BACK TO DIRECTORY

BaseCloud UTM Tracker

by BaseCloud

5.0
(2 ratings)

BaseCloud UTM Tracker v3.0 is the ultimate UTM tracking and webhook management solution for WordPress. Replace Gravity Forms webhook add-on with unlimited custom webhooks, full merge tag support, and automatic UTM injection for the “Big 4” form plugins.

NEW in 4.3: search keywords, AI visibility and reports

Everything new is part of the Blog Post Conversion Tracker and is off by default. The UTM tracker is unchanged.

  • Search keywords – connect Google Search Console with a service account to see the queries that sent clicks to the landing page of each organic Google conversion, flagged against your target keywords (read from Yoast SEO, Rank Math, All in One SEO and SEOPress, plus your own list). These are the likely keywords, not the visitor’s exact search: Google does not share that, and Search Console data is 2-3 days behind.
  • AI visibility – conversions referred by AI assistants (ChatGPT, Perplexity, Gemini, Copilot, Claude and others), an AI crawler log per page with optional IP verification, a robots.txt check for AI crawlers, an llms.txt generator, and AI answer citations from the Ahrefs API.
  • Reports – daily, weekly, monthly and half-yearly JSON reports of your best converting posts, channels, forms, keywords and AI visibility, sent to report webhooks with an optional PDF attachment, plus previews and PDF downloads for any date range.
  • Secure by design – API keys, service account keys and report webhook URLs are encrypted and write-only, requests go only to fixed service hosts or validated https webhooks, and reports contain no personal data.

NEW in 4.2: Blog Post Conversion Tracker

See which blog post a visitor was reading right before they filled in your Gravity Form. Turn it on under UTM Tracker > Blog Post Conversion Tracker (it is off by default).

  • Journey tracking – the browser keeps first and last touch, the first and last post read and the most recent pages in localStorage, with a compact first-party cookie (bc_blog_attr, under 2 KB) as a backup. Gravity Forms submissions carry the full journey in a hidden field. Cache-safe, size-safe and consent-aware (Google Consent Mode regions respected).
  • Entry columns – “Blog: Converted From Post” (Yes, Yes (unverified) or No) and “Blog: Source Post” on Gravity Forms entries, plus minutes to convert, same visit, pages viewed after the post and an optional attribution window.
  • Clean webhooks – a readable JSON payload (form, entry, contact, fields, conversion, visitor, journey) with ISO 8601 times, sent after the visitor’s response so forms stay fast. UTM parameters are left to the UTM tracker.
  • Secure by design – webhook URLs and secrets are encrypted (AES-256-GCM, with an optional BASECLOUD_BPCT_KEY constant), HTTPS only with private-network blocking, never shown again after saving, and requests can be HMAC-signed.
  • Top Converting Posts and recent conversions in the dashboard.
  • Fully separate from the UTM tracker: its settings, cookies and webhooks are untouched. Deleting the plugin removes only the Blog Post Conversion Tracker data.

🎯 THE COLLECTOR: Advanced Cookie Tracking

Automatically captures and stores UTM parameters from your marketing campaigns in secure, persistent cookies.

📦 THE COURIER: Automated Webhook Injection

Game Changer! Automatically injects UTM data into ALL form webhook submissions – works with Gravity Forms, Elementor Pro, WPForms, and Contact Form 7!

The “Big 4” Form Support

  • Gravity Forms – Full integration with async webhook support
  • Elementor Pro Forms – Webhook injection for page builder forms
  • WPForms – Complete webhook automation
  • Contact Form 7 – Classic form plugin support

Key Features

  • 🚀 Zero Manual Configuration – Works automatically after activation
  • 🎯 COLLECTOR System – Advanced cookie-based tracking for 8 parameters
  • 📦 COURIER System – Automatic webhook injection for all major form plugins
  • âš¡ Async Webhook Support – Works with background processing (critical for Gravity Forms)
  • 🔄 Real-Time Diagnostics – Animated status dashboard shows system health
  • 📊 Entry Meta Storage – UTM data saved with each Gravity Forms submission
  • 🎨 Beautiful Dashboard – Modern, animated interface with live status indicators
  • 🔒 Privacy Compliant – Secure cookies with proper SameSite and HTTPS support
  • 📱 iOS 14+ Support – Tracks gbraid and wbraid for enhanced Apple privