Send now\" for any date range, and preview and PDF download in the admin.<\/li>\n<li>NEW: A conversion data store (<code>{prefix}bpct_conversions<\/code>, no personal data) with a one-time import of existing entries and daily retention.<\/li>\n<li>NEW: Conversion webhook payloads include <code>visitor.first_touch.channel<\/code> and <code>visitor.last_touch.channel<\/code> labels (additive, still schema version 1, never UTM values).<\/li>\n<li>Security: encrypted, write-only keys and webhook secrets; a fixed host allowlist for service requests; SSRF checks, forced TLS and HMAC signatures for report webhooks; nonce and capability checks on every action; redirects and unsafe URLs pinned off for all Blog Post Conversion Tracker requests.<\/li>\n<li>Security: the development scripts update-release.php and version-helper.php now refuse to run outside the command line and, with the internal release notes, are no longer included in the plugin package.<\/li>\n<li>Bundles FPDF 1.86 for PDF reports, loaded only while a PDF is generated.<\/li>\n<li>The UTM tracker, its cookies and its webhooks are unchanged. Deleting the plugin also removes the new tables, options and scheduled events.<\/li>\n<\/ul>\n\n<h4>4.2.0<\/h4>\n\n<p><strong>Blog Post Conversion Tracker<\/strong><\/p>\n\n<ul>\n<li>NEW: <strong>Blog Post Conversion Tracker<\/strong> tab (off by default). Shows which blog post a visitor read right before submitting a Gravity Form.<\/li>\n<li>Journey storage: the full journey (first\/last touch, first\/last post read, recent pages) lives in localStorage. A compact first-party <code>bc_blog_attr<\/code> cookie, capped at 2 KB so the site's Cookie header stays small, is the backup, and Gravity Forms submissions carry the full journey in a hidden <code>bcpct_record<\/code> field. Cache-safe and size-safe.<\/li>\n<li>Optional consent mode: waits for a consent cookie, a <code>bc-consent-granted<\/code> event or Google Consent Mode granting <code>analytics_storage<\/code>. Regional consent defaults are respected.<\/li>\n<li>Last touch changes only for a campaign visit that did not come from internal navigation, or a new session from an external site.<\/li>\n<li>Gravity Forms entry columns \"Blog: Converted From Post\" (Yes, Yes (unverified) or No) and \"Blog: Source Post\", plus minutes to convert, same visit (by visit number), pages viewed after the post, posts read (verified posts only) and an optional attribution window. Source posts and journey titles are verified server-side.<\/li>\n<li>Webhooks with a clean, readable JSON payload (form, entry, contact, fields, conversion, visitor, journey) and ISO 8601 times. No UTM parameters or click IDs. Sent after the visitor's response, within a 10-second budget and without retrying timeouts. Per-webhook target forms, \"only blog-post conversions\" option, contact toggle, send test and delivery log.<\/li>\n<li>Security: webhook URLs and secrets are encrypted at rest (AES-256-GCM, optional <code>BASECLOUD_BPCT_KEY<\/code> constant so salt rotation does not break them), HTTPS only, SSRF-protected for IPv4 and IPv6, TLS verification forced, write-only in the admin, and requests can be HMAC-SHA256 signed.<\/li>\n<li>Top Converting Posts and Recent Conversions panels. Uninstalling removes only the Blog Post Conversion Tracker data.<\/li>\n<li>The UTM tracker is unchanged. The new feature uses its own settings, cookie, webhooks and entry meta. Its cookie is named <code>bc_blog_attr<\/code> so it never collides with other attribution scripts that use <code>bc_attr<\/code>.<\/li>\n<\/ul>\n\n<h4>4.1.2<\/h4>\n\n<ul>\n<li>IMPROVED: Advanced Name field parts can now be mapped individually instead of returning the full name. {Name} or {First Name} returns the first name only, and {Surname} or {Last Name} returns the last name only. {Middle Name}, {Prefix}, and {Suffix} are also supported, and {Full Name} returns the complete name.