Description
★ What Makes TrackSure Different
TrackSure is the only free WordPress plugin that combines server-side conversion tracking (Meta CAPI + GA4 Measurement Protocol) with a complete first-party analytics platform — no GTM required, no external cloud, no monthly fees. Unlike PixelYourSite, TrackSure includes a full analytics dashboard — user journeys, funnels, and attribution — at no extra cost. Unlike GTM-based solutions, it needs no server container, no custom subdomain, and no external hosting.
42% of internet users run ad blockers, and iOS 14+ reduced Meta Pixel reported conversions by 30–40% for most advertisers. TrackSure’s server-side tracking recovers conversions from both, sending events directly from your WordPress server to Meta, GA4, TikTok, Pinterest, and Google Ads — bypassing browser limitations entirely. Setup takes under 3 minutes: paste your Meta Pixel ID and Access Token, and TrackSure handles the browser pixel, Conversion API, event deduplication, and Advanced Matching for maximum Event Match Quality (EMQ).
For WooCommerce Store Owners
If you run WooCommerce and Meta or Google Ads, TrackSure connects your real purchase data directly to your ad platform — bypassing iOS restrictions, ad blockers, and Safari cookie limits. Higher Event Match Quality (EMQ) means better optimization and lower cost-per-acquisition.
For Marketers & Agencies
Get user journey tracking, funnel visualization, multi-touch attribution, and traffic source analysis without paying $500/month for Amplitude or Mixpanel. Five attribution models and an assisted conversions report show exactly which channels drive revenue. Manage multiple client sites from the same plugin.
For Developers
TrackSure exposes a JavaScript API (window.TrackSure.track()), a PHP API, and WordPress hooks (tracksure_filter_event_data, tracksure_conversion_recorded) for custom event tracking with full server-side control — no dependency on browser JavaScript.
window.TrackSure.track('button_click', { button_name: 'Download PDF' });
Documentation | Support | GitHub | Get Pro
What TrackSure Does
Server-Side Conversion Tracking (CAPI)
- Meta Conversion API — send purchase, view content, add to cart, checkout, and page view events server-to-server
- Google Analytics 4 Measurement Protocol — server-side GA4 event forwarding
- TikTok Events API and Pinterest Conversion API (Pro)
- Automatic browser + server event deduplication — each event gets a unique ID shared between client and server so platforms count it once
First-Party Analytics Dashboard
- All analytics data stored in your WordPress database — you own every byte
- Automatic traffic source detection — organic search (Google, Bing, DuckDuckGo), social media (Facebook, Instagram, LinkedIn, TikTok), email, referrals, AI chatbots (ChatGPT, Claude, Perplexity), and direct — identified without UTM tags
- Session-based user journeys with 30-day attribution window (configurable) — complete path from first visit to conversion, including every touchpoint across multiple sessions
- Five attribution models: first-touch, last-touch, linear, time-decay, position-based
- Assisted conversion reporting — see which channels helped even without getting final credit
- Real-time visitors — see who is on your site now and what pages they’re viewing
Goals, Funnels & Conversion Tracking
- Custom conversion goals for form submissions, purchases, downloads, video views, or any event
- Funnel visualization — see where visitors drop off in your checkout or signup flow
- Goal completion rates with trend analysis
- Revenue attribution — connect each sale to its traffic source, campaign, and touchpoint
eCommerce Conversion Tracking
- Auto-tracks the full purchase funnel: product view add to cart checkout purchase
- Works with WooCommerce and FluentCart (Free), Easy Digital Downloads, SureCart, Cartflow, and MemberPress (Pro)
- Revenue attribution — connect each sale to its traffic source and campaign
- Checkout funnel visualization with drop-off rates at each step
Privacy & Compliance
- GDPR and CCPA ready with built-in consent manager support (Cookiebot, CookieYes, OneTrust, and more)
- Cookieless tracking option (uses localStorage instead of cookies — no consent banner required in some jurisdictions)
- IP anonymization, Do Not Track (DNT) support, and WordPress privacy tools integration
- No data leaves your server unless you enable an ad platform destination — with the single exception of the optional IP geolocation lookup, which can be switched off in Settings Privacy
Who Is TrackSure For?
- WooCommerce & FluentCart store owners running paid ads who need more accurate conversion data for Meta, Google Ads, and other platforms
- Bloggers & content creators who want to see which posts bring the most traffic, engagement, and conversions
- Small business owners who need simple, privacy-friendly analytics without Google Analytics complexity
- Digital marketers managing ad campaigns who want user journey tracking, funnel visualization, and multi-touch attribution
- Agencies & freelancers who need analytics and conversion tracking across client sites (Pro includes white label)
- Privacy-focused site owners who want GDPR-compliant analytics without sending data to external services
- Developers who need JavaScript and PHP APIs for custom event tracking with WordPress hooks
Free vs Pro
Free includes everything you need for analytics and conversion tracking:
- First-party analytics dashboard with user journeys, funnels, goals, and attribution
- Real-time visitor tracking
- Meta Pixel + Conversion API (CAPI) server-side tracking
- Google Analytics 4 + Measurement Protocol server-side tracking
- WooCommerce and FluentCart automatic ecommerce tracking
- All form plugins (Contact Form 7, Gravity Forms, WPForms, Fluent Forms, Elementor Forms)
- All page builders (Elementor, Divi, Beaver Builder, Gutenberg, WPBakery, Oxygen, Bricks)
- Five attribution models with assisted conversion reports
- Consent management integration
- Unlimited events and sessions
Pro adds advanced ad platforms and ecommerce integrations:
- 14+ ad platform destinations: TikTok, Pinterest, LinkedIn, Snapchat, Reddit, Google Ads, Microsoft Ads, Twitter/X, Taboola, Outbrain, and more
- Advanced ecommerce: Easy Digital Downloads, SureCart, Cartflow, MemberPress, LearnDash, Amelia, WooCommerce Bookings, GiveWP
- Cart abandonment emails, session recording, heatmaps, cohort analysis, predictive analytics
- Email marketing sync (Mailchimp, ActiveCampaign, Klaviyo)
- White label for agencies
- Priority support with 24-hour response time
Integrations
- eCommerce: WooCommerce, FluentCart, Easy Digital Downloads (Pro), SureCart (Pro), Cartflow (Pro), MemberPress (Pro)
- Forms: Contact Form 7, Gravity Forms, WPForms, Fluent Forms, Elementor Forms
- Builders: Elementor, Divi, Beaver Builder, Gutenberg, WPBakery, Oxygen, Bricks
- Ad Platforms: Meta (Facebook/Instagram), Google Analytics 4, Google Ads (Pro), TikTok (Pro), Pinterest (Pro), LinkedIn (Pro), Snapchat (Pro), Microsoft Ads (Pro), Reddit (Pro), Twitter/X (Pro), Taboola (Pro), Outbrain (Pro)
- Consent: Cookiebot, CookieYes, OneTrust, and custom consent filters
Getting Started
- Install and activate TrackSure Cloud from the WordPress plugin directory
- Visit TrackSure Settings to review tracking and privacy options
- (Optional) Add your Meta Pixel ID + Access Token or GA4 Measurement ID for server-side conversion tracking
- Go to TrackSure Overview — analytics data starts appearing after 1 hour
External services
This plugin connects to external third-party services to provide its functionality. Below is a complete list of all external services used, when they are called, what data is transmitted, and links to their terms of service and privacy policies.
