{"id":379417,"date":"2026-10-03T14:23:47","date_gmt":"2026-10-03T14:23:47","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/clickhelm\/"},"modified":"2026-10-03T18:08:49","modified_gmt":"2026-10-03T18:08:49","slug":"clickhelm","status":"publish","type":"plugin","link":"https:\/\/it.wordpress.org\/plugins\/clickhelm\/","author":23577424,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"6.92.0","stable_tag":"6.92.0","tested":"7.1.2","requires":"5.6","requires_php":"7.2","requires_plugins":null,"header_name":"ClickHelm","header_author":"ClickHelm","header_description":"Google Ads click-fraud protection that identifies visitors by <strong>device, not by IP address<\/strong>, so the same person is recognised after they clear storage, switch browser or move to mobile data. It records every arrival, scores it, and explains the reasoning in plain language. Calls, WhatsApp taps, forms and WooCommerce orders all count as leads, so the Google Ads tab shows real profit and loss per campaign, keyword and placement rather than click counts - and the exclusion list gives you every address worth excluding. <strong>This edition does not block anyone.<\/strong> Automatic blocking, your own rules, the breakdown reports and heatmaps are a separate plugin from clickhelm.com, and none of that code is in this one.","assets_banners_color":"091420","last_updated":"2026-10-03 18:08:49","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"https:\/\/clickhelm.com\/","header_author_uri":"","rating":0,"author_block_rating":0,"active_installs":0,"downloads":56,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"6.92.0":{"tag":"6.92.0","author":"clickhelm","date":"2026-10-03 18:08:49","revision":3726598}},"upgrade_notice":{"5.14.0":"<p>Adds licensing with a seven day trial. Existing blocks are never affected by a licence\nlapse \u2014 this release cannot leave your site unprotected.<\/p>"},"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3726360,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3726360,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3726360,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3726360,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["6.92.0"],"block_files":[],"assets_screenshots":{"screenshot-1.png":{"filename":"screenshot-1.png","revision":3726360,"resolution":"1","location":"assets","locale":"","width":1440,"height":1150},"screenshot-2.png":{"filename":"screenshot-2.png","revision":3726360,"resolution":"2","location":"assets","locale":"","width":1440,"height":1150},"screenshot-3.png":{"filename":"screenshot-3.png","revision":3726360,"resolution":"3","location":"assets","locale":"","width":1440,"height":1150},"screenshot-4.png":{"filename":"screenshot-4.png","revision":3726360,"resolution":"4","location":"assets","locale":"","width":1440,"height":1150},"screenshot-5.png":{"filename":"screenshot-5.png","revision":3726360,"resolution":"5","location":"assets","locale":"","width":1440,"height":1150}},"screenshots":{"1":"The dashboard. What the ads cost over the period, what came back, and how much of the spend\nwent on visitors worth a second look - each one listed underneath with the reasoning in plain\nlanguage.","2":"Every visitor the plugin has seen, searchable and filterable, with the risk score, the\nnetworks they arrived on and whether they became a lead.","3":"One visitor in full: why they scored what they scored, the device behind the fingerprint, the\naddresses they have used and the ad clicks they arrived on.","4":"Google Ads by campaign - clicks, people, leads, what share was wasted and what that cost,\nfrom your own click log priced at the rate you set.","5":"The exclusion list: the addresses worth excluding, grouped by campaign, ready to paste into\nGoogle Ads, with a plain note on what excluding an address does and does not do."