<\/li>\n<li>Address and other multi-input fields can be mapped by their sub-field labels, for example {City} or {Postal Code}.<\/li>\n<\/ul>\n\n<h4>4.1.1<\/h4>\n\n<ul>\n<li>FIXED: Advanced Name field (and other multi-input Gravity Forms fields) returned empty when used as a merge tag like {Name} in Select Fields mode. These fields store their data in sub-inputs, so a direct lookup missed them. They are now resolved with Gravity Forms' export formatter, the same method used by \"All Fields\" mode.<\/li>\n<li>Applies to merge tags by label ({Name}) and by field ID ({Name:1}).<\/li>\n<\/ul>\n\n<h4>4.1.0<\/h4>\n\n<p><strong>Per-Form Webhook Targeting<\/strong><\/p>\n\n<ul>\n<li><strong>Target Form selector<\/strong> - Each webhook can now be scoped to a specific Gravity Form, or left as \"All Forms\" to fire on every submission. The dropdown lists every form on the site automatically.<\/li>\n<li><strong>Form-aware field picker<\/strong> - When a form is selected, the \"Load My Form Fields\" picker shows only that form's fields, making \"Select Fields\" mapping faster and more accurate.<\/li>\n<li>Works with both \"All Fields\" and \"Select Fields\" body modes, scoped to the chosen form.<\/li>\n<li>Fully backward compatible - existing webhooks default to \"All Forms\" and behave exactly as before.<\/li>\n<\/ul>\n\n<h4>4.0.0<\/h4>\n\n<p><strong>\ud83d\ude80 MAJOR UPDATE \u2014 Close the Loop: Conversion Intelligence<\/strong><\/p>\n\n<ul>\n<li>\ud83c\udfaf <strong>Meta Conversions API (CAPI)<\/strong> - Send server-side conversion events to Meta on every Gravity Forms submission. Email &amp; phone are SHA-256 hashed, with _fbc\/_fbp and fbclid support, event de-duplication, and a Test Event Code for validation. Beats browser-only pixels against ad-blockers and iOS.<\/li>\n<li><strong>Multi-Channel Click ID Capture<\/strong> - Now tracks Meta (fbclid), Microsoft\/Bing (msclkid), TikTok (ttclid) and LinkedIn (li_fat_id) click IDs alongside Google's gclid\/gbraid\/wbraid - plus the previously missing utm_content.<\/li>\n<li><strong>Full Attribution Journey<\/strong> - Captures first-touch AND last-touch source\/medium\/campaign, landing page, first-visit timestamp, and visit count - all forwarded to your webhooks\/CRM.<\/li>\n<li><strong>Webhook Delivery Log + Auto-Retry<\/strong> - Every webhook and CAPI call is logged (status, time, response) with an automatic single retry on failure, viewable right in the admin.<\/li>\n<li><strong>Consent Mode (GDPR)<\/strong> - Optional consent gating: tracking cookies are only set after a named consent cookie is granted or Google Consent Mode allows storage. Off by default.<\/li>\n<li>All new features are additive or off-by-default - existing setups are unaffected until enabled.<\/li>\n<\/ul>\n\n<h4>3.0.4<\/h4>\n\n<ul>\n<li>\ud83c\udfaf <strong>Fixed \"All Fields\" Webhooks<\/strong> - The \"All Fields\" body option now correctly includes Form Title, Form ID, Entry ID, Entry Date, Source URL and User IP - no more missing form titles and entry metadata<\/li>\n<li><strong>Complete Field Capture<\/strong> - Multi-input Gravity Forms fields (Name, Address, Checkboxes, Multi-select, List) are now resolved with Gravity Forms' own export formatter instead of being silently dropped<\/li>\n<li><strong>NEW: Extra Fields in \"All Fields\" Mode<\/strong> - You can now add custom\/extra field mappings even when \"All Fields\" is selected, so anything missing can be added manually<\/li>\n<li><strong>NEW: Load My Form Fields<\/strong> - Browse the real fields from all your Gravity Forms