When You Enable Meta Pixel / Conversion API:
- Service: Meta (Facebook) Graph API
- Purpose: Send conversion events (purchases, add-to-cart, page views) to Facebook for ad optimization
- What data is sent: Event name, timestamp, hashed user email/phone (if available), product SKU, revenue, IP address, user agent, pixel ID
- When it’s sent: Automatically when a tracked event occurs (product view, purchase, etc.) and Meta destination is enabled in settings
- Service provider: Meta Platforms, Inc.
- Terms of Service: https://www.facebook.com/legal/terms
- Privacy Policy: https://www.facebook.com/privacy/policy
- Data Processing Agreement: https://www.facebook.com/legal/terms/dataprocessing
When You Enable Google Analytics 4:
- Service: Google Analytics 4 Measurement Protocol
- Purpose: Send analytics events to Google Analytics for website traffic analysis
- What data is sent: Event name, page URL, referrer, session ID, client ID, IP address, user agent, device information
- When it’s sent: Automatically when page views or custom events occur and GA4 destination is enabled in settings
- Service provider: Google LLC
- Terms of Service: https://marketingplatform.google.com/about/analytics/terms/us/
- Privacy Policy: https://policies.google.com/privacy
When Loading Google Tag Manager Script (If Enabled):
- Service: Google Tag Manager CDN
- Purpose: Load gtag.js library for browser-side Google Analytics tracking
- What data is sent: Standard HTTP request data (IP address, user agent, referrer) when loading the script
- When it’s sent: On every page load when GA4 browser tracking is enabled
- Service provider: Google LLC
- Script URL: https://www.googletagmanager.com/gtag/js
- Terms of Service: https://marketingplatform.google.com/about/analytics/terms/us/
- Privacy Policy: https://policies.google.com/privacy
When Loading Facebook Pixel Script (If Enabled):
- Service: Facebook Connect CDN
- Purpose: Load fbevents.js library for browser-side Facebook Pixel tracking
- What data is sent: Standard HTTP request data (IP address, user agent, referrer) when loading the script
- When it’s sent: On every page load when Meta Pixel browser tracking is enabled
- Service provider: Meta Platforms, Inc.
- Script URL: https://connect.facebook.net/en_US/fbevents.js
- Terms of Service: https://www.facebook.com/legal/terms
- Privacy Policy: https://www.facebook.com/privacy/policy
Cloudflare IP Detection (Always Active):
- Service: Cloudflare IP Ranges API
- Purpose: Fetch current list of Cloudflare proxy IP addresses to accurately detect real visitor IPs behind Cloudflare CDN. A bundled static list is included as fallback.
- What data is sent: Standard HTTP request headers only (no user data transmitted)
- When it’s sent: Once per day (cached for 24 hours) to refresh the Cloudflare IP list. The plugin includes a bundled fallback list and works without this request.
- Service provider: Cloudflare, Inc.
- API URLs: https://www.cloudflare.com/ips-v4 and https://www.cloudflare.com/ips-v6
- Terms of Service: https://www.cloudflare.com/website-terms/
- Privacy Policy: https://www.cloudflare.com/privacypolicy/
IP Geolocation (When Tracking Is Enabled):
- Service: ipapi.co (primary), ip-api.com (secondary fallback), WordPress.com Geo API (tertiary fallback)
- Purpose: Determine the country, region, and city of visitors based on their IP address for geographic analytics reporting
- What data is sent: The visitor’s IP address is sent to one of the geolocation providers. No other user data is transmitted.
- When it’s sent: When a new visitor session is recorded and the IP has not been looked up recently. Results are cached for 24 hours per IP.
- Service providers and policies:
- ipapi.co (primary) – https://ipapi.co/privacy/ and https://ipapi.co/terms/
- ip-api.com (fallback) – https://ip-api.com/docs/legal
- WordPress.com Geo API (fallback) – https://automattic.com/privacy/ and https://wordpress.com/tos/
- Local sources are tried first: if your site is behind Cloudflare, has the PHP GeoIP extension, or has a local MaxMind database, the country is read from those and no address leaves your server.
- Transport: ipapi.co and the WordPress.com Geo API are contacted over HTTPS. ip-api.com does not offer HTTPS on its free tier, so that fallback is contacted over plain HTTP — it is only reached if ipapi.co has already failed.
- Turning it off: Settings Privacy “Look up visitor location remotely”. Turning it off keeps the local sources above and stops any address being sent to a third party. Developers can also decide per request with the
tracksure_remote_geolocation_enabledfilter.
Important Notes:
- Destinations are opt-in: TrackSure does not send anything to an advertising or analytics platform — Meta, Google Analytics, or any other destination — unless you enable and configure it in TrackSure Settings Destinations. IP geolocation, described above, is the one exception: it runs while tracking is enabled and is not tied to any destination.
- Consent-aware: If you use a cookie consent plugin (Cookiebot, CookieYes, etc.), TrackSure will respect user consent choices and only fire pixels after consent is granted.
- First-party analytics: TrackSure’s core analytics features store all data in your WordPress database. Nothing is sent to an analytics platform unless you enable Google Analytics 4 or another destination. The one external call made without a destination being enabled is the IP geolocation lookup described above, which can be switched off in Settings Privacy.