}},"plugin_section":[],"plugin_tags":[149009,22770,4270,985,322],"plugin_category":[],"plugin_contributors":[284207,284208],"plugin_business_model":[],"class_list":["post-379417","plugin","type-plugin","status-publish","hentry","plugin_tags-ad-fraud","plugin_tags-bot-detection","plugin_tags-click-fraud","plugin_tags-google-ads","plugin_tags-ppc","plugin_contributors-clickhelm","plugin_contributors-hanymahfouz","plugin_committers-clickhelm"],"banners":{"banner":"https:\/\/ps.w.org\/clickhelm\/assets\/banner-772x250.png?rev=3726360","banner_2x":"https:\/\/ps.w.org\/clickhelm\/assets\/banner-1544x500.png?rev=3726360","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/clickhelm\/assets\/icon-128x128.png?rev=3726360","icon_2x":"https:\/\/ps.w.org\/clickhelm\/assets\/icon-256x256.png?rev=3726360","generated":false},"screenshots":[{"src":"https:\/\/ps.w.org\/clickhelm\/assets\/screenshot-1.png?rev=3726360","caption":"The dashboard. What the ads cost over the period, what came back, and how much of the spend\nwent on visitors worth a second look - each one listed underneath with the reasoning in plain\nlanguage."},{"src":"https:\/\/ps.w.org\/clickhelm\/assets\/screenshot-2.png?rev=3726360","caption":"Every visitor the plugin has seen, searchable and filterable, with the risk score, the\nnetworks they arrived on and whether they became a lead."},{"src":"https:\/\/ps.w.org\/clickhelm\/assets\/screenshot-3.png?rev=3726360","caption":"One visitor in full: why they scored what they scored, the device behind the fingerprint, the\naddresses they have used and the ad clicks they arrived on."},{"src":"https:\/\/ps.w.org\/clickhelm\/assets\/screenshot-4.png?rev=3726360","caption":"Google Ads by campaign - clicks, people, leads, what share was wasted and what that cost,\nfrom your own click log priced at the rate you set."},{"src":"https:\/\/ps.w.org\/clickhelm\/assets\/screenshot-5.png?rev=3726360","caption":"The exclusion list: the addresses worth excluding, grouped by campaign, ready to paste into\nGoogle Ads, with a plain note on what excluding an address does and does not do."}],"raw_content":"<!--section=description-->\n<p>ClickHelm watches who arrives on your site from Google Ads and works out which of them are\ncosting you money without ever becoming a customer.<\/p>\n\n<p><strong>No limit, no time limit, no card, and nothing to unlock.<\/strong> There is no visit cap, no site\ncount and no key to enter. Everything described below runs on every install, for as long as you\nkeep the plugin.<\/p>\n\n<p><strong>It recognises the person, not the address.<\/strong> Identity comes from a device fingerprint resolved\non your own server, so the same visitor is still the same visitor after clearing their storage,\nswitching browser, or moving from home WiFi to mobile data. An address on its own tells you\nlittle: it changes when a phone's data is turned off and on.<\/p>\n\n<h4>What it shows you<\/h4>\n\n<ul>\n<li><strong>Dashboard<\/strong> \u2014 the traffic you paid for, what it cost, and which visitors are worth a second\nlook today, ranked, each with the reasoning in plain language<\/li>\n<li><strong>Visitors<\/strong> \u2014 everyone seen, searchable and filterable, with the evidence behind each score:\nthe fingerprint, the addresses, the networks, and what they did on each visit<\/li>\n<li><strong>Google Ads<\/strong> \u2014 spend, waste and profit per campaign, ad group, keyword and placement, with\nyour own click log beside the clicks Google actually charged you for<\/li>\n<li><strong>The exclusion list<\/strong> \u2014 every address worth excluding, ready to copy into Google Ads<\/li>\n<li><strong>Possible Duplicates<\/strong> \u2014 fingerprints that probably belong to someone you already know<\/li>\n<\/ul>\n\n<h4>What this edition does not do<\/h4>\n\n<p><strong>It does not block anyone.<\/strong> It shows you who is costing you money and leaves the acting to you.\nCopying addresses into Google Ads by hand works, and is what the exclusion list is for.<\/p>\n\n<p>Automatic blocking, your own rules, the breakdown reports and heatmaps are a separate plugin sold\nfrom clickhelm.com. <strong>None of that code is in this one<\/strong> \u2014 it is not here and switched off, it\nis not here at all.<\/p>\n\n<h4>What it measures<\/h4>\n\n<p>Revenue is read from the actual WooCommerce order on the server, so it counts even when a\nshopper blocks scripts, and it is the real total rather than an estimate. That is what makes\ngenuine per-campaign profit and loss possible.<\/p>\n\n<p>Calls, WhatsApp taps, form submissions, thank-you pages and your own buttons all count as\nleads, so the plugin works for a service business as well as a shop.<\/p>\n\n<h4>Email<\/h4>\n\n<p>A weekly or monthly report summarising what the plugin saw, what it cost you, and which\nvisitors are worth a look, with a link straight to each one. Switch it on under Settings, and\ntell it not to write when there is nothing to say.