{"id":353608,"date":"2026-08-28T02:48:17","date_gmt":"2026-08-28T02:48:17","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/click-guardian-for-google-ads-click-fraud-protection-gclid-tracking\/"},"modified":"2026-08-28T02:47:30","modified_gmt":"2026-08-28T02:47:30","slug":"vetraclix-for-google-ads","status":"publish","type":"plugin","link":"https:\/\/azb.wordpress.org\/plugins\/vetraclix-for-google-ads\/","author":21149320,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"1.0.2","stable_tag":"1.0.2","tested":"7.0.4","requires":"6.2","requires_php":"8.1","requires_plugins":null,"header_name":"Vetraclix for Google Ads - Click Fraud Protection & GCLID Tracking","header_author":"Muhammad Arfa Rehman","header_description":"Captures, validates, and gates Google Ads (GCLID), Microsoft Ads, and Meta ad clicks so recycled, shared, expired, or suspicious clicks can no longer fire your tracking scripts or submit your forms.","assets_banners_color":"61a1c0","last_updated":"2026-08-28 02:47:30","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"","header_author_uri":"https:\/\/www.arfarehman.net\/","rating":0,"author_block_rating":0,"active_installs":0,"downloads":41,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"1.0.2":{"tag":"1.0.2","author":"arfarehman","date":"2026-08-28 02:47:30","revision":3669715}},"upgrade_notice":{"1.0.1":"<p>Bug-fix release: resolves a WordPress 6.7+ early-translation-loading notice and hardens database queries. No settings or data changes.<\/p>","1.0.0":"<p>Initial release.<\/p>"},"ratings":[],"assets_icons":{"icon-256x256.png":{"filename":"icon-256x256.png","revision":3669724,"resolution":"256x256","location":"assets","locale":"","width":1254,"height":1254}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3669724,"resolution":"1544x500","location":"assets","locale":"","width":1983,"height":793}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["1.0.2"],"block_files":[],"assets_screenshots":[],"screenshots":{"1":"Dashboard: status counters, 30-day activity chart, most-reused clicks, top countries, and most-blocked visitors.","2":"Click Records: every captured click with its status, confidence score, and expandable event history.","3":"Settings: seven tabs covering detection, protection, the blocked page, forms, tracking IDs, privacy, and advanced options.","4":"Protection settings, including the fully adjustable confidence-scoring weights.","5":"The blocked-click notice a visitor sees, with configurable wording and colours.","6":"Diagnostics: current configuration, CDN detection, and detected form plugins."}},"plugin_section":[],"plugin_tags":[4270,986,34183,985,322],"plugin_category":[],"plugin_contributors":[264704],"plugin_business_model":[],"class_list":["post-353608","plugin","type-plugin","status-publish","hentry","plugin_tags-click-fraud","plugin_tags-conversion-tracking","plugin_tags-gclid","plugin_tags-google-ads","plugin_tags-ppc","plugin_contributors-arfarehman","plugin_committers-arfarehman"],"banners":[],"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/vetraclix-for-google-ads\/assets\/icon-256x256.png?rev=3669724","icon_2x":"https:\/\/ps.w.org\/vetraclix-for-google-ads\/assets\/icon-256x256.png?rev=3669724","generated":false},"screenshots":[],"raw_content":"<!--section=description-->\n<p>Every paid click that reaches your site carries a click identifier - <code>gclid<\/code> from Google Ads, <code>msclkid<\/code> from Microsoft Advertising, <code>fbclid<\/code> from Meta. Those identifiers are meant to be used once, by one visitor. In practice they get shared in messages, pasted into forums, replayed by bots, indexed by scrapers, and clicked again days later by people who never saw your ad.<\/p>\n\n<p>Every one of those replays looks to your analytics exactly like a fresh paid click. Your conversion data drifts. Your cost-per-lead looks wrong. And your sales team calls leads that came from an ad click nobody paid for.<\/p>\n\n<p><strong>Vetraclix records every ad click the first time it arrives, then refuses to let it count twice.<\/strong><\/p>\n\n<h4>How it works<\/h4>\n\n<ol>\n<li><strong>Capture.<\/strong> When a visitor arrives with an ad click identifier in the URL, it is recorded server-side, before your theme renders anything.<\/li>\n<li><strong>Clean.