- You control the data: You choose which platforms to enable, what events to track, and what user data to include (emails, phones, etc.).
For more information about data privacy and compliance, see the Privacy & GDPR Compliance section below.
Source Code & Build Instructions
The admin interface is built with React 18 and TypeScript, compiled with Webpack 5. The compiled files in admin/dist/ are generated from the source code in admin/src/.
Full source code is available on GitHub:
https://github.com/tracksure-cloud/tracksure
To build from source:
- Navigate to the
admin/directory - Run
npm installto install dependencies - Run
npm run buildfor a production build, ornpm run devfor development mode with watch
Build tools used:
- Node.js (v18+)
- npm
- Webpack 5 (config:
admin/webpack.config.js) - TypeScript 5 (config:
admin/tsconfig.json) - ts-loader for TypeScript compilation
Key source directories:
admin/src/— React/TypeScript source code (pages, components, contexts, hooks)admin/dist/— Compiled production JavaScript (generated by Webpack)assets/js/— Frontend tracking scripts (non-compiled, human-readable)includes/— PHP backend (non-compiled, human-readable)
Privacy Policy
TrackSure stores the following data in your WordPress database:
Tracking Data (90-day retention):
– Page URLs visited
– Referrer URLs
– UTM campaign parameters
– Device type (desktop/mobile/tablet)
– Browser and OS information (user agent)
– IP address (can be anonymized)
– Session duration and engagement metrics
For E-commerce (if using WooCommerce/FluentCart/EDD/SureCart):
– Product views
– Cart actions
– Order completion (order ID, total, items)
– Customer email and phone (hashed when sent to Meta/GA4)
External Data Sharing (Optional):
TrackSure stores all analytics data locally in your WordPress database. No data is sent to an ad platform or analytics service unless you enable that integration. The one exception is the IP geolocation lookup used for geographic reporting, described under “External services” above — it is not tied to any integration, and it can be switched off in Settings Privacy.
Privacy Controls:
– IP Anonymization: Available in Settings Privacy. Default is off for accurate geo reporting; enable it for GDPR compliance.
– Cookieless Mode: Uses localStorage instead of cookies to avoid cookie consent requirements.
– Consent Integration: Respects Cookiebot, CookieYes, OneTrust, and custom consent filters.
Supported Third-Party Services:
TrackSure connects to the following services only when you enable them and provide API credentials.
1. Meta (Facebook/Instagram) – Available in Free & Pro
– Method: Server-to-Server via Meta Graph API (CAPI)
– Data Sent: Event data (PageView, ViewContent, AddToCart, Checkout, Purchase), Hashed user data (email, phone, IP, User Agent)
– Purpose: Ad optimization and attribution
2. Google Analytics 4 (GA4) – Available in Free & Pro
– Method: Server-to-Server via Measurement Protocol
– Data Sent: Event parameters, Client ID, User Agent, IP
– Purpose: Analytics reporting
3. Pro-Only Integrations (Add-ons)
– Google Ads: Sends offline conversion adjustments via Google Ads API.
– TikTok: Sends web events via TikTok Events API.
– Pinterest: Sends conversion events via Pinterest API.
– Snapchat: Sends conversion events via Snapchat Conversions API.
– Microsoft Ads: Sends offline conversions via Microsoft Ads API.
– LinkedIn: Sends conversion events via LinkedIn CAPI.
You must obtain user consent before enabling these destinations (GDPR/CCPA requirement).
Your Responsibilities:
- Disclose TrackSure’s tracking in your privacy policy
- Obtain consent before tracking (if required by law)
- Configure data retention periods appropriately
- Enable IP anonymization if required
Data Deletion:
Users can request data deletion via WordPress Privacy Tools or TrackSure Settings Privacy.
Support
Free Support:
- Documentation
- [Community …
Screenshots
















Installation
From WordPress Admin
- Go to Plugins Add New
- Search for “TrackSure”
- Click Install Now, then Activate
Manual Upload
- Download the ZIP from WordPress.org
- Go to Plugins Add New Upload Plugin
- Upload the ZIP, install, and activate
After Activation
- Go to TrackSure Settings
- Tracking is enabled by default — data appears in your dashboard immediately
- (Optional) Add Meta Pixel ID + Access Token or GA4 Measurement ID under Destinations for server-side ad tracking
- If WooCommerce or FluentCart is active, eCommerce events are tracked automatically (EDD, SureCart, Cartflow, MemberPress available in Pro)
FAQ
-
How does TrackSure improve ROAS and lower CPA?
-
When browser-side pixels miss conversions (due to iOS 14+, ad blockers, or cookie restrictions), ad platforms optimize on incomplete data and your cost-per-acquisition rises. TrackSure fixes this by sending conversion events server-to-server via Meta Conversion API and GA4 Measurement Protocol. Browser and server events are deduplicated automatically, so platforms see more of your real conversions without double-counting. More complete data means better optimization and improved Return on Ad Spend.
-
How do I set up the Meta Pixel with server-side tracking?
-
Meta Pixel setup in TrackSure takes under 5 minutes:
- Install and activate TrackSure Cloud
- Go to TrackSure Settings Destinations Meta
- Enter your Pixel ID (from Meta Events Manager)
- Generate and paste a Conversion API Access Token (Events Manager Pixel Settings Conversions API)
- Enable “Server-Side Tracking (CAPI)” and save
TrackSure automatically fires both the browser Meta Pixel and Meta Conversion API (CAPI) events server-to-server. Browser and server events are deduplicated using a shared event_id, so Meta counts each conversion once. User data (email, phone, name, address) is hashed and sent as Advanced Matching parameters for maximum Event Match Quality (EMQ). No Google Tag Manager server container required.
-
What is server-side tracking and why do I need it?
-
Server-side tracking sends conversion events directly from your WordPress server to ad platforms like Meta, Google Analytics, TikTok, and Pinterest — instead of relying only on browser JavaScript pixels. This matters because:
- Ad blockers block ~40% of browser tracking pixels
- iOS 14+ App Tracking Transparency reduced Meta Pixel reported conversions by 30–40%
- Safari ITP limits first-party cookies to 7 days, causing session data loss
- Browser privacy features increasingly restrict third-party tracking
With server-side tracking, your conversion data bypasses all browser restrictions. Ad platforms see your real sales, optimize better, and your ROAS improves. TrackSure sends server-side events directly from WordPress — no GTM server container, no external cloud, no third-party services.
