ClickHelm – Click Fraud Protection & Bot Blocking

Description

ClickHelm watches who arrives on your site from Google Ads and works out which of them are
costing you money without ever becoming a customer.

No limit, no time limit, no card, and nothing to unlock. There is no visit cap, no site
count and no key to enter. Everything described below runs on every install, for as long as you
keep the plugin.

It recognises the person, not the address. Identity comes from a device fingerprint resolved
on your own server, so the same visitor is still the same visitor after clearing their storage,
switching browser, or moving from home WiFi to mobile data. An address on its own tells you
little: it changes when a phone’s data is turned off and on.

What it shows you

  • Dashboard — the traffic you paid for, what it cost, and which visitors are worth a second
    look today, ranked, each with the reasoning in plain language
  • Visitors — everyone seen, searchable and filterable, with the evidence behind each score:
    the fingerprint, the addresses, the networks, and what they did on each visit
  • Google Ads — spend, waste and profit per campaign, ad group, keyword and placement, with
    your own click log beside the clicks Google actually charged you for
  • The exclusion list — every address worth excluding, ready to copy into Google Ads
  • Possible Duplicates — fingerprints that probably belong to someone you already know

What this edition does not do

It does not block anyone. It shows you who is costing you money and leaves the acting to you.
Copying addresses into Google Ads by hand works, and is what the exclusion list is for.

Automatic blocking, your own rules, the breakdown reports and heatmaps are a separate plugin sold
from clickhelm.com. None of that code is in this one — it is not here and switched off, it
is not here at all.

What it measures

Revenue is read from the actual WooCommerce order on the server, so it counts even when a
shopper blocks scripts, and it is the real total rather than an estimate. That is what makes
genuine per-campaign profit and loss possible.

Calls, WhatsApp taps, form submissions, thank-you pages and your own buttons all count as
leads, so the plugin works for a service business as well as a shop.

Email

A weekly or monthly report summarising what the plugin saw, what it cost you, and which
visitors are worth a look, with a link straight to each one. Switch it on under Settings, and
tell it not to write when there is nothing to say.

Privacy

Visitor data stays in your own database. One thing can leave it, and only if you say so: visitor
IP addresses, for address classification. They go to api.clickhelm.com, which asks proxycheck.io
and keeps none of them. It is off until you switch it on – the setup asks, in plain words,
and Settings has the switch. Say so in your site’s privacy policy if you do switch it on. Old
data is cleaned up automatically on a schedule you set.

External services

Every request below leaves from your own server. Nothing is ever sent from a visitor’s browser.
This plugin does not check a licence, does not look for its own updates – updates come from
WordPress.org like any other plugin here – and sends no usage reports. The one thing our server
learns about your site is described under Address classification below: that it asked, and when.

Google Ads (googleads.googleapis.com), only with a licence, and only if you connect an account

If you choose to connect Google Ads, the plugin reads your own campaign reporting once a day –
click identifiers, campaign and keyword names, and cost figures – so it can compare the clicks
recorded on your site against the clicks Google actually charged you for.

It changes two things in the account, and only when you switch them on in the plugin: it can add
ClickHelm’s tracking template to the account, and it can keep an account-level IP exclusion list
made from the visitors you blocked (never anybody you did not block, and never exclusions you added
yourself). It never touches campaigns, ads, budgets or bids. Our server builds those two changes
itself and refuses any other kind.

The request is routed through api.clickhelm.com because Google requires credentials that cannot
be shipped inside a plugin; the reporting data is passed straight through to your site and is
not stored on our server. You can disconnect at any time.

What is read and why: https://clickhelm.com/google-ads-data
Terms: https://clickhelm.com/terms
Privacy: https://clickhelm.com/privacy

Address classification (api.clickhelm.com, then proxycheck.io)

This one is off until you switch it on, and the setup asks. A visitor arriving from a data centre, a VPN
or a commercial proxy is the cheapest kind of fraudulent click there is, and telling them apart
from a real customer cannot be done on your own server – it needs a database of who owns which
network, kept current by somebody whose job that is.

So the plugin sends visitor IP addresses to api.clickhelm.com, which passes them to
proxycheck.io under our account and hands the answer back: country, network operator, and
whether the address belongs to a VPN, proxy, Tor exit or data centre. Each address is looked up
once and remembered on your site, so a returning visitor costs nothing.

Our server keeps none of the addresses. They are relayed and discarded within the request; what
it records is how many were classified, never which – together with the address of the site that
asked, the plugin version and the time. That record is what enforces each site’s daily allowance,
and it is kept for nothing else. You do not need an account anywhere and there is no key to
enter.

The same answer can carry short notices from ClickHelm – that a new version is out, or something
about security – which the plugin shows at the top of its own screens, never elsewhere in
WordPress, in whichever of English or Arabic you read ClickHelm in. Nothing is sent to ask for them,
and each can be dismissed.

Because visitor IP addresses leave your server, say so in your site’s privacy policy.

Terms: https://clickhelm.com/terms
Privacy: https://clickhelm.com/privacy
proxycheck.io terms: https://proxycheck.io/terms
proxycheck.io privacy: https://proxycheck.io/privacy

Screenshots

Installation

  1. Upload the plugin folder to /wp-content/plugins/, or install the zip from Plugins Add New Upload Plugin.
  2. Activate it. The database tables are created automatically.
  3. Open ClickHelm Settings and set your average cost per click, so the plugin can show what traffic is costing you rather than hiding every money figure.
  4. Open ClickHelm Google Ads Setup & names and paste the tracking template into Google Ads. Without it, Google does not tell the plugin which campaign a click came from, and that information cannot be recovered afterwards.