<\/p>\n\n<h4>Privacy<\/h4>\n\n<p>Visitor data stays in your own database. One thing can leave it, and only if you say so: visitor\nIP addresses, for address classification. They go to api.clickhelm.com, which asks proxycheck.io\nand keeps none of them. <strong>It is off until you switch it on<\/strong> - the setup asks, in plain words,\nand Settings has the switch. Say so in your site's privacy policy if you do switch it on. Old\ndata is cleaned up automatically on a schedule you set.<\/p>\n\n<h3>External services<\/h3>\n\n<p>Every request below leaves from your own server. Nothing is ever sent from a visitor's browser.\nThis plugin does not check a licence, does not look for its own updates - updates come from\nWordPress.org like any other plugin here - and sends no usage reports. The one thing our server\nlearns about your site is described under Address classification below: that it asked, and when.<\/p>\n\n<p><strong>Google Ads<\/strong> (googleads.googleapis.com), only with a licence, and only if you connect an account<\/p>\n\n<p>If you choose to connect Google Ads, the plugin reads your own campaign reporting once a day -\nclick identifiers, campaign and keyword names, and cost figures - so it can compare the clicks\nrecorded on your site against the clicks Google actually charged you for.<\/p>\n\n<p>It changes two things in the account, and only when you switch them on in the plugin: it can add\nClickHelm's tracking template to the account, and it can keep an account-level IP exclusion list\nmade from the visitors you blocked (never anybody you did not block, and never exclusions you added\nyourself). It never touches campaigns, ads, budgets or bids. Our server builds those two changes\nitself and refuses any other kind.<\/p>\n\n<p>The request is routed through api.clickhelm.com because Google requires credentials that cannot\nbe shipped inside a plugin; the reporting data is passed straight through to your site and is\nnot stored on our server. You can disconnect at any time.<\/p>\n\n<p>What is read and why: https:\/\/clickhelm.com\/google-ads-data\nTerms: https:\/\/clickhelm.com\/terms\nPrivacy: https:\/\/clickhelm.com\/privacy<\/p>\n\n<p><strong>Address classification<\/strong> (api.clickhelm.com, then proxycheck.io)<\/p>\n\n<p>This one is off until you switch it on, and the setup asks. A visitor arriving from a data centre, a VPN\nor a commercial proxy is the cheapest kind of fraudulent click there is, and telling them apart\nfrom a real customer cannot be done on your own server - it needs a database of who owns which\nnetwork, kept current by somebody whose job that is.<\/p>\n\n<p>So the plugin sends visitor IP addresses to api.clickhelm.com, which passes them to\nproxycheck.io under our account and hands the answer back: country, network operator, and\nwhether the address belongs to a VPN, proxy, Tor exit or data centre. Each address is looked up\nonce and remembered on your site, so a returning visitor costs nothing.<\/p>\n\n<p>Our server keeps none of the addresses. They are relayed and discarded within the request; what\nit records is how many were classified, never which - together with the address of the site that\nasked, the plugin version and the time. That record is what enforces each site's daily allowance,\nand it is kept for nothing else. You do not need an account anywhere and there is no key to\nenter.<\/p>\n\n<p>The same answer can carry short notices from ClickHelm - that a new version is out, or something\nabout security - which the plugin shows at the top of its own screens, never elsewhere in\nWordPress, in whichever of English or Arabic you read ClickHelm in. Nothing is sent to ask for them,\nand each can be dismissed.<\/p>\n\n<p>Because visitor IP addresses leave your server, say so in your site's privacy policy.<\/p>\n\n<p>Terms: https:\/\/clickhelm.com\/terms\nPrivacy: https:\/\/clickhelm.com\/privacy\nproxycheck.io terms: https:\/\/proxycheck.io\/terms\nproxycheck.io privacy: https:\/\/proxycheck.io\/privacy<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Upload the plugin folder to <code>\/wp-content\/plugins\/<\/code>, or install the zip from\nPlugins \u2192 Add New \u2192 Upload Plugin.<\/li>\n<li>Activate it. The database tables are created automatically.