{"id":376626,"date":"2026-10-05T02:20:48","date_gmt":"2026-10-05T02:20:48","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/convermetry\/"},"modified":"2026-10-05T02:20:12","modified_gmt":"2026-10-05T02:20:12","slug":"convermetry","status":"publish","type":"plugin","link":"https:\/\/ro.wordpress.org\/plugins\/convermetry\/","author":23574911,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"1.0.2","stable_tag":"1.0.2","tested":"7.1.2","requires":"6.3","requires_php":"8.3","requires_plugins":null,"header_name":"Convermetry","header_author":"Chris Paschall","header_description":"Visitor analytics, campaign attribution, and server-confirmed form conversion tracking with reliable webhook delivery. Connects every lead to its analytics session, traffic source, and campaign, and delivers analytics reports and form submissions to any number of webhook endpoints with signing, retries, and idempotency.","assets_banners_color":"","last_updated":"2026-10-05 02:20:12","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"","header_author_uri":"","rating":0,"author_block_rating":0,"active_installs":0,"downloads":43,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"1.0.2":{"tag":"1.0.2","author":"cpaschall1981","date":"2026-10-05 02:20:12","revision":3727991}},"upgrade_notice":{"1.0.2":"<p>Security hardening of admin requests and settings validation. No settings or data change on upgrade; custom header names that are not valid HTTP are reported the next time the page is saved.<\/p>","1.0.1":"<p>Renames the plugin&#039;s stored settings, tables and scheduled events to the <code>cvmtry<\/code> prefix. Settings and data saved by 1.0.0 are not carried over.<\/p>","1.0.0":"<p>First WordPress.org release. Adds privacy-policy text and personal-data export\/erasure for form submissions, and makes the interface translatable. No settings or data change on upgrade.<\/p>"},"ratings":[],"assets_icons":[],"assets_banners":[],"assets_blueprints":{},"all_blocks":[],"tagged_versions":["1.0.2"],"block_files":[],"assets_screenshots":[],"screenshots":{"1":"The Home screen: what Convermetry is recording on this site, the setup checklist and a status overview.","2":"The Analytics dashboard: overview totals and daily page views, followed by content, engagement, acquisition, device, goal and lead reports.","3":"A submission expanded: lead status and value, form details, channel and campaign attribution, and the visitor's path to the form.","4":"The Forms screen: form engagement and abandonment, detected form plugins and per-form settings.","5":"Webhook endpoints: the message types each one receives, signing secrets and test buttons.","6":"The Activity Log: every delivery attempt with its payload and response, including retries.","7":"Goals with their completions, conversion rates and value.","8":"A funnel showing how many visits reached each step on the way to a quote request.","9":"Tracking and privacy settings: interaction types, logged-in users, Do Not Track \/ Global Privacy Control, IP storage and data retention."}},"plugin_section":[],"plugin_tags":[232,601,5446,24188,34953],"plugin_category":[36,42],"plugin_contributors":[284371],"plugin_business_model":[],"class_list":["post-376626","plugin","type-plugin","status-publish","hentry","plugin_tags-analytics","plugin_tags-forms","plugin_tags-lead-tracking","plugin_tags-utm","plugin_tags-webhooks","plugin_category-analytics","plugin_category-contact-forms","plugin_contributors-cpaschall1981","plugin_committers-cpaschall1981"],"banners":[],"icons":{"svg":false,"icon":"https:\/\/s.w.org\/plugins\/geopattern-icon\/convermetry.svg","icon_2x":false,"generated":true},"screenshots":[],"raw_content":"<!--section=description-->\n<p>Convermetry connects the question \"where did this visitor come from?\" to the answer \"which lead did they become?\" \u2014 inside your own WordPress site.<\/p>\n\n<p>It records how visitors use your pages, attributes each visit to a traffic channel and campaign, and captures form submissions <strong>after the form plugin has confirmed them on the server<\/strong>. Every lead is linked to the analytics session and campaign that produced it. Leads can then be forwarded to your own systems through webhooks, and you can be emailed when one arrives.<\/p>\n\n<p>Everything is stored in your WordPress database. Convermetry works on its own: it needs no account, no API key and no external service.<\/p>\n\n<h4>Analytics and attribution<\/h4>\n\n<ul>\n<li>Page views, clicks, form views, starts, validation errors and submit attempts, confirmed conversions, scroll depth, hover and custom events. Each type can be switched off.