-
Do I need to run ads to use TrackSure?
-
No. TrackSure is a standalone first-party analytics platform that works without any ad platform. You get traffic source tracking, user journeys, content performance, goal tracking, funnel visualization, revenue attribution, and real-time monitoring — all stored in your WordPress database. The ad platform integrations (Meta, Google, TikTok) are optional.
-
What is Meta Conversion API (CAPI)?
-
Meta CAPI (Conversion API) sends conversion events directly from your server to Meta, bypassing browser restrictions. TrackSure handles both the browser Meta Pixel and server-side CAPI automatically. Events are deduplicated using a shared event_id so conversions are never double-counted. See the “How do I set up the Meta Pixel with server-side tracking?” FAQ above for setup steps.
-
Does TrackSure support Google Analytics 4 (GA4)?
-
Yes. TrackSure supports GA4 with both browser-side tracking (gtag.js) and server-side event forwarding via the GA4 Measurement Protocol. This dual approach ensures your GA4 data is accurate even when browsers block tracking scripts.
-
Does TrackSure detect traffic sources without UTM parameters?
-
Yes. TrackSure automatically identifies organic search (Google, Bing, DuckDuckGo etc.), social media (Facebook, Instagram, LinkedIn, TikTok), email clients (Gmail, Outlook), AI chatbots (ChatGPT, Claude, Perplexity), referral sites, and direct traffic. UTM parameters are also captured when present.
-
What eCommerce platforms does TrackSure support?
-
TrackSure auto-tracks the full purchase funnel (product view add to cart checkout purchase) for WooCommerce and FluentCart in the free version. No manual event setup required. Pro adds Easy Digital Downloads, SureCart, Cartflow, MemberPress, LearnDash, Amelia, WooCommerce Bookings, GiveWP, and more.
-
Does TrackSure work with WooCommerce?
-
Yes. TrackSure automatically tracks all WooCommerce ecommerce events: product view, add to cart, remove from cart, initiate checkout, and purchase — including order value, SKU, and product categories. Server-side tracking via Meta CAPI and GA4 Measurement Protocol ensures conversions are captured even when browser tracking is blocked.
-
How do user journeys and funnel tracking work?
-
TrackSure records every page a visitor views across sessions. Go to TrackSure Visitor Journeys to see the complete path from first visit to conversion, including all touchpoints, time between visits, and how many sessions it took to convert. The funnel view shows drop-off rates at each step of your checkout or signup flow.
-
What attribution models are available?
-
Five models are included: First-Touch (credits the channel that first brought the visitor), Last-Touch (credits the final interaction before conversion), Linear (equal credit to all touchpoints), Time-Decay (more credit to recent interactions), and Position-Based (40% first, 40% last, 20% middle). The attribution window defaults to 30 days and is configurable. Assisted conversion reports show which channels helped without getting final credit.
-
Does TrackSure support Google Consent Mode v2?
-
Yes. TrackSure integrates with consent management platforms including Cookiebot, CookieYes, and OneTrust. It respects user consent choices and only fires tracking pixels after consent is granted. Cookieless tracking mode is also available for sites that want to track without cookies or consent banners.
-
Is TrackSure GDPR and CCPA compliant?
-
Yes. TrackSure includes cookieless tracking (localStorage), IP anonymization, Do Not Track (DNT) support, and integrates with consent managers. Users can request data export and deletion through WordPress privacy tools. No data leaves your server unless you enable an ad platform.
-
Will TrackSure slow down my website?
-
No. The tracking script loads asynchronously (non-blocking), events are batched to reduce HTTP requests, database queries use indexed tables, and dashboard metrics are pre-computed. Compatible with WP Rocket, LiteSpeed, W3 Total Cache, Cloudflare, and other caching/CDN solutions.
-
Does TrackSure work with High-Performance Order Storage (HPOS)?
-
Yes. TrackSure is fully compatible with WooCommerce HPOS (High-Performance Order Storage) and uses its own database tables for analytics, so it doesn’t affect your store’s order processing performance.
-
Do I need a GTM server container?
-
No. TrackSure sends server-side events directly from your WordPress server to ad platform APIs. No Google Tag Manager server container, no external cloud hosting, and no custom subdomain setup required.
-
Can I track custom events and goals?
-
Yes. TrackSure provides a JavaScript API and a PHP API for custom events, plus a goal system for tracking form submissions, downloads, video views, purchases, or any custom action.
JavaScript:
window.TrackSure.track('button_click', { button_name: 'Download PDF' });WordPress hooks for developers:
–tracksure_filter_event_data— modify any event before storage
–tracksure_session_started— run custom logic on new sessions
–tracksure_conversion_recorded— sync conversions to CRM, email, or external systems -
What’s the difference between Free and Pro?
-
Free includes: first-party analytics, user journeys, funnel tracking, goals, real-time tracking, Meta Pixel + CAPI, GA4 + Measurement Protocol, WooCommerce and FluentCart auto-tracking, all form plugins, all page builders, all 5 attribution models, assisted conversions, consent management, and unlimited events.
Pro adds: 14+ ad platforms (TikTok, Pinterest, LinkedIn, Snapchat, Reddit, Google Ads, Microsoft Ads, and more), advanced ecommerce integrations (Easy Digital Downloads, SureCart, Cartflow, MemberPress), cart abandonment emails, session recording, heatmaps, cohort analysis, predictive analytics, email marketing sync, white label for agencies, and priority support.
-
Where is my data stored?
-
All tracking data is stored in your WordPress database — not on TrackSure servers or any third party. Raw events are retained for 90 days (configurable: 30/60/90/180 days), and aggregated metrics (no PII) are kept indefinitely. Automatic daily cleanup removes expired data via WP-Cron.
-
Can I export analytics data?
-
Yes. Every report page has a CSV export button. All data is also accessible directly in your WordPress database (
wp_tracksure_events,wp_tracksure_sessions,wp_tracksure_analytics_daily). Pro adds REST API endpoints for programmatic access. -
Does TrackSure work with page builders?
-
Yes — Elementor, Divi, Beaver Builder, Gutenberg, WPBakery, Oxygen, and Bricks are all supported. Page views, button clicks, form submissions, and popup interactions are tracked automatically.
-
Can I use TrackSure on client sites / white label?