<\/li>\n<li>Open <strong>ClickHelm \u2192 Settings<\/strong> and set your average cost per click, so the plugin\ncan show what traffic is costing you rather than hiding every money figure.<\/li>\n<li>Open <strong>ClickHelm \u2192 Google Ads \u2192 Setup &amp; names<\/strong> and paste the tracking template\ninto Google Ads. Without it, Google does not tell the plugin which campaign a click came\nfrom, and that information cannot be recovered afterwards.<\/li>\n<\/ol>\n\n<!--section=faq-->\n<dl>\n<dt id=\"can%20it%20get%20my%20money%20back%20from%20google%3F\"><h3>Can it get my money back from Google?<\/h3><\/dt>\n<dd><p>It can help you ask, and Google decides. Google credits the invalid clicks it detects by\nitself, automatically. For the ones it missed you can ask it to investigate any click from the\nlast 60 days, through its Click Quality form, and it wants evidence only your website has:\neach click's IP address, browser and click id, and why it looks invalid. <strong>Google Ads \u2192\nRefund claim<\/strong> puts that together - an evidence file, and a letter in English to paste into\nthe form. Nothing guarantees a refund, and be wary of anything that promises one. What the\nplugin does by itself is stop the same person costing you again, and show you which\ncampaigns and keywords are worth cutting.<\/p><\/dd>\n<dt id=\"does%20this%20plugin%20block%20anyone%3F\"><h3>Does this plugin block anyone?<\/h3><\/dt>\n<dd><p>No. It identifies, scores and explains, and the acting is yours: the exclusion list gives you\nevery address worth excluding, ready to paste into Google Ads. Automatic blocking is a separate\nplugin from clickhelm.com, and none of its code is in this one.<\/p><\/dd>\n<dt id=\"the%20same%20person%20keeps%20coming%20back%20under%20a%20new%20fingerprint.\"><h3>The same person keeps coming back under a new fingerprint.<\/h3><\/dt>\n<dd><p>Open <strong>Possible Duplicates<\/strong>. The plugin has probably already spotted the match and is waiting\nfor you to confirm it \u2014 lower the confidence threshold in Settings to catch more. Confirming a\nmatch folds the two together, so the history and the score follow the person rather than the\nbrowser they happened to use.<\/p><\/dd>\n<dt id=\"does%20it%20work%20with%20page%20caching%3F\"><h3>Does it work with page caching?<\/h3><\/dt>\n<dd><p>Yes. Nothing this plugin does depends on a page being uncached: the visit is recorded from the\nbrowser, so a cached page is measured exactly like an uncached one.<\/p><\/dd>\n<dt id=\"will%20it%20slow%20my%20site%20down%3F\"><h3>Will it slow my site down?<\/h3><\/dt>\n<dd><p>The tracking script is small and loads without blocking the page. Everything else \u2014 the\nscoring, the matching, the address classification \u2014 happens after the request the visitor\nsees, on a schedule.<\/p><\/dd>\n<dt id=\"what%20happens%20to%20my%20data%20if%20i%20delete%20the%20plugin%3F\"><h3>What happens to my data if I delete the plugin?<\/h3><\/dt>\n<dd><p>Nothing, unless you asked for it. Deleting leaves your visitors and their history intact\nso a reinstall picks up where you left off. To erase everything, tick the option under\nSettings \u2192 Housekeeping first.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>6.92.0<\/h4>\n\n<ul>\n<li><strong>Classifying a visitor's address is now off until you ask for it.<\/strong> The setup asks in plain\nwords what is sent and what saying no costs, and Settings carries the switch. It was on from\nthe first page view of a fresh install, which is what WordPress.org's guideline 7 forbids and\nwhat their review pulled us up on - rightly.<\/li>\n<li><strong>Heatmaps are out of this edition entirely.<\/strong> The recording, the settings and the flag that\nheld them shut are all gone from the file rather than disabled inside it.<\/li>\n<li>The plugin's own description on the Plugins screen described the paid edition - blocking, rules\nand automatic Google Ads exclusions, none of which are here. It describes this one now.<\/li>\n<li>This edition no longer deactivates another copy of ClickHelm, and no longer carries the code\nthat did.<\/li>\n<li>The one script printed into the page markup moved into the plugin's own JavaScript file.<\/li>\n<li>Translations come from translate.wordpress.org for this edition, so no catalogues ship inside\nit and nothing loads them early.