<\/li>\n<li>UTM campaign parameters, ad-click identifiers (only which parameter was present, never its value) and entrance referrers classified into channels such as Paid Search, Organic Social or Email.<\/li>\n<li>An analytics dashboard with top pages, landing pages, referrers, campaigns, channels, devices, conversions and lead outcomes.<\/li>\n<li>Goals for actions that are not form submissions (phone and email link clicks, downloads, reaching a page, custom events) and funnels that measure the ordered path to a conversion.<\/li>\n<li>Form engagement and abandonment reporting that never records what a visitor typed into a form they did not submit.<\/li>\n<\/ul>\n\n<h4>Leads<\/h4>\n\n<ul>\n<li>A Submissions screen with each lead's answers, the page it came from, its campaign attribution and its webhook delivery status.<\/li>\n<li>Lead status (new, qualified, won, lost\u2026) and value, with history, and lead reports by channel, campaign, landing page and form.<\/li>\n<li>CSV export, per-submission delete, and a retention window after which data is deleted automatically.<\/li>\n<\/ul>\n\n<h4>Supported form plugins<\/h4>\n\n<p>Convermetry detects these automatically and records a submission when the form plugin's own server-side success hook fires. None of them is required.<\/p>\n\n<ul>\n<li><strong>Contact Form 7, WPForms, Gravity Forms, Fluent Forms, Ninja Forms and Formidable Forms<\/strong> \u2014 captured automatically, with no per-form setup.<\/li>\n<li><strong>Elementor Pro (classic Form widget)<\/strong> \u2014 captured automatically.<\/li>\n<li><strong>Elementor Pro Atomic forms<\/strong> \u2014 opt in per form: in the Elementor editor, add <strong>Convermetry<\/strong> under <em>Actions after submit<\/em> on the form and update the page.<\/li>\n<li><strong>Bricks Builder (native Form element), Bricks 1.12.2 or newer<\/strong> \u2014 opt in per form: in Bricks, tick <strong>Convermetry<\/strong> under <em>Actions after successful form submit<\/em> and save. Older Bricks versions are shown as unavailable.<\/li>\n<li><strong>Any other form<\/strong> \u2014 send it through the documented <code>convermetry_form_submission<\/code> action or the <code>convermetry_submit_form()<\/code> function.<\/li>\n<\/ul>\n\n<p>Submissions made before a form is connected are not recorded and cannot be recovered. Per-form options (exclude a form, set a custom form ID, add per-form webhook headers and query parameters) are on the Forms screen.<\/p>\n\n<h4>Webhooks and email notifications<\/h4>\n\n<ul>\n<li>Send <strong>form submissions<\/strong> (one message per confirmed lead, delivered in the background) and\/or scheduled <strong>analytics reports<\/strong> (hourly, twice daily, daily or weekly) to any number of HTTPS endpoints you configure.<\/li>\n<li>Optional HMAC-SHA256 signatures, stable delivery IDs for idempotency, automatic retries and an Activity Log of every attempt with its (redacted) payload and response.<\/li>\n<li>Optional internal <strong>email notifications<\/strong> to addresses you choose, sent through <code>wp_mail()<\/code>. They are off by default.<\/li>\n<\/ul>\n\n<h4>Privacy and data handling<\/h4>\n\n<p>This section describes what Convermetry does. It is not legal advice, and Convermetry does not by itself make a site compliant with any law. Review your privacy policy and your legal basis for processing.<\/p>\n\n<p><strong>What is collected<\/strong><\/p>\n\n<ul>\n<li>For each tracked interaction: the event type, the page address without its query string, page title, clicked element text and link target, referrer (without query string), campaign parameters, a traffic channel, a device type (desktop, tablet or mobile), a random visit identifier and a timestamp.<\/li>\n<li><strong>IP addresses are stored by default<\/strong> with analytics events and form submissions. You can turn this off under Convermetry \u2192 Settings (\"Store visitor IP addresses\"). User agents are never stored.<\/li>\n<li>For each confirmed form submission: the values the visitor submitted, the page and its query parameters, and the analytics context of the visit (channel, campaign, landing page, pages viewed). Fields that look like passwords or other credentials are withheld from email notifications and redacted in the Activity Log.<\/li>\n<li>Logged-in users are excluded from tracking by default.<\/li>\n<li><strong>Do Not Track \/ Global Privacy Control are not honored by default.<\/strong> When you enable that setting, visitors who send either signal are not tracked, and no IP address is stored with a form they submit.<\/li>\n<\/ul>\n\n<p><strong>Browser storage \u2014 no cookies.