-
The free version can be installed on unlimited sites. Pro includes a white label option — rebrand the plugin name, logo, menu, and support URL for your agency.
Reviews
Contributors & Developers
“TrackSure Cloud – Server-Side Tracking, Meta CAPI & GA4 for WooCommerce” is open source software. The following people have contributed to this plugin.
ContributorsInterested in development?
Browse the code, check out the SVN repository, or subscribe to the development log by RSS.
Changelog
1.2.9 – 2026-08-26
Traffic sources — where your visitors came from
- Fix: an ad click reached the server with nothing to say it had been paid for. The tracker read every advertising click identifier out of the address — Google, Microsoft, Meta, TikTok, Reddit, LinkedIn, Snapchat, X — and then left all of them behind when it reported the visit, so the server was asked to identify an unlabelled click from a referrer that either named the wrong thing or said nothing at all. A Search ad, which arrives with no referrer, was recorded as direct. On one site this was a fifth of all traffic and almost the whole of its advertising.
- Fix: an ad shown on YouTube was reported as somebody sharing a video. Google identifies a Search ad and a video ad the same way, and only the referrer separates them, so the identifier is now read for whether the visit was paid for and the referrer for where the ad was seen. Ads on YouTube, Vimeo, Dailymotion and Twitch are reported as paid video; ads on a social platform as paid social.
- New: wbraid and gbraid, which Google sends instead of gclid on iOS, and gad_source, which its newer surfaces send on their own. None were read, so those clicks were invisible as advertising.
- New: dclid, for Display & Video 360.
- Fix: a link tagged with a source and no medium was recorded with a medium of “unknown”, which is not a medium — it says the visit could not be classified. What kind of place the source is, is often known: reddit.com is social and bing.com is a search engine, and a source nobody has heard of is a referral rather than a mystery.
- Fix: “unknown” was also being sent to Google Analytics as a medium, where it matches no channel and files the visit under Unassigned. Placeholders are no longer sent at all, which leaves the tag to read the address for itself.
Reports
- Fix: paid traffic was reported as “other” — the bucket for visits nothing is known about — whenever the campaign tagged itself with anything other than cpc, ppc or paidsearch. utm_medium=paid is the common spelling on a hand-tagged Google or YouTube ad, and TrackSure writes paid_social itself for a click on a TikTok, Reddit, X, Snapchat or LinkedIn ad; none of them were recognised. Google Analytics counts all of these as paid, so the two reports disagreed about the same visit. Whether a paid click is search or social is now decided by the source, against the lists already used to identify search engines and social platforms.
- Fix: the traffic sources report could list one campaign twice. Rows were grouped by the channel name recorded at the time as well as by the source, so a campaign whose name had since been corrected split into two rows carrying the same label. The channel is worked out from the source and medium when the report is built, so the stored name is no longer grouped on and existing history is described by the current rules.
Release packaging
- Improvement: the release build now refuses to run while a database dump, archive, environment file or private key is sitting in the plugin folder, naming what it found. The packaging list said what to leave out, so anything it had not heard of was included.
1.2.8 – 2026-08-22
Tracking accuracy
- Fix: “Track Administrators”, when turned off, now stops events the server records as well as those the browser sends — previously a logged-in administrator placing a test order still had that order sent to Meta and GA4, which is the one thing the setting exists to prevent. The check now happens once, at the single point every integration passes through.
- Fix: repeated events in one session are no longer collapsed into a single row — an event carrying nothing to identify it produced the same event id for the whole session, so only the first occurrence was kept
- Fix: session event counts counted recording attempts rather than events, so an action tracked by both the browser and the server counted twice — genuine single-page visits were never counted as bounces, and the better the tracking worked the lower the bounce rate looked
- Fix: aggregate tables treated an unknown dimension (direct traffic, unknown country, unidentified device) as never matching itself, so every aggregation run inserted a new row instead of updating the previous one and those visits were counted once per run
- Improvement: automatic database migration (DB v1.0.4) folds the affected rows together rather than discarding them — counts are summed, nothing is lost, no manual action required
- Fix: consent decisions recorded with an event are no longer re-read at delivery time, when the visitor’s request has long ended
Traffic sources — where your visitors came from
- Fix: Google Ads and Microsoft Ads clicks were reported as free organic search. Both platforms tag their own clicks (auto-tagging is the default) and add no UTM, so the visit arrives from google.com or bing.com looking exactly like an organic search. The click identifier is now read first, so paid clicks are reported as paid — with or without UTM tags.
- Fix: referrers were matched by looking for a domain anywhere inside the hostname, which misfiled a large amount of traffic. Any host containing “t.co” — including chatgpt.com, client.co.uk and most domains ending in “t.com” — was reported as Twitter; “phoenix.com” was reported as X; “disc.com” as Snapchat. Matching is now on the actual domain, so a site is only credited when the visit genuinely came from it.
- Fix: a visit from another website whose domain merely ended with yours was discarded as your own internal traffic.
- Fix: regional search domains (google.co.uk, google.de, google.com.au, yandex.ru and the rest) are now reported as one source instead of being split per country, and lookalike domains such as “notgoogle.com” are no longer counted as Google.
- Fix: AI assistant referrals now work at the addresses those services actually use — chatgpt.com, gemini.google.com and copilot.microsoft.com were all missed, and Gemini was being reported as an organic Google search because it sits on a Google domain.
- Fix: referrals from the Gmail and other mobile apps were reported as organic Google search.
- Fix: a campaign tagged with utm_source but no utm_medium was filed under “other” alongside unclassifiable traffic instead of being reported as a referral.
- Improvement: Ecosia, Brave Search and Startpage are recognised as search engines.
- Fix: Google Analytics was never told where a visitor came from. The traffic source was read from a field nothing ever filled in, and the parameters it would have sent are not ones Google recognises — so every event the browser tag did not report itself, including sales recorded by the shop, arrived at GA4 unattributed. The campaign now travels the way Google documents, under Google’s own parameter names.
- Improvement: a paid click from Microsoft, TikTok, Reddit, Snapchat, X or LinkedIn is now named to Google Analytics as well. Google reads its own click identifiers and the utm_ parameters; nobody else’s means anything to it, so those visits were filed under whatever the referrer suggested, or under no source at all. TrackSure already knows what each identifier means and now tells the tag, reading the same list it attributes by rather than keeping a second one that could disagree.