inside the webhook editor and click any field to add it instantly<\/li>\n<li>FIXED: Empty values no longer cause a field to disappear from the payload in \"All Fields\" mode<\/li>\n<\/ul>\n\n<h4>3.0.3<\/h4>\n\n<ul>\n<li>\ud83c\udfaf <strong>Smart Field Matching<\/strong> - Enhanced merge tag parser with intelligent field detection and normalization<\/li>\n<li><strong>Field Aliases<\/strong> - Automatic mapping for common field variations (phone = telephone\/mobile\/contact number)<\/li>\n<li><strong>Special Character Support<\/strong> - Properly handles ampersands, hyphens in field labels like \"Name &amp; Surname\"<\/li>\n<li><strong>Better Empty Handling<\/strong> - Unmatched merge tags replaced with empty string instead of showing literal {FieldName}<\/li>\n<li><strong>3-Tier Matching<\/strong> - Exact match \u2192 Partial match \u2192 Alias-based matching for maximum compatibility<\/li>\n<li>FIXED: Merge tags like {Phone} now properly match fields named \"Contact Number\", \"Telephone\", \"Mobile\"<\/li>\n<li>FIXED: Complex field labels with special characters (&amp; - .) now match simple merge tags<\/li>\n<\/ul>\n\n<h4>3.0.2<\/h4>\n\n<ul>\n<li>FIXED: Webhook Edit\/Delete buttons causing page reload - Added type=\"button\" attribute to prevent form submission<\/li>\n<li>IMPROVED: Webhook management stability and user experience<\/li>\n<\/ul>\n\n<h4>3.0.1<\/h4>\n\n<ul>\n<li>Enhanced save button styling with border accent<\/li>\n<li>Simplified version management (removed unnecessary constant)<\/li>\n<li>Improved code maintainability and deployment infrastructure<\/li>\n<li>Updated changelog formatting for better readability<\/li>\n<\/ul>\n\n<h4>3.0.0<\/h4>\n\n<ul>\n<li>Complete rewrite with modern architecture<\/li>\n<li>Enhanced visual effects with improved logo glow and pulse animation<\/li>\n<li>Fixed entry date merge tags to display actual submission timestamps<\/li>\n<li>Improved field detection with smart label matching<\/li>\n<li>Added email tracking for notification success monitoring<\/li>\n<li>Enhanced merge tag parser for entry properties and UTM data<\/li>\n<li>Modern glassmorphism UI design<\/li>\n<li>Webhook management with intuitive inline editor<\/li>\n<\/ul>\n\n<h4>2.3.3<\/h4>\n\n<p><strong>\ud83d\udd27 Critical Fixes + \ud83c\udfa8 Futuristic UI Upgrade<\/strong><\/p>\n\n<p>\u2022 <strong>FIXED: Entry Date Merge Tag<\/strong> - Now properly displays actual submission timestamp instead of literal text\n\u2022 <strong>FIXED: Field Detection<\/strong> - Use simple merge tags like {Name}, {Email}, {Phone} instead of field IDs\n\u2022 <strong>FIXED: Smart Field Matching<\/strong> - Intelligent partial matching for field labels (e.g., \"Name &amp; Surname\" matches {Name})\n\u2022 <strong>NEW: Email Tracking<\/strong> - Track if email notifications were successfully sent to client inbox\n\u2022 <strong>NEW: Email Data in Webhook<\/strong> - Includes email_sent (boolean), email_count, and email_notifications array\n\u2022 <strong>NEW: Email Notification Details<\/strong> - Shows recipient, subject, timestamp, and success status for each email\n\u2022 <strong>IMPROVED: Merge Tag Parser<\/strong> - Enhanced to recognize Entry Properties: {Entry Date}, {Entry ID}, {User IP}, {Source URL}, {Form Title}\n\u2022 <strong>IMPROVED: Field Label Support<\/strong> - Use exact field names from your forms - no more guessing field IDs!