<\/strong> The tracker sets no cookies. It stores a random visit identifier (<code>cvmtry_session<\/code>) and the visit's attribution (<code>cvmtry_campaign<\/code>) in the browser's localStorage, and briefly holds unsent events (<code>cvmtry_pending<\/code>) in sessionStorage. The visit identifier is replaced after 30 minutes of inactivity. In the EU and UK, the rules that govern cookies also apply to this kind of storage.<\/p>\n\n<p><strong>Consent.<\/strong> Convermetry has no consent banner of its own and is not integrated with a consent-management plugin. Analytics starts collecting as soon as the plugin is activated. If your site needs consent before analytics runs, have your consent tool block the script handle <code>cvmtry-tracker<\/code> until consent is given, or return <code>false<\/code> from the <code>convermetry_should_enqueue_tracker<\/code> filter. Form submissions are still recorded server-side when the tracker does not run.<\/p>\n\n<p><strong>Where it is stored and for how long.<\/strong> In seven custom tables in your WordPress database. Analytics events, submissions, goal completions, lead history and Activity Log entries are deleted automatically after the retention period (default 90 days, adjustable from 7 to 365). Deleting the plugin from the Plugins screen removes every table, option and scheduled task it created.<\/p>\n\n<p><strong>WordPress privacy tools.<\/strong> Convermetry adds suggested text to Settings \u2192 Privacy \u2192 Policy Guide, generated from your current settings. It also adds an exporter and an eraser to Tools \u2192 Export Personal Data and Tools \u2192 Erase Personal Data. For an email address, they find the form submissions whose submitted values contain that exact address. The eraser deletes those submissions with their lead history and queued deliveries and notifications. It removes the lead from the Activity Log's stored payloads, and removes the visitor's IP address from the analytics of that visit. Analytics recorded during visits in which no form was submitted is not linked to an email address, so it can only age out through the retention period.<\/p>\n\n<h4>External services<\/h4>\n\n<p>Convermetry does <strong>not<\/strong> contact any server by default, and it never sends data to the plugin's author. All fonts, scripts and styles are bundled with the plugin. Information leaves your site only through features a site administrator configures:<\/p>\n\n<ul>\n<li><strong>Webhook endpoints.<\/strong> When you add an endpoint under Convermetry \u2192 Webhooks, Convermetry sends it HTTPS POST requests to the URL you entered. Form submission messages contain the submitted form values, the submitter's IP address (when IP storage is on), the page and its query parameters, and the visit's analytics context. Analytics report messages contain aggregated statistics plus a list of individual conversions, each with its IP address (when stored) and visit identifier. You choose which endpoints receive which message type. The receiving service is chosen by you, so its terms of use and privacy policy are the ones you agreed to with that service.<\/li>\n<li><strong>Email notifications.<\/strong> When enabled, a notification for each new submission is sent through your site's own mail system (<code>wp_mail()<\/code>, and any SMTP plugin you use) to the recipients you enter. It can include the submitted values, analytics context and, only if you enable it, the visitor journey and IP address.<\/li>\n<\/ul>\n\n<p>Copies that have already been delivered to a webhook endpoint or sent by email are outside Convermetry's control. Deleting a submission, retention and the eraser cannot recall them; they are kept according to the receiving system's own policies.<\/p>\n\n<h4>For developers<\/h4>\n\n<p>Convermetry has a documented hook API (85 actions and filters), a custom form submission API, a read-only REST endpoint for the delivery log, and versioned webhook payload schemas. The full reference is in the plugin under Convermetry \u2192 About and in the README.md file included with the plugin.<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Install Convermetry from the Plugins \u2192 Add New screen, or upload the <code>convermetry<\/code> folder to <code>\/wp-content\/plugins\/<\/code>.<\/li>\n<li>Activate it on the Plugins screen. Your server must run PHP 8.3 or newer.<\/li>\n<li>Open <strong>Convermetry \u2192 Home<\/strong>. It shows what the plugin is recording and a setup checklist.<\/li>\n<li>Review <strong>Convermetry \u2192 Settings<\/strong>: which interactions to track, whether to store IP addresses, whether to honor Do Not Track \/ Global Privacy Control, and the retention period.<\/li>\n<li>Check <strong>Convermetry \u2192 Forms<\/strong>. Supported form plugins are detected automatically. For Elementor Pro Atomic forms and Bricks forms, add the Convermetry action to each form in the builder (see Description).