- Improvement: nothing is claimed over an auto-tagged Google Ads click, or over a link somebody tagged by hand. Naming a source overrides what the address says, and answering “google / cpc” over a click a linked Google Ads account can resolve would trade the campaign, ad group and cost for two words.
- Fix: a branch in the tag’s event mapper would have handed Google a session identifier of TrackSure’s own, filing those events under a session Google never recorded a source against — the same fault the Measurement Protocol side reads the visitor’s cookie to avoid. Nothing ever filled the field it read, so it never ran; it is removed rather than left waiting to.
- Fix: a visitor who bought on their first visit had that visit recorded as a touchpoint two or three times over. Every attribution model that shares credit between touchpoints — linear, time decay, position based — then gave that one source two or three shares of the same sale.
- Fix: coming back later from the same place is now recorded as the separate visit it was. Recorded once, a campaign that kept working looked like one that worked in March and stopped, which is exactly what time-decay attribution is meant to show.
- Fix: the admin screens classified traffic for themselves, in the browser, from a second set of rules that did not match the server’s — matching by fragment, so any source containing “online” was reported as a messaging app, anything containing “aff” as an affiliate, and a link tagged with a source but no medium as direct. Channels are now decided once, where the visit is recorded.
- Fix: Google Analytics counted every visitor’s arrival twice. TrackSure raises its own session_start and first_visit events, and those were passed straight to the Google tag — which raises events of the same names itself, and reserves those names. Two visitors arriving showed as four first_visit and four session_start against two page views.
- Fix: the Google Analytics tag wrote a line to the browser console for every event it handled, on every visit.
- New: the Journeys view shows the whole path a visitor took to reach you, in order — an ad, then a search, then a link from a newsletter weeks later — rather than only the first and last of them.
- Fix: the AI Assistant, Affiliates and Messaging channels were drawn with icons that do not exist, so they appeared blank.
E-commerce and the Products report
- Fix: a product sold in several variations is now counted once rather than once per variation, and each advertising platform is told the kind of id it expects — Meta matches its catalogue on the variation, GA4 joins views to sales on the product, and they genuinely disagree
- Fix: products no longer appear as “Unknown Product” in the Products report
- Fix: the shop’s own pages are no longer listed among its products
- Fix: WooCommerce add-to-cart no longer invents a product name from the button’s text
- Fix: FluentCart — a product with a single buyable option had two identities and was reported twice
- Fix: FluentCart — a product could be reported under a name the shop had never used
- Fix: FluentCart — the checkout no longer renders blank
- New: a setting to choose whether the advertising platforms are told the site’s internal product id or the product’s SKU. The wrong one fails silently, so it is now a choice rather than an assumption. Covers WooCommerce, FluentCart, and the e-commerce integrations in Pro.
Reports, retention and storage
- Fix: the daily product aggregate table was never cleaned up by anything — it was the only table in the plugin that grew without limit, one row per product per day per campaign. The retention period the site chose now reaches it like every other table.
- Improvement: an unused index was dropped from the events table. Its leading column was already the table’s primary key, so it was never used for reading while still being written on every insert, on the largest table the plugin has.
- Improvement: empty values are stored as empty rather than as text that merely looks empty, across every table
Destinations and delivery
- Fix: a delivery run could end in a fatal error at the moment it tried to record a failure
- Fix: a destination that stopped sending in batches could never start again. Batching is abandoned when a platform refuses a whole batch, which is right — but the commonest reason for that is a credential, and credentials get fixed. Any site that had one bad afternoon paid an extra request per event indefinitely, with the settings screen showing everything in order.
- Fix: Meta is told whether an id names a product or a group of variations, in both the browser and server paths
Admin screens
- Fix: every setting inside an integration card was drawn without its on/off switch, so sub-settings appeared as plain unclickable text
- Fix: the “Test connection” button had never appeared for any destination, and Meta had no connection test at all
- Fix: conversion mappings displayed as “[object Object]”
- Fix: destinations showed every field they support rather than the ones the site needs
- Fix: the “Test connection” button was unreadable in the light theme
- Fix: “No such destination, or it is not enabled” was shown to people whose destination exists and is switched on
- Fix: the health panel no longer reports a problem on a correctly configured site — excluding administrators is deliberate and is no longer counted as events being turned away, and a Pro event catalogued but not loaded no longer warns on every install
Admin appearance
- Fix: thirty-three colour and spacing names were used across the admin but never defined anywhere. A name a browser cannot resolve does not fall back — it throws the whole declaration away, in silence. The clearest casualty was the session journey’s conversion funnel, whose bar lost its background while keeping white text: invisible on a light panel, and only looking deliberate in dark mode.
- Fix: the names added for those thirty-three were themselves fixed to the light theme’s colours, so the dark theme drew dark text on its own dark panels. A name defined in terms of another is resolved where it is written, not where it is read, and these were written above the point the theme is chosen.
- Fix: the conversion funnel took its colour from the component rather than from a stylesheet, which put that colour beyond the reach of either theme. A reached purchase and a step not yet reached were among the names that did not exist, so those bars drew no fill at all.
- Fix: on the Integrations and Destinations screens the browser’s own checkbox appeared beside the on/off switch wherever the switch was disabled — WordPress styles a disabled checkbox in a way that outweighed the rule hiding it.
- Fix: the Pages report sized its address column to its contents, so a single checkout link carrying a click identifier pushed views, conversions and revenue off the screen. The address is now bounded and shown in full on hover.
- Fix: a separator drawn in the border colour was all but invisible against the panel behind it.
- Fix: the delivery panel on Diagnostics drew white cards in the dark theme, with the theme’s near-white text on them. The card colour was named once for the light theme in terms of another name, and a name defined that way keeps the answer it had where it was written.
- Fix: nine colours existed only for the dark theme, so the rules asking for them did nothing at all in the light one — among them the danger button, which did not react to the pointer.
- Fix: three names the Goals screens ask for had never been defined, leaving filter and import controls with no hover, no accent border, and an active filter with white text on no fill.
- Fix: a green, amber, red or indigo used as small text reads between 2.1 and 3.6 against a panel, and white on those same colours is no better. Each now has a tone for text and a tone for a filled block, and every rule in the admin asks for the one it means. Roughly 250 rules across every screen.
- Fix: the chart legend took its label colour from the series it describes, which is chosen to stand out against a plot rather than to be read as small text.