\n\u2022 <strong>UI: Glassmorphism Design<\/strong> - Beautiful frosted glass effect with backdrop blur on all containers\n\u2022 <strong>UI: Animated Glow Effects<\/strong> - Pulsing borders and glow animations on active webhooks\n\u2022 <strong>UI: Shimmer Animations<\/strong> - Sweeping light effects across containers\n\u2022 <strong>UI: Floating Logo<\/strong> - Animated logo with glow drop shadow\n\u2022 <strong>UI: Gradient Buttons<\/strong> - Enhanced buttons with hover shine effects and smooth transitions\n\u2022 <strong>UI: In-Form Help<\/strong> - Added helpful merge tag documentation directly in the webhook editor\n\u2022 <strong>UI: Enhanced Shadows<\/strong> - Improved depth with multi-layer shadows and lighting effects\n\u2022 <strong>UI: Smooth Transitions<\/strong> - Cubic-bezier easing for professional animations<\/p>\n\n<p><strong>Available Merge Tags:<\/strong>\n- <strong>Entry Properties:<\/strong> {Entry Date}, {Entry ID}, {User IP}, {Source URL}, {Form Title}\n- <strong>Field Names:<\/strong> {Name}, {Email}, {Phone}, {Surname}, {Message} - use any field label from your form!\n- <strong>UTM Parameters:<\/strong> {utm_source}, {utm_campaign}, {utm_medium}, {utm_term}, {gclid}, {referrer}, {gbraid}, {wbraid}<\/p>\n\n<p><strong>Email Tracking Example:<\/strong>\n    <code>json\n{\n  \"email_sent\": true,\n  \"email_count\": 2,\n  \"email_notifications\": [\n    {\n      \"success\": true,\n      \"to\": \"client@example.com\",\n      \"subject\": \"New Form Submission\",\n      \"timestamp\": \"2026-02-12 14:30:00\"\n    }\n  ]\n}<\/code><\/p>\n\n<h4>3.0.0<\/h4>\n\n<p><strong>\ud83d\ude80 WEBHOOK MANAGEMENT REVOLUTION - Complete Gravity Forms Webhook Replacement<\/strong><\/p>\n\n<p>\u2022 <strong>NEW: Custom Webhook Builder<\/strong> - Replace Gravity Forms webhook add-on with unlimited custom webhooks\n\u2022 <strong>NEW: Merge Tag Support<\/strong> - Full Gravity Forms merge tag integration ({Name:1}, {Email:6}, {entry_id}, etc.)\n\u2022 <strong>NEW: Dynamic Field Mapping<\/strong> - Select specific fields or send all form data automatically\n\u2022 <strong>NEW: Two-Column Dashboard<\/strong> - Professional layout with settings on left, webhooks on right\n\u2022 <strong>NEW: Unlimited Webhooks<\/strong> - Add as many webhooks as needed for each form submission\n\u2022 <strong>NEW: Request Method Selection<\/strong> - Support for GET, POST, PUT, PATCH, DELETE methods\n\u2022 <strong>NEW: Individual Webhook Toggle<\/strong> - Enable\/disable webhooks without deleting configuration\n\u2022 <strong>NEW: In-Place Editing<\/strong> - Edit webhook configurations inline with smooth animations\n\u2022 <strong>NEW: BaseCloud Logo<\/strong> - Professional branding with icon instead of Lottie animation\n\u2022 <strong>IMPROVED: Webhook System<\/strong> - Complete webhook management replaces need for Gravity Forms webhook add-on\n\u2022 <strong>IMPROVED: UTM Injection<\/strong> - All custom webhooks automatically include UTM parameters\n\u2022 <strong>IMPROVED: UI\/UX<\/strong> - Wider layout (1400px) with responsive grid design\n\u2022 <strong>REMOVED: Denied Webhooks<\/strong> - Exclusion list removed in favor of individual webhook control<\/p>\n\n<p><strong>Webhook Features:<\/strong>\n- Unlimited custom webhooks per installation\n- Full Gravity Forms merge tag support\n- All Fields or Select Fields body options\n- Automatic UTM parameter injection\n- GET, POST, PUT, PATCH, DELETE methods\n- JSON request format\n- Enable\/disable individual webhooks\n- In-place editing with live preview<\/p>\n\n<p><strong>Supported Merge Tags:<\/strong>\n{FieldLabel:ID}, {entry_id}, {entry_date}, {form_id}, {form_title}, {utm_source}, {utm_campaign}, {gclid}, {referrer}, and more!