<\/li>\n<li>Optionally add webhook endpoints under <strong>Convermetry \u2192 Webhooks<\/strong> and email notifications under <strong>Convermetry \u2192 Notifications<\/strong>.<\/li>\n<li>Review the suggested text under <strong>Settings \u2192 Privacy \u2192 Policy Guide<\/strong> and update your privacy policy.<\/li>\n<\/ol>\n\n<!--section=faq-->\n<dl>\n<dt id=\"do%20i%20need%20an%20account%20or%20an%20external%20service%3F\"><h3>Do I need an account or an external service?<\/h3><\/dt>\n<dd><p>No. Convermetry stores everything in your WordPress database and works with no account, API key or remote service. Webhooks and email notifications are optional and send data only to destinations you configure.<\/p><\/dd>\n<dt id=\"does%20convermetry%20use%20cookies%3F\"><h3>Does Convermetry use cookies?<\/h3><\/dt>\n<dd><p>No. It uses the browser's localStorage and sessionStorage instead (see \"Browser storage\" in the Description). Privacy rules on cookies generally also apply to this storage, so treat it like a cookie in your privacy notice and consent decisions.<\/p><\/dd>\n<dt id=\"does%20analytics%20start%20as%20soon%20as%20i%20activate%20the%20plugin%3F\"><h3>Does analytics start as soon as I activate the plugin?<\/h3><\/dt>\n<dd><p>Yes. Page views and the other interaction types are enabled by default, logged-in users are excluded, and IP addresses are stored. Review Convermetry \u2192 Settings after activating. If you need visitor consent first, see the next question.<\/p><\/dd>\n<dt id=\"how%20do%20i%20wait%20for%20consent%20before%20tracking%3F\"><h3>How do I wait for consent before tracking?<\/h3><\/dt>\n<dd><p>Configure your consent tool to block the <code>cvmtry-tracker<\/code> script until consent is given, or add a filter to <code>convermetry_should_enqueue_tracker<\/code> that returns <code>false<\/code> until your consent check passes. Server-confirmed form submissions are still recorded, without analytics context, when the tracker does not run.<\/p><\/dd>\n<dt id=\"which%20form%20plugins%20are%20supported%3F\"><h3>Which form plugins are supported?<\/h3><\/dt>\n<dd><p>Contact Form 7, WPForms, Gravity Forms, Fluent Forms, Ninja Forms, Formidable Forms, Elementor Pro (classic forms and Atomic forms) and Bricks Builder 1.12.2+. Other forms can use the developer API.<\/p><\/dd>\n<dt id=\"my%20elementor%20atomic%20or%20bricks%20form%20is%20listed%20on%20the%20forms%20screen%20but%20nothing%20is%20recorded.\"><h3>My Elementor Atomic or Bricks form is listed on the Forms screen but nothing is recorded.<\/h3><\/dt>\n<dd><p>Those builders only run the actions you select for each form. Add <strong>Convermetry<\/strong> to the form's actions in the builder and save the page. Listing a form on the Forms screen does not add the action for you.<\/p><\/dd>\n<dt id=\"what%20data%20leaves%20my%20site%3F\"><h3>What data leaves my site?<\/h3><\/dt>\n<dd><p>Nothing, unless you configure webhook endpoints or email notifications. See \"External services\" in the Description for exactly what each one sends.<\/p><\/dd>\n<dt id=\"how%20long%20is%20data%20kept%3F\"><h3>How long is data kept?<\/h3><\/dt>\n<dd><p>90 days by default. Change it between 7 and 365 days under Convermetry \u2192 Settings. Older data is deleted by a daily cleanup task.<\/p><\/dd>\n<dt id=\"how%20do%20i%20stop%20storing%20ip%20addresses%3F\"><h3>How do I stop storing IP addresses?<\/h3><\/dt>\n<dd><p>Untick <strong>Store visitor IP addresses<\/strong> under Convermetry \u2192 Settings. New records then have no IP address; existing records keep theirs until retention deletes them. You can also honor Do Not Track \/ Global Privacy Control on the same screen.<\/p><\/dd>\n<dt id=\"how%20do%20i%20export%20or%20erase%20someone%27s%20data%3F\"><h3>How do I export or erase someone's data?<\/h3><\/dt>\n<dd><p>Use WordPress's Tools \u2192 Export Personal Data and Tools \u2192 Erase Personal Data with the person's email address. Convermetry finds form submissions whose submitted values contain that exact address. Webhook deliveries and emails that were already sent cannot be recalled; the eraser lists the webhook destinations the data had reached. Entries stored by your form plugin itself are handled by that plugin's own privacy tools, if it provides them.<\/p><\/dd>\n<dt id=\"what%20happens%20when%20i%20deactivate%20or%20delete%20the%20plugin%3F\"><h3>What happens when I deactivate or delete the plugin?<\/h3><\/dt>\n<dd><p>Deactivating stops tracking and scheduled tasks but keeps your data. Deleting the plugin from the Plugins screen removes all of its tables, options and scheduled tasks, on every site of a multisite network.