<\/strong> The click identifier and campaign parameters are removed from the visible address bar, so they never land in browser history and never travel in a copied link.<\/li>\n<li><strong>Score.<\/strong> If the same identifier comes back, it is scored 0-100 on how suspicious the repeat looks: a changed IP address, a changed device, a changed country, how quickly it was reused, how many times it has been seen, and how late in its lifetime it reappeared.<\/li>\n<li><strong>Act.<\/strong> Depending on the resulting status, tracking scripts are withheld, form submissions are refused, and the visitor can be shown a branded notice or quietly redirected to a clean version of the page.<\/li>\n<\/ol>\n\n<p>Genuine visitors are never affected. Organic and direct traffic carries no click identifier at all and is ignored completely.<\/p>\n\n<h4>What makes it different<\/h4>\n\n<ul>\n<li><strong>It blocks before your page loads, not after.<\/strong> Most approaches hide something in the footer, long after the tracking script in your <code>&lt;head&gt;<\/code> has already fired and already counted the visit. Vetraclix intercepts on <code>template_redirect<\/code>, before your theme is loaded at all, so a bad click never reaches a single tracking tag.<\/li>\n<li><strong>It works with the tags you already have.<\/strong> There is no need to rip out Google Tag Manager or move your pixels. Wrap them in one function call and they are gated automatically.<\/li>\n<li><strong>It makes no external requests.<\/strong> No third-party fraud API, no geolocation service, no account to sign up for, no data leaves your server. Country data is read from headers your CDN already sends.<\/li>\n<li><strong>Nothing is hard-coded.<\/strong> Expiration windows, scoring weights, which networks to watch, what visitors see, which forms are protected, how long data is kept - all of it is configurable from the settings screen.<\/li>\n<\/ul>\n\n<h4>Ad networks supported<\/h4>\n\n<p>Google Ads (<code>gclid<\/code>, <code>gbraid<\/code>, <code>wbraid<\/code>), Microsoft Advertising (<code>msclkid<\/code>), Meta Ads (<code>fbclid<\/code>), TikTok (<code>ttclid<\/code>), X\/Twitter (<code>twclid<\/code>), LinkedIn (<code>li_fat_id<\/code>), Pinterest (<code>epik<\/code>), and Impact\/affiliate (<code>irclickid<\/code>). Enable only the networks you actually advertise on.<\/p>\n\n<h4>Form protection<\/h4>\n\n<p>Submissions made under an invalid click session are rejected and logged, with built-in integrations for <strong>Contact Form 7<\/strong>, <strong>Gravity Forms<\/strong>, <strong>WPForms<\/strong>, <strong>Fluent Forms<\/strong>, <strong>Elementor Forms<\/strong>, and <strong>Forminator<\/strong>. Each one can be switched on or off individually, and the rejection message is yours to write.<\/p>\n\n<h4>Gating your own tracking<\/h4>\n\n<p>In PHP:<\/p>\n\n<pre><code>if ( function_exists( 'click_guardian_can_track' ) &amp;&amp; click_guardian_can_track() ) {\n    \/\/ Print or enqueue your conversion tag here.\n}\n<\/code><\/pre>\n\n<p>In JavaScript:<\/p>\n\n<pre><code>window.ClickGuardian.whenTrackable( function () {\n    \/\/ Fire your conversion event here.\n} );\n<\/code><\/pre>\n\n<p>Both answer \"yes\" when the plugin is deactivated, so a gated tag can never be silently lost.<\/p>\n\n<h4>Reporting<\/h4>\n\n<p>A dashboard with status counters and a 30-day activity chart; a searchable, filterable record of every click with its score and full visit history; a grouped event log; CSV export; and a diagnostics screen showing exactly what the plugin is configured to do and what it can see.<\/p>\n\n<h4>Privacy<\/h4>\n\n<p>IP addresses and user agents are stored as a salted, one-way SHA-256 hash - enough to recognise the same visitor reusing a click, impossible to reverse. Storing readable IP addresses alongside the hash is a separate setting you can leave switched off; if you turn it on, disclose it in your privacy policy. The plugin's own click-fraud detection makes no external requests and sends no data anywhere outside your own site.