<\/p>\n\n<p><strong>Breaking Changes:<\/strong> None - Fully backward compatible with v2.x<\/p>\n\n<h4>2.3.3<\/h4>\n\n<p><strong>Lottie Logo Fix<\/strong><\/p>\n\n<p>\u2022 Fixed Lottie player script loading order to display logo properly\n\u2022 Changed script loading from footer to header for immediate availability\n\u2022 Resolved warning icon display issue on page load<\/p>\n\n<h4>2.3.2<\/h4>\n\n<p><strong>Animated Logo Addition<\/strong><\/p>\n\n<p>\u2022 Added animated BaseCloud Lottie logo to settings page header\n\u2022 Enhanced brand presence with looping logo animation\n\u2022 Improved visual consistency with BaseCloud brand identity<\/p>\n\n<h4>2.3.1<\/h4>\n\n<p><strong>API Endpoint Update<\/strong><\/p>\n\n<p>\u2022 <strong>UPDATED: Default Webhook URL<\/strong> - Migrated from legacy portal.basecloudglobal.com to new api.basecloudglobal.com endpoint\n\u2022 <strong>IMPROVED: URL Format<\/strong> - New webhook URLs use \/webhook\/ path structure for better API organization\n\u2022 <strong>ENHANCED: Security<\/strong> - Updated default excluded webhook to new API endpoint (https:\/\/api.basecloudglobal.com\/webhook\/92b3163196af061b6d009264)\n\u2022 <strong>BACKWARD COMPATIBLE<\/strong> - No impact on existing installations or custom excluded URLs<\/p>\n\n<p><strong>Technical Changes:<\/strong>\n\u2022 Default denied URL updated to api.basecloudglobal.com domain\n\u2022 Activation hook updated with new default webhook URL\n\u2022 Maintained full backward compatibility with existing configurations<\/p>\n\n<h4>2.3.0<\/h4>\n\n<p><strong>\ud83c\udfa8 DARK THEME UI REDESIGN - BaseCloud Branding<\/strong><\/p>\n\n<p>\u2022 <strong>NEW: Dark Theme Interface<\/strong> - Complete UI redesign with navy blue (#0f2c52) background and green (#4bc46a) accents\n\u2022 <strong>NEW: Toggle Switches<\/strong> - Modern toggle switches replace checkboxes for cleaner interface\n\u2022 <strong>NEW: Gradient Effects<\/strong> - Beautiful gradient borders and hover effects throughout\n\u2022 <strong>ENHANCED: BaseCloud Branding<\/strong> - Professional color scheme matching BaseCloud Global identity\n\u2022 <strong>IMPROVED: Status Indicators<\/strong> - Pulsing green status dots for active systems\n\u2022 <strong>ADDED: Dark Cards<\/strong> - Settings sections now use elegant dark cards with subtle shadows\n\u2022 <strong>REDESIGNED: Button Styling<\/strong> - Primary green buttons with hover effects and shadows\n\u2022 <strong>UPDATED: Typography<\/strong> - Improved font hierarchy with better contrast on dark background\n\u2022 <strong>OPTIMIZED: Visual Hierarchy<\/strong> - Better spacing and organization for improved UX\n\u2022 <strong>POLISHED: Animations<\/strong> - Smooth transitions and hover effects for modern feel<\/p>\n\n<p><strong>Design Elements:<\/strong>\n\u2022 CSS variables for consistent theming (--bc-bg, --bc-card, --bc-green, --bc-border)\n\u2022 Gradient borders on cards and input fields\n\u2022 Box shadows for depth and dimension\n\u2022 Pulsing animations for status indicators\n\u2022 Modern toggle switch component with smooth transitions<\/p>\n\n<p><strong>Breaking Changes:<\/strong>\n\u2022 None - fully backward compatible with v2.2.0<\/p>\n\n<h4>2.2.0<\/h4>\n\n<p><strong>\ud83d\ude80 THE \"BIG 4\" FORM AUTOMATOR - Multi-Plugin Support<\/strong><\/p>\n\n<p>\u2022 <strong>NEW: Elementor Pro Integration<\/strong> - Automatic webhook injection for Elementor forms\n\u2022 <strong>NEW: WPForms Integration<\/strong> - Complete webhook automation for WPForms\n\u2022 <strong>NEW: Contact Form 7 Integration<\/strong> - Classic form plugin support with data injection\n\u2022 <strong>CRITICAL: Async Webhook Support<\/strong> - Fixed Gravity Forms background processing (Priority 1 save)\n\u2022 <strong>ENHANCED: Database Storage<\/strong> - UTM data now saved to database BEFORE async webhook queue\n\u2022 <strong>IMPROVED: Multi-Plugin Dashboard<\/strong> - Real-time status for all 4 form plugins\n\u2022 <strong>FIXED: Cookie Availability in Async<\/strong> - Reads from database when cookies unavailable\n\u2022 <strong>ADDED: Form Plugin Detection<\/strong> - Automatic detection of installed form plugins\n\u2022 <strong>OPTIMIZED: Webhook Injection Logic<\/strong> - Universal injection method for all form types\n\u2022 <strong>UPDATED: Settings Panel<\/strong> - Individual toggles for each form plugin integration<\/p>\n\n<p><strong>Technical Improvements:<\/strong>\n\u2022 Priority 1 execution for <code>gform_after_submission<\/code> (runs before async queue at Priority 10)\n\u2022 Force database read in <code>inject_gf_webhook<\/code> for reliable async operation\n\u2022 Added <code>is_url_denied()<\/code> helper method for cleaner deny list checking\n\u2022 Support for JSON and array body formats in webhooks\n\u2022 Elementor filter: <code>elementor_pro\/forms\/webhook\/request_args<\/code>\n\u2022 WPForms filter: <code>wpforms_webhooks_request_args<\/code>\n\u2022 CF7 filter: <code>wpcf7_posted_data<\/code><\/p>\n\n<p><strong>Breaking Changes:<\/strong>\n\u2022 None - fully backward compatible with v2.0.0<\/p>\n\n<h4>2.0.0<\/h4>\n\n<p><strong>\ud83d\ude80 GAME CHANGER: Complete Automation Revolution<\/strong><\/p>\n\n<p>\u2022 <strong>NEW: THE COURIER System<\/strong> - Automatic UTM injection into Gravity Forms webhooks - NO manual fields needed!\n\u2022 <strong>NEW: THE COLLECTOR System<\/strong> - Advanced cookie-based tracking engine with enhanced reliability\n\u2022 <strong>NEW: Animated Dashboard<\/strong> - Real-time system diagnostics with smooth animations and status indicators\n\u2022 <strong>NEW: Entry Meta Storage<\/strong> - UTM data automatically saved with each Gravity Forms submission\n\u2022 <strong>NEW: Excluded Webhooks<\/strong> - Configure specific webhook URLs to bypass UTM injection\n\u2022 <strong>NEW: System Health Monitor<\/strong> - Live COLLECTOR and COURIER status with animated feedback\n\u2022 <strong>ENHANCED: iOS 14+ Support<\/strong> - Full gbraid and wbraid parameter tracking for Apple privacy\n\u2022 <strong>IMPROVED: Zero Configuration<\/strong> - Works automatically after activation - no setup required\n\u2022 <strong>ADDED: Webhook Automation<\/strong> - All 8 parameters auto-injected into webhook payloads\n\u2022 <strong>REDESIGNED: Modern UI<\/strong> - Beautiful gradient designs, hover effects, and smooth transitions\n\u2022 <strong>REMOVED: Manual Field Creation<\/strong> - No longer needed! COURIER handles everything automatically\n\u2022 <strong>OPTIMIZED: Performance<\/strong> - Streamlined code for faster page loads\n\u2022 <strong>UPDATED: Cookie Names<\/strong> - Standardized naming (removed bc_ prefix) for better CRM compatibility<\/p>\n\n<p><strong>Breaking Changes:<\/strong>\n\u2022 Removed auto_create_fields option (no longer needed with COURIER system)\n\u2022 Removed tracked_parameters option (all 8 parameters now tracked by default)\n\u2022 Changed gclid cookie from bc_gclid to gclid for CRM compatibility<\/p>\n\n<h4>1.2.2<\/h4>\n\n<p><strong>Enhanced Secret Sauce - CRM\/Webhook Integration Update<\/strong><\/p>\n\n<p>\u2022 <strong>NEW: Google Brand Engagement Tracking<\/strong> - Added gbraid and wbraid parameters for iOS 14+ tracking\n\u2022 <strong>IMPROVED: GCLID Cookie Naming<\/strong> - Changed from bc_gclid to gclid for better CRM\/webhook compatibility\n\u2022 <strong>ENHANCED: Field Population<\/strong> - Streamlined secret sauce code with optimized field population\n\u2022 <strong>UPDATED: Default Parameters<\/strong> - Now includes referrer, utm_source, utm_medium, utm_campaign, utm_term, gclid, gbraid, wbraid\n\u2022 <strong>IMPROVED: Event Triggering<\/strong> - Added input and change events for better form integration\n\u2022 <strong>OPTIMIZED: Label-Based Population<\/strong> - Streamlined field detection for text