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>1.0.2<\/h4>\n\n<ul>\n<li>Security: every admin form, link and AJAX action checks the request method, the user's capability and its own nonce as separate steps before reading any input. Saves, deletions, exports and retry discards run only on their own admin-post actions, never on ordinary admin page loads.<\/li>\n<li>Security: webhook URLs, labels, signing secrets, custom headers and query parameters are validated field by field. A rejected URL is reported without storing what was typed, and a malformed submission no longer resets saved settings.<\/li>\n<li>Security: reporting-period links on Analytics, Goals and Funnels carry their own nonce; an expired link shows the last 30 days with a notice.<\/li>\n<li>Fix: Discard on a pending analytics retry now removes it.<\/li>\n<li>Fix: removing an endpoint on the Webhooks screen no longer gives the next endpoint a new identity when saved.<\/li>\n<li>Fix: a site that delegates the Settings screen with the <code>convermetry_admin_capability<\/code> filter can now save it.<\/li>\n<\/ul>\n\n<h4>1.0.1<\/h4>\n\n<ul>\n<li>Changed: every plugin-owned name now uses the <code>cvmtry<\/code> prefix \u2014 stored options, database tables, scheduled events, script and style handles, CSS classes, <code>data-cvmtry-*<\/code> attributes, browser storage keys and the <code>cvmtry_track_event()<\/code> helper. Public <code>convermetry_*<\/code> hooks and functions are unchanged.<\/li>\n<li>Changed: the About screen's hook reference and the confirmation prompts for Remove and Clear All now run entirely from enqueued scripts and stylesheets; no inline script or style blocks are printed.<\/li>\n<li>Changed: the PHP version notice is shown only to administrators, on the Dashboard and Plugins screens.<\/li>\n<li>Hardening: report queries bind every table and column name as an identifier and every value through prepared statements, and display-only request parameters are sanitized where they are read.<\/li>\n<\/ul>\n\n<h4>1.0.0<\/h4>\n\n<ul>\n<li>New: WordPress privacy tools integration \u2014 suggested privacy policy text generated from your settings, and a personal-data exporter and eraser for form submissions and their linked data.<\/li>\n<li>New: the plugin interface, notification emails and scripts are translatable (text domain <code>convermetry<\/code>), with a translation template in <code>languages\/<\/code>.<\/li>\n<li>Fix: the Remove buttons on the Goals and Funnels screens now ask for confirmation as intended.<\/li>\n<li>Fix: deleting the plugin now removes every option it created (one version option was previously left behind).<\/li>\n<li>Fix: Ninja Forms submissions are now linked to the visit and campaign they came from (they were previously recorded without attribution).<\/li>\n<li>Fix: the Forms screen now counts submit attempts (the Attempts column previously always showed 0), and lists Formidable Forms and Ninja Forms forms in its engagement report.<\/li>\n<li>Hardening: stricter escaping of admin output and prepared SQL identifiers throughout.<\/li>\n<li>Changed: first public release on WordPress.org. Earlier 0.x versions were distributed privately; their full history is in CHANGELOG.md, included with the plugin.<\/li>\n<\/ul>","raw_excerpt":"Visitor analytics, campaign attribution and server-confirmed form lead tracking for WordPress, with signed, retried webhook delivery.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ro.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/376626","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ro.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/ro.wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/ro.wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=376626"}],"author":[{"embeddable":true,"href":"https:\/\/ro.wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/cpaschall1981"}],"wp:attachment":[{"href":"https:\/\/ro.wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=376626"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/ro.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=376626"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/ro.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=376626"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/ro.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=376626"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/ro.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=376626"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/ro.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=376626"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}