<\/p>\n\n<h3>External services<\/h3>\n\n<p>This plugin's own fraud-detection engine makes no external requests. It has one optional, off-by-default feature that does: <strong>Print Snippets For Me<\/strong>, under Settings \u2192 Tracking IDs. It exists only for sites with no tag manager already installed; when enabled, it loads the tracking scripts for the ad network IDs you enter, gated behind the same click-validity check the rest of the plugin uses. No account is created and no data is sent to these services by the plugin itself beyond loading the script you asked for; whatever that script then does is between your site and the ad network, governed by that network's own terms.<\/p>\n\n<ul>\n<li><strong>Google (Google Tag Manager, gtag.js, Google Analytics\/GA4, Google Ads)<\/strong> - loads <code>googletagmanager.com\/gtm.js<\/code> and\/or <code>googletagmanager.com\/gtag\/js<\/code> when a GTM container ID, GA4 measurement ID, or Google Ads conversion ID is entered and this feature is enabled. Sent when: on every page load where tracking is allowed. <a href=\"https:\/\/policies.google.com\/terms\">Google Terms of Service<\/a>, <a href=\"https:\/\/policies.google.com\/privacy\">Google Privacy Policy<\/a>.<\/li>\n<li><strong>Microsoft Advertising (Microsoft\/Bing UET)<\/strong> - loads <code>bat.bing.com\/bat.js<\/code> when a UET tag ID is entered and this feature is enabled. Sent when: on every page load where tracking is allowed. <a href=\"https:\/\/www.microsoft.com\/en-us\/servicesagreement\">Microsoft Services Agreement<\/a>, <a href=\"https:\/\/privacy.microsoft.com\/en-us\/privacystatement\">Microsoft Privacy Statement<\/a>.<\/li>\n<li><strong>Meta (Meta Pixel)<\/strong> - loads <code>connect.facebook.net\/en_US\/fbevents.js<\/code> and sends a PageView event when a Pixel ID is entered and this feature is enabled. Sent when: on every page load where tracking is allowed. <a href=\"https:\/\/www.facebook.com\/legal\/terms\">Meta Terms of Service<\/a>, <a href=\"https:\/\/www.facebook.com\/privacy\/policy\/\">Meta Privacy Policy<\/a>.<\/li>\n<\/ul>\n\n<p>If you already have any of these tags installed through a tag manager or another plugin, leave <strong>Print Snippets For Me<\/strong> off and gate your existing tags with <code>click_guardian_can_track()<\/code> instead - see \"Gating your own tracking\" above.<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Install through <strong>Plugins \u2192 Add New<\/strong>, or upload the plugin folder to <code>\/wp-content\/plugins\/<\/code>.<\/li>\n<li>Activate it through the <strong>Plugins<\/strong> screen.<\/li>\n<li>Go to <strong>Vetraclix \u2192 Settings<\/strong> and tick the ad networks you advertise on under <strong>Detection<\/strong>.<\/li>\n<li>Under <strong>Protection<\/strong>, choose an expiration window. Twelve hours suits most lead-generation campaigns.<\/li>\n<li>Gate your existing tracking tags with <code>click_guardian_can_track()<\/code>, or turn on <strong>Print Snippets For Me<\/strong> under <strong>Tracking IDs<\/strong> if you have no tag manager yet.<\/li>\n<\/ol>\n\n<p>Nothing else is required. Sensible defaults are applied on activation.<\/p>\n\n<!--section=faq-->\n<dl>\n<dt id=\"will%20this%20block%20real%20visitors%3F\"><h3>Will this block real visitors?<\/h3><\/dt>\n<dd><p>No. A visitor with no ad click identifier in their session - all organic, direct, referral and social traffic - is never touched. Only a session that arrived from a paid click can ever be gated, and then only once that click has expired or looks reused.<\/p><\/dd>\n<dt id=\"does%20this%20replace%20google%20ads%20conversion%20tracking%3F\"><h3>Does this replace Google Ads conversion tracking?<\/h3><\/dt>\n<dd><p>No. It controls <em>when<\/em> your existing tags are allowed to fire. It does not replace Google Tag Manager, GA4, or your conversion tags, and it never sends data to Google on your behalf.<\/p><\/dd>\n<dt id=\"i%20already%20have%20google%20tag%20manager.%20should%20i%20use%20the%20built-in%20snippets%3F\"><h3>I already have Google Tag Manager. Should I use the built-in snippets?<\/h3><\/dt>\n<dd><p>No - leave <strong>Print Snippets For Me<\/strong> switched off. It exists for sites with no tag manager at all. If you already have tags installed, printing a second copy would double-count every pageview. Gate your existing tags with <code>click_guardian_can_track()<\/code> instead.<\/p><\/dd>\n<dt id=\"what%20does%20single-use%20mode%20do%3F\"><h3>What does single-use mode do?