- Fix: two spellings of the primary button are in use and only one was styled, so buttons written the other way came out with the panel’s own background behind their white text.
- Fix: milestone buttons put white text on the bright shade of each tier colour; they now use the same hues a step deeper.
- Improvement: nothing in the admin now falls below the readable contrast ratio, in either theme — 3,064 pieces of text across fifteen screens were measured in the browser to confirm it.
- Improvement: colours derived from the theme are written in one place instead of being restated per theme, and eight names nothing asked for were removed.
Removal and cleanup
- Fix: uninstalling left the site running a delivery job every minute, permanently — WordPress reschedules a recurring job whether or not anything still listens for it. Uninstalling now stops it.
- Fix: uninstalling did not remove three integration settings, three per-user dismissed-notice records, or any queued Action Scheduler task
- Fix: development-only files were being included in the released plugin
- Improvement: a quantity of dead and unreachable code removed, including a documented filter that had never been connected to anything
Security
- Fix: hardening of the public event-collection endpoints
- Fix: the single-event collection endpoint recorded no attribution
Compatibility
- Tested with WordPress 7.1.
Pro
- Fix (Pro): licensing was disabled in every downloaded copy — the development-mode flag shipped as a literal “true”. It now defaults to off and is opted into from wp-config.php, and the release build refuses to run if that ever returns.
- Fix (Pro): the minimum free-plugin version check produced a warning and then loaded Pro anyway, causing a fatal error the first time a form was submitted against an out-of-date free plugin
- Fix (Pro): Reddit counted every conversion twice
- Fix (Pro): TikTok was sending nothing usable, in five separate ways
- Fix (Pro): the Microsoft Ads UET tag was never placed on the page
- Fix (Pro): X (Twitter) reported conversions against hard-coded conversion tag ids rather than the site’s own
- Fix (Pro): LinkedIn’s identity block was in a shape LinkedIn does not read
- Fix (Pro): every destination was sent the same phone-number hash, though the platforms do not agree on the format
- Fix (Pro): Experiences targeting silently matched nothing — it read data that was never loaded, queried a column that does not exist, and called geolocation that could never resolve
- Fix (Pro): the daily licence check kept its place in the schedule after the plugin was deactivated
1.2.7 – 2026-07-12
- Fix: GA4 Measurement Protocol events now reuse the visitor’s real GA4 client_id and session_id (captured from the first-party ga / _ga{stream} cookies) instead of a separate TrackSure identity — resolves “(not set)” / Unassigned traffic and doubled sessions in GA4 acquisition reports
- Fix: GA4 server-side delivery now checks browser pixel confirmation before sending — resolves duplicate purchase/ecommerce events appearing twice in GA4 (once with correct source/medium, once as “(not set)”)
- Fix: FluentCart purchase events (order_paid_done) are no longer silently dropped when processed asynchronously via Action Scheduler — affected all payment gateways including Razorpay
- Fix: FluentCart cart and checkout events (view_cart, begin_checkout) now use the store’s actual currency instead of defaulting to USD — affects all non-USD stores
- Fix: Settings now save correctly on sites running LiteSpeed Cache — REST API responses are marked no-cache and page caches are purged automatically after a settings change
- Fix: Reddit tracking — rdt_cid (Reddit click ID) is now captured from ad landing URLs, persisted to sessions, and forwarded to the Reddit Conversions API for proper attribution and deduplication
- Improvement: Automatic database migration (DB v1.0.2) adds rdt_cid column to tracksure_sessions table on existing installs — no manual action required
- Fix (Pro): Reddit Pixel now correctly sends value, currency, transactionId, itemCount, products, and search at the top level of the pixel options object — these params were previously silently dropped inside customEventProperties
- Fix (Pro): Reddit Conversions API server-side events now correctly detect HTTP 200 success responses — previously all API calls were incorrectly reported as failures even when Reddit accepted them
- Fix (Pro): begin_checkout event now maps to Reddit’s InitiateCheckout standard event instead of AddToCart
- Fix (Pro): Removed incorrect uuid field from Reddit CAPI user data — uuid must come from the Reddit Pixel browser cookie, not the server-side event ID
1.2.6 – 2026-05-22
- Fix: Meta Pixel initialized with
{autoConfig: false}to prevent Meta’s automatic checkout/purchase event detection from firing a duplicate, parameterlessInitiateCheckoutalongside TrackSure’s enriched server-side event
1.2.5 – 2026-04-28
- Fix: PHP E_WARNINGs on attribution rows — null coalescing added for first/last touch conversion and revenue fields in query controller
- Fix: DB SQL error “Unknown column dest.destination” in delivery stats — corrected JSON_TABLE alias and join condition in diagnostics controller
- Fix: FluentCart offline/COD purchase tracking — orders with
pendingpayment status (offline_payment method) are now correctly tracked; status list is filterable viatracksure_fluentcart_purchase_statuses - Fix: GA4 Measurement Protocol session attribution — changed
source/medium/campaignto requiredsession_source/session_medium/session_campaignparams so active users show traffic source in GA4 - Fix: Pro settings schema now always registered before license gate so REST API accepts
tracksure_forminator_enabledandtracksure_bit_form_enabledkeys without validation errors
1.2.4 – 2026-04-27
- Improvement: Redesigned admin sidebar navigation — split 11-item Analytics group into 5 focused groups (Analytics, Behaviour, Conversions, Tools, Settings) for better UX
- Improvement: Data Quality moved to Tools group alongside Diagnostics for logical grouping
- Improvement: Conversions group now follows logical setup-to-report order: Goals Conversions Attribution
- Improvement: Admin panel default theme set to light mode
- Fix: Dark theme card backgrounds now use opaque tokens (–ts-card-bg) instead of semi-transparent –ts-surface — eliminates white bleed-through in dark mode
- Fix: SVG sparkline gradient IDs sanitized (spaces removed) — resolves invalid SVG spec warning
- Improvement: Sparkline fill color is now neutral indigo (non-alarming) while stroke color reflects trend direction
1.2.3 – 2026-04-19
- Fix: Meta CAPI “Invalid parameter” error — removed unsupported