fields set to hidden visibility\n\u2022 <strong>ENHANCED: Popup Integration<\/strong> - Improved Elementor popup support with better event handling<\/p>\n\n<h4>1.2.1<\/h4>\n\n<p><strong>\ud83d\udd27 Critical Gravity Forms Integration Fix<\/strong><\/p>\n\n<p>\u2022 <strong>FIXED: Proper Field Creation<\/strong> - Auto-created fields now use text fields with hidden visibility (WordPress best practice)\n\u2022 <strong>NEW: Server-Side Population<\/strong> - Added reliable server-side field population using Gravity Forms filters\n\u2022 <strong>IMPROVED: Dynamic Population<\/strong> - Fields now properly support \"Allow field to be populated dynamically\" setting\n\u2022 <strong>ENHANCED: Parameter Name Support<\/strong> - Correct parameter names (gclid, utm_source, etc.) for dynamic population\n\u2022 <strong>ADDED: Triple Population Method<\/strong> - Server-side + parameter matching + label fallback for 100% reliability\n\u2022 <strong>FIXED: Field Detection<\/strong> - Smart field detection prevents overwriting existing data\n\u2022 <strong>IMPROVED: Form Compatibility<\/strong> - Better compatibility with all Gravity Forms features and add-ons<\/p>\n\n<h4>1.2.0<\/h4>\n\n<p><strong>\ud83d\ude80 Major Feature Release - Enhanced Tracking &amp; Automation<\/strong><\/p>\n\n<p>\u2022 <strong>NEW: Referrer Tracking<\/strong> - Automatically captures and stores the previous page URL (document.referrer)\n\u2022 <strong>NEW: Auto-Create Hidden Fields<\/strong> - Automatically adds UTM hidden fields to new Gravity Forms\n\u2022 <strong>Enhanced JavaScript Engine<\/strong> - Improved \"secret sauce\" code with modern ES6 features\n\u2022 <strong>Smart Cookie Logic<\/strong> - Only sets cookies if they don't exist, preventing data overwriting<br \/>\n\u2022 <strong>Advanced Popup Support<\/strong> - Enhanced integration with Elementor and other page builders\n\u2022 <strong>Automatic Field Detection<\/strong> - Intelligent field creation with duplicate prevention\n\u2022 <strong>Form-Level Settings<\/strong> - Per-form control for UTM field creation in Gravity Forms admin\n\u2022 <strong>Updated Default Parameters<\/strong> - Now includes referrer tracking by default\n\u2022 <strong>Improved Field Population<\/strong> - Better support for multiple forms and popup scenarios\n\u2022 <strong>Enhanced Admin UI<\/strong> - Added referrer field to the field reference guide<\/p>\n\n<h4>1.1.6<\/h4>\n\n<p><strong>Major UI Enhancement<\/strong><\/p>\n\n<p>\u2022 Modern dashboard layout with real-time status indicators\n\u2022 Enhanced admin interface with responsive grid design\n\u2022 Added visual status cards showing tracking configuration at-a-glance\n\u2022 Improved success messages and user feedback\n\u2022 Professional styling with better visual hierarchy\n\u2022 Enhanced field reference guide with color-coded categories\n\u2022 Added quick stats display for cookie duration and integrations\n\u2022 Mobile-responsive admin interface\n\u2022 Better documentation integration and support links<\/p>\n\n<h4>1.1.5<\/h4>\n\n<p><strong>Release Update<\/strong><\/p>\n\n<p>\u2022 Bug fixes and improvements\n\u2022 Updated version for deployment<\/p>\n\n<h4>1.1.4<\/h4>\n\n<p><strong>Release Update<\/strong><\/p>\n\n<p>\u2022 Bug fixes and improvements\n\u2022 Updated version for deployment<\/p>\n\n<h4>1.1.3<\/h4>\n\n<p><strong>GitHub Actions Deployment Trigger<\/strong><\/p>\n\n<p>\u2022 Re-triggered automated deployment to WordPress.org\n\u2022 Ensure assets are properly deployed via GitHub Actions\n\u2022 Force deployment pipeline activation\n\u2022 Test automated SVN commit process<\/p>\n\n<h4>1.1.2<\/h4>\n\n<p><strong>Assets and Deployment Fix<\/strong><\/p>\n\n<p>\u2022 Added GitHub Actions