FAQ

Can it get my money back from Google?

It can help you ask, and Google decides. Google credits the invalid clicks it detects by
itself, automatically. For the ones it missed you can ask it to investigate any click from the
last 60 days, through its Click Quality form, and it wants evidence only your website has:
each click’s IP address, browser and click id, and why it looks invalid. Google Ads
Refund claim
puts that together – an evidence file, and a letter in English to paste into
the form. Nothing guarantees a refund, and be wary of anything that promises one. What the
plugin does by itself is stop the same person costing you again, and show you which
campaigns and keywords are worth cutting.

Does this plugin block anyone?

No. It identifies, scores and explains, and the acting is yours: the exclusion list gives you
every address worth excluding, ready to paste into Google Ads. Automatic blocking is a separate
plugin from clickhelm.com, and none of its code is in this one.

The same person keeps coming back under a new fingerprint.

Open Possible Duplicates. The plugin has probably already spotted the match and is waiting
for you to confirm it — lower the confidence threshold in Settings to catch more. Confirming a
match folds the two together, so the history and the score follow the person rather than the
browser they happened to use.

Does it work with page caching?

Yes. Nothing this plugin does depends on a page being uncached: the visit is recorded from the
browser, so a cached page is measured exactly like an uncached one.

Will it slow my site down?

The tracking script is small and loads without blocking the page. Everything else — the
scoring, the matching, the address classification — happens after the request the visitor
sees, on a schedule.

What happens to my data if I delete the plugin?

Nothing, unless you asked for it. Deleting leaves your visitors and their history intact
so a reinstall picks up where you left off. To erase everything, tick the option under
Settings Housekeeping first.

Reviews

There are no reviews for this plugin.

Contributors & Developers

“ClickHelm – Click Fraud Protection & Bot Blocking” adalah perisian sumber terbuka. Orang-orang berikut telah menyumbang kepada pemalam ini.

Penyumbang

Changelog

6.92.0

  • Classifying a visitor’s address is now off until you ask for it. The setup asks in plain
    words what is sent and what saying no costs, and Settings carries the switch. It was on from
    the first page view of a fresh install, which is what WordPress.org’s guideline 7 forbids and
    what their review pulled us up on – rightly.
  • Heatmaps are out of this edition entirely. The recording, the settings and the flag that
    held them shut are all gone from the file rather than disabled inside it.
  • The plugin’s own description on the Plugins screen described the paid edition – blocking, rules
    and automatic Google Ads exclusions, none of which are here. It describes this one now.
  • This edition no longer deactivates another copy of ClickHelm, and no longer carries the code
    that did.
  • The one script printed into the page markup moved into the plugin’s own JavaScript file.
  • Translations come from translate.wordpress.org for this edition, so no catalogues ship inside
    it and nothing loads them early.
  • The readme no longer says the address record is used to count how many sites run the free
    edition. It is not, any more.

6.91.0

  • Tested against WordPress 7.1.
  • The plugin is credited to the ClickHelm account, which owns it, with its developer listed
    alongside so support questions reach a person.
  • Fixed: an admin page load could erase the campaign behind arrivals it had already recorded.
    The backfill that reads ad parameters out of each stored landing-page URL wrote its answer for
    every field, including the ones the URL said nothing about – so any arrival whose campaign came
    from somewhere else lost it. Measured on a test site: one page load erased the campaign, ad
    group, keyword, match type, network and device from 487 of 1,689 arrivals. It now fills blanks
    and never overwrites.
  • Fixed: the free edition’s tab strip linked to three screens it does not have. Reports,
    Rules and Your plan were still printed above every screen; opening one answered “you are not
    allowed to access this page”.
  • The free edition no longer carries the paid features at all. Blocking, rules, reports and
    heatmaps used to ship inside it behind a licence check, and the month was capped at 500
    visits. Both are gone from this build: the code is not there to unlock, and nothing counts
    down. What the free edition does, it does without limit.
  • Percentages, and the three words under every dashboard figure – no change, nothing to
    compare, flat – are translated. They were English in every language.
  • The renewal-date arithmetic no longer depends on PHP’s default timezone.
  • A search containing an apostrophe now finds what it should on the Visitors screen.
  • Escaping, unslashing and the code comments that explain both, throughout – for the
    WordPress.org review.

6.90.2

  • Housekeeping only: the plugin is credited to its developer’s WordPress.org account. Nothing
    in the plugin itself changed.

6.90.1

  • Fixed: a keyword running in more than one ad group reported clicks as coming from before
    ClickHelm was installed.
    The Keywords tab counted only the last ad group’s share of the
    charged clicks, so the rest were labelled “before tracking started” on sites where every
    click was inside the window. The rest of the 6.89.0 keyword fix was correct; this one column
    is built elsewhere and was missed.
  • Fixed: every install and every upgrade logged two database errors. Comments written
    inside the table definitions were read as columns, producing two invalid statements that
    added nothing — harmless, but the first thing anybody debugging a real problem would meet.

The releases before 6.90.0 are in changelog.txt, which ships with the plugin.