ClickHelm Wordpress Plugin - Rating, Reviews, Demo & Download
Plugin Description
ClickHelm watches who arrives on your site from Google Ads and works out which of them are
costing you money without ever becoming a customer.
No limit, no time limit, no card, and nothing to unlock. There is no visit cap, no site
count and no key to enter. Everything described below runs on every install, for as long as you
keep the plugin.
It recognises the person, not the address. Identity comes from a device fingerprint resolved
on your own server, so the same visitor is still the same visitor after clearing their storage,
switching browser, or moving from home WiFi to mobile data. An address on its own tells you
little: it changes when a phone’s data is turned off and on.
What it shows you
- Dashboard — the traffic you paid for, what it cost, and which visitors are worth a second
look today, ranked, each with the reasoning in plain language - Visitors — everyone seen, searchable and filterable, with the evidence behind each score:
the fingerprint, the addresses, the networks, and what they did on each visit - Google Ads — spend, waste and profit per campaign, ad group, keyword and placement, with
your own click log beside the clicks Google actually charged you for - The exclusion list — every address worth excluding, ready to copy into Google Ads
- Possible Duplicates — fingerprints that probably belong to someone you already know
What this edition does not do
It does not block anyone. It shows you who is costing you money and leaves the acting to you.
Copying addresses into Google Ads by hand works, and is what the exclusion list is for.
Automatic blocking, your own rules, the breakdown reports and heatmaps are a separate plugin sold
from clickhelm.com. None of that code is in this one — it is not here and switched off, it
is not here at all.
What it measures
Revenue is read from the actual WooCommerce order on the server, so it counts even when a
shopper blocks scripts, and it is the real total rather than an estimate. That is what makes
genuine per-campaign profit and loss possible.
Calls, WhatsApp taps, form submissions, thank-you pages and your own buttons all count as
leads, so the plugin works for a service business as well as a shop.
A weekly or monthly report summarising what the plugin saw, what it cost you, and which
visitors are worth a look, with a link straight to each one. Switch it on under Settings, and
tell it not to write when there is nothing to say.
Privacy
Visitor data stays in your own database. One thing can leave it, and only if you say so: visitor
IP addresses, for address classification. They go to api.clickhelm.com, which asks proxycheck.io
and keeps none of them. It is off until you switch it on – the setup asks, in plain words,
and Settings has the switch. Say so in your site’s privacy policy if you do switch it on. Old
data is cleaned up automatically on a schedule you set.
External services
Every request below leaves from your own server. Nothing is ever sent from a visitor’s browser.
This plugin does not check a licence, does not look for its own updates – updates come from
WordPress.org like any other plugin here – and sends no usage reports. The one thing our server
learns about your site is described under Address classification below: that it asked, and when.
Google Ads (googleads.googleapis.com), only with a licence, and only if you connect an account
If you choose to connect Google Ads, the plugin reads your own campaign reporting once a day –
click identifiers, campaign and keyword names, and cost figures – so it can compare the clicks
recorded on your site against the clicks Google actually charged you for.
It changes two things in the account, and only when you switch them on in the plugin: it can add
ClickHelm’s tracking template to the account, and it can keep an account-level IP exclusion list
made from the visitors you blocked (never anybody you did not block, and never exclusions you added
yourself). It never touches campaigns, ads, budgets or bids. Our server builds those two changes
itself and refuses any other kind.
The request is routed through api.clickhelm.com because Google requires credentials that cannot
be shipped inside a plugin; the reporting data is passed straight through to your site and is
not stored on our server. You can disconnect at any time.
What is read and why: https://clickhelm.com/google-ads-data
Terms: https://clickhelm.com/terms
Privacy: https://clickhelm.com/privacy
Address classification (api.clickhelm.com, then proxycheck.io)
This one is off until you switch it on, and the setup asks. A visitor arriving from a data centre, a VPN
or a commercial proxy is the cheapest kind of fraudulent click there is, and telling them apart
from a real customer cannot be done on your own server – it needs a database of who owns which
network, kept current by somebody whose job that is.
So the plugin sends visitor IP addresses to api.clickhelm.com, which passes them to
proxycheck.io under our account and hands the answer back: country, network operator, and
whether the address belongs to a VPN, proxy, Tor exit or data centre. Each address is looked up
once and remembered on your site, so a returning visitor costs nothing.
Our server keeps none of the addresses. They are relayed and discarded within the request; what
it records is how many were classified, never which – together with the address of the site that
asked, the plugin version and the time. That record is what enforces each site’s daily allowance,
and it is kept for nothing else. You do not need an account anywhere and there is no key to
enter.
The same answer can carry short notices from ClickHelm – that a new version is out, or something
about security – which the plugin shows at the top of its own screens, never elsewhere in
WordPress, in whichever of English or Arabic you read ClickHelm in. Nothing is sent to ask for them,
and each can be dismissed.
Because visitor IP addresses leave your server, say so in your site’s privacy policy.
Terms: https://clickhelm.com/terms
Privacy: https://clickhelm.com/privacy
proxycheck.io terms: https://proxycheck.io/terms
proxycheck.io privacy: https://proxycheck.io/privacy
Screenshots
The dashboard. What the ads cost over the period, what came back, and how much of the spend
went on visitors worth a second look – each one listed underneath with the reasoning in plain
language.
Every visitor the plugin has seen, searchable and filterable, with the risk score, the
networks they arrived on and whether they became a lead.
One visitor in full: why they scored what they scored, the device behind the fingerprint, the
addresses they have used and the ad clicks they arrived on.
Google Ads by campaign – clicks, people, leads, what share was wasted and what that cost,
from your own click log priced at the rate you set.
The exclusion list: the addresses worth excluding, grouped by campaign, ready to paste into
Google Ads, with a plain note on what excluding an address does and does not do.