address/adfield from user_data, added strict whitelist of Meta-accepted fields - Fix: Browser/server race condition — concurrent add_to_cart requests with same event_id caused server’s ecommerce_data to be silently dropped (INSERT IGNORE ON DUPLICATE KEY UPDATE)
- Fix: Outbox payload merge — when browser event wins the outbox INSERT race, server’s richer payload (items[], value, currency) is now merged back
- Fix: add_to_cart double-counting — browser and server now use item_id as content identifier for deterministic event_id, preventing duplicate events
- Fix: Grouped product add_to_cart — browser no longer fires a hollow add_to_cart for grouped product parent; server correctly fires individual events per child item with full ecommerce data
- Fix: Pipeline diagnostics Section 6 now correctly shows “Skipped” instead of “Pending” for events without destination mapping
- Fix: Pipeline diagnostics Section 10 now correctly shows “Skipped” instead of “Pending” for non-Meta events
- Improvement: Enhanced Meta CAPI error capture with error code and subcode for faster debugging
1.2.2 – 2026-04-13
- Fix: WooCommerce purchase event now uses transactional event_id (order_id based) for reliable Meta CAPI deduplication — consistent with FluentCart
- Fix: Checkout form billing data (email, phone, name, address) was not being saved — replaced dead filter with woocommerce_checkout_order_processed hook
- Fix: Guest user billing fields now enrich EMQ (Event Match Quality) data on the thank-you page for Meta CAPI and server-side destinations
- Fix: Checkout form JS event_id generation corrected from ‘purchase’ to ‘begin_checkout’ — purchase event_id is now transactional
1.2.1 – 2026-04-06
- Fix: Resolved 9,234+ PHPCS coding standards violations across 22 files via auto-formatter
- Fix: Fixed 3 PreparedSQL placeholder errors in dynamic database INSERT queries
- Fix: Fixed undefined $event variable bug in event builder — page context data (title, URL, referrer) was not being passed to validated params
- Fix: Added strict comparison (true) to all in_array() calls for type safety
- Fix: Changed urlencode() to rawurlencode() for RFC 3986 compliant URL encoding in geolocation
- Fix: Converted loose == comparisons to strict === with proper type casting
- Improvement: Updated PHPCS ruleset to suppress VIP-specific false positives for non-VIP hosting
- Improvement: Suppressed noisy warnings (commented-out code detection, unused hook params, global redeclarations)
1.2.0 – 2026-04-04
- Improvement: Meta EMQ (Event Match Quality) now sends full user data (em, fn, ln, ph, ct, st, zp, country) with purchase events for both WooCommerce and FluentCart
- Improvement: FluentCart purchase events now pull billing address data (name, phone, city, zip) from order addresses instead of sparse customer profile
- Improvement: Meta pixel sender re-initializes fbq with per-event user_data before firing for accurate Advanced Matching
- Fix: FluentCart EMQ was only sending country, state, and external_id — now sends all available checkout fields
1.1.0 – 2026-04-01
- New: Milestone celebrations — celebrate visitor milestones (1/50/100/500/1K/5K/10K) and conversion milestones (1/10/50/100/500) with confetti burst animations
- New: Tier-based celebration themes — starter, growing, popular, champion, and legendary tiers with unique colors and icons
- Improvement: Loading spinner no longer conflicts with other plugin spinner styles
- Fix: Light theme button text now uses solid white color for consistent readability
- Fix: Dark mode milestone toast backgrounds are now opaque for better text readability
1.0.5 – 2026-04-01
- New: SEO-friendly plugin name for better WordPress.org search visibility (server side tracking, meta pixel, CAPI, WooCommerce)
- New: Onboarding welcome banner after first activation — guides users through Live tab, admin tracking, dashboard timing, and CAPI setup
- Improvement: Tracking now enabled by default on fresh installs — users see data immediately without manual configuration
- Improvement: Updated plugin description and tags for better discoverability
1.0.4 – 2026-04-01
- Fix: MariaDB compatibility — replaced MySQL-only JSON ->> operator with JSON_UNQUOTE(JSON_EXTRACT()) for cross-database support
- Fix: Logger column mismatch — aligned code with installer schema (context_json context, log_id id)
- Fix: Race condition duplicate entry errors on visitors, sessions, and outbox tables — replaced SELECT-then-INSERT with INSERT IGNORE
- Fix: Added automatic database upgrade mechanism so schema changes apply on plugin update, not just activation
1.0.3 – 2026-03-31
- Fix: Re-release of 1.0.2 (previous SVN upload was corrupted)
1.0.2 – 2026-03-31
- Fix: Journeys page now shows correct total visitor count — previously limited to 50 due to missing server-side pagination
- Fix: Sessions page summary cards (total sessions, conversions, revenue) now display accurate global totals instead of current-page-only counts
- Fix: Filter button labels on Journeys page now show correct counts across all data
- Improvement: Journeys page uses true server-side pagination for better performance with large datasets
- Improvement: Frontend JS files are now minified (132 KB saved) with SCRIPT_DEBUG-aware switching
- Improvement: Inlined event registry via wp_localize_script — eliminates extra HTTP request on every page load
1.0.1 – 2026-03-03
- Fix: Goal cards now correctly display performance data (conversions, revenue, conversion rate) — batch performance cache was returning data without the expected wrapper key
- Fix: 3 broken goal templates (scroll_depth, time_on_page, video_complete) now fire correctly
- Fix: Goal condition evaluator type coercion — wp_localize_script sends numbers as strings, causing operator comparisons to fail
- Fix: Ecommerce platform detection now recognizes SureCart and FunnelKit
- Improvement: All 6 frontend scripts now use defer loading strategy for better page speed
- Improvement: Conditional script loading — minicart/currency scripts only load when ecommerce is active, goal scripts only when goals exist
- Improvement: Added loading skeleton placeholders on goal cards while performance data loads
- Improvement: PHP goal evaluator uses secondary trigger_type index for faster lookups
- Improvement: Reduced goal cache TTL from 5 minutes to 1 minute for fresher dashboard data
- Improvement: Added auto-refresh (5 min) for performance queries
1.0.0 – 2026-02-05
- Initial release
- Browser tracking SDK with comprehensive event capture
- Server-side integrations (WooCommerce, FluentCart, EDD, SureCart)
- First-party analytics dashboards
- Multi-touch attribution (first-touch, last-touch, linear, time-decay, position-based)
- Meta Pixel + CAPI integration
- GA4 gtag.js + Measurement Protocol integration
- Privacy-first features (GDPR compliance, cookieless mode)
- Performance optimizations (caching, CDN compatibility)