<\/li>\n<li>The readme no longer says the address record is used to count how many sites run the free\nedition. It is not, any more.<\/li>\n<\/ul>\n\n<h4>6.91.0<\/h4>\n\n<ul>\n<li>Tested against WordPress 7.1.<\/li>\n<li>The plugin is credited to the ClickHelm account, which owns it, with its developer listed\nalongside so support questions reach a person.<\/li>\n<li><strong>Fixed: an admin page load could erase the campaign behind arrivals it had already recorded.<\/strong>\nThe backfill that reads ad parameters out of each stored landing-page URL wrote its answer for\nevery field, including the ones the URL said nothing about - so any arrival whose campaign came\nfrom somewhere else lost it. Measured on a test site: one page load erased the campaign, ad\ngroup, keyword, match type, network and device from 487 of 1,689 arrivals. It now fills blanks\nand never overwrites.<\/li>\n<li><strong>Fixed: the free edition's tab strip linked to three screens it does not have.<\/strong> Reports,\nRules and Your plan were still printed above every screen; opening one answered \"you are not\nallowed to access this page\".<\/li>\n<li>The free edition no longer carries the paid features at all. Blocking, rules, reports and\nheatmaps used to ship inside it behind a licence check, and the month was capped at 500\nvisits. Both are gone from this build: the code is not there to unlock, and nothing counts\ndown. What the free edition does, it does without limit.<\/li>\n<li>Percentages, and the three words under every dashboard figure - no change, nothing to\ncompare, flat - are translated. They were English in every language.<\/li>\n<li>The renewal-date arithmetic no longer depends on PHP's default timezone.<\/li>\n<li>A search containing an apostrophe now finds what it should on the Visitors screen.<\/li>\n<li>Escaping, unslashing and the code comments that explain both, throughout - for the\nWordPress.org review.<\/li>\n<\/ul>\n\n<h4>6.90.2<\/h4>\n\n<ul>\n<li>Housekeeping only: the plugin is credited to its developer\u2019s WordPress.org account. Nothing\nin the plugin itself changed.<\/li>\n<\/ul>\n\n<h4>6.90.1<\/h4>\n\n<ul>\n<li><strong>Fixed: a keyword running in more than one ad group reported clicks as coming from before\nClickHelm was installed.<\/strong> The Keywords tab counted only the last ad group\u2019s share of the\ncharged clicks, so the rest were labelled \"before tracking started\" on sites where every\nclick was inside the window. The rest of the 6.89.0 keyword fix was correct; this one column\nis built elsewhere and was missed.<\/li>\n<li><strong>Fixed: every install and every upgrade logged two database errors.<\/strong> Comments written\ninside the table definitions were read as columns, producing two invalid statements that\nadded nothing \u2014 harmless, but the first thing anybody debugging a real problem would meet.<\/li>\n<\/ul>\n\n<p>The releases before 6.90.0 are in changelog.txt, which ships with the plugin.<\/p>","raw_excerpt":"Shows which Google Ads clicks are wasting your budget, and recognises visitors by device, so the same person is the same person however they return.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/it.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/379417","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/it.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/it.wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/it.wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=379417"}],"author":[{"embeddable":true,"href":"https:\/\/it.wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/clickhelm"}],"wp:attachment":[{"href":"https:\/\/it.wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=379417"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/it.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=379417"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/it.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=379417"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/it.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=379417"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/it.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=379417"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/it.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=379417"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}