<\/h3><\/dt>\n<dd><p>A click identifier is valid only for its very first visit. If the same value appears in a URL again - from the same visitor or anyone else - it is immediately expired. This is the strictest setting, and suits businesses that want every click to be strictly one-time.<\/p><\/dd>\n<dt id=\"do%20i%20need%20cloudflare%3F\"><h3>Do I need Cloudflare?<\/h3><\/dt>\n<dd><p>No. A CDN or WAF is detected automatically when present and its headers are used for more accurate IP and country data, at no extra cost. Cloudflare, Amazon CloudFront, Fastly, Sucuri and Akamai are recognised out of the box, and a filter lets you add others. Sites with no CDN work normally; they simply have no country data.<\/p><\/dd>\n<dt id=\"will%20my%20own%20clicks%20be%20recorded%20while%20i%20test%3F\"><h3>Will my own clicks be recorded while I test?<\/h3><\/dt>\n<dd><p>Not if you are signed in. <strong>Ignore Signed-in Users<\/strong> is on by default, precisely because site owners and agencies click their own ads far more often than they expect.<\/p><\/dd>\n<dt id=\"can%20i%20try%20it%20without%20affecting%20visitors%3F\"><h3>Can I try it without affecting visitors?<\/h3><\/dt>\n<dd><p>Yes. Turn <strong>Enable Click Blocking<\/strong> off under <strong>Protection<\/strong>. Clicks are still captured, scored and reported, but no visitor is ever interrupted and no tracking is withheld. Run it that way for a week, look at the records, then decide.<\/p><\/dd>\n<dt id=\"can%20my%20agency%20see%20the%20reports%20without%20being%20an%20administrator%3F\"><h3>Can my agency see the reports without being an administrator?<\/h3><\/dt>\n<dd><p>Yes. Change <strong>Required Capability<\/strong> under <strong>Advanced<\/strong> to a capability their role holds.<\/p><\/dd>\n<dt id=\"does%20it%20make%20my%20site%20slower%3F\"><h3>Does it make my site slower?<\/h3><\/dt>\n<dd><p>No measurable amount. Capture is one indexed database query on a paid-click landing, and nothing at all for organic traffic. There are no external HTTP requests during a page load, and the admin assets load only on the plugin's own screens.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>1.0.2<\/h4>\n\n<ul>\n<li>The optional managed-snippets feature (Google Tag Manager, gtag.js, Microsoft UET, Meta Pixel) now loads through <code>wp_enqueue_script()<\/code> instead of printed <code>&lt;script&gt;<\/code> tags.<\/li>\n<li>Hardened the safety-net output buffer used on <code>template_redirect<\/code> so it never closes a buffer opened by another plugin or the theme.<\/li>\n<li>Documented the optional managed-snippets feature's external services in this readme.<\/li>\n<\/ul>\n\n<h4>1.0.1<\/h4>\n\n<ul>\n<li>Fixed a \"translation loading too early\" notice by deferring form-integration registration to <code>init<\/code>.<\/li>\n<li>Hardened all custom-table queries to use <code>$wpdb-&gt;prepare()<\/code>'s <code>%i<\/code> identifier placeholder instead of raw string interpolation.<\/li>\n<\/ul>\n\n<h4>1.0.0<\/h4>\n\n<ul>\n<li>Initial release.<\/li>\n<\/ul>","raw_excerpt":"Stop recycled, shared and expired ad clicks from firing your tracking scripts or submitting your forms. Works with Google, Microsoft and Meta Ads.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/azb.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/353608","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/azb.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/azb.wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/azb.wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=353608"}],"author":[{"embeddable":true,"href":"https:\/\/azb.wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/arfarehman"}],"wp:attachment":[{"href":"https:\/\/azb.wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=353608"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/azb.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=353608"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/azb.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=353608"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/azb.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=353608"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/azb.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=353608"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/azb.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=353608"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}