workflow for automated WordPress.org deployment\n\u2022 Corrected asset filenames to meet WordPress.org requirements\n\u2022 Fixed plugin branding assets (banners and icons)\n\u2022 Established automated deployment pipeline matching Security Manager<\/p>\n\n<h4>1.1.1<\/h4>\n\n<p><strong>Deployment System Enhancement<\/strong><\/p>\n\n<p>\u2022 Updated deployment script to use Git-based approach\n\u2022 Removed SVN dependencies for cleaner deployment process\n\u2022 Added plugin network compatibility information\n\u2022 Improved deployment workflow matching Security Manager<\/p>\n\n<h4>1.1.0<\/h4>\n\n<p><strong>Admin Interface Enhancement<\/strong><\/p>\n\n<p>\u2022 Updated admin menu title from \"UTM Tracker\" to \"UTM Analytics\"\n\u2022 Enhanced admin interface terminology for better clarity\n\u2022 Improved user experience in WordPress dashboard navigation\n\u2022 Minor version bump for interface improvements<\/p>\n\n<h4>1.0.3<\/h4>\n\n<p><strong>Description Enhancement<\/strong><\/p>\n\n<p>\u2022 Enhanced plugin description with improved clarity\n\u2022 Added emphasis on secure cookie storage\n\u2022 Improved analytics terminology for better user understanding\n\u2022 Minor text improvements for professional presentation<\/p>\n\n<h4>1.0.2<\/h4>\n\n<p><strong>Assets Update<\/strong><\/p>\n\n<ul>\n<li>Added professional plugin assets (banners and icons)<\/li>\n<li>Enhanced WordPress.org directory presentation<\/li>\n<li>Improved plugin branding and visual identity<\/li>\n<li>Updated deployment workflow for assets<\/li>\n<\/ul>\n\n<h4>1.0.1<\/h4>\n\n<p><strong>Minor Update &amp; Testing<\/strong><\/p>\n\n<ul>\n<li>Improved GitHub repository integration and documentation<\/li>\n<li>Enhanced deployment workflow testing<\/li>\n<li>Minor code optimizations for better performance<\/li>\n<li>Updated repository links and branding consistency<\/li>\n<\/ul>\n\n<h4>1.0.0<\/h4>\n\n<p><strong>Initial Release<\/strong><\/p>\n\n<ul>\n<li>Complete UTM parameter tracking system<\/li>\n<li>Gravity Forms integration for automatic field population<\/li>\n<li>Configurable cookie duration (1-365 days)<\/li>\n<li>Custom parameter tracking support<\/li>\n<li>Professional admin interface with BaseCloud branding<\/li>\n<li>HTTPS and security best practices<\/li>\n<li>WordPress coding standards compliance<\/li>\n<li>Translation ready<\/li>\n<\/ul>","raw_excerpt":"Advanced UTM tracking with automated webhook injection for Gravity Forms, Elementor, WPForms, and Contact Form 7.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/es-do.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/248935","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/es-do.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/es-do.wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/es-do.wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=248935"}],"author":[{"embeddable":true,"href":"https:\/\/es-do.wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/basecloud"}],"wp:attachment":[{"href":"https:\/\/es-do.wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=248935"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/es-do.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=248935"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/es-do.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=248935"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/es-do.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=248935"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/es-do.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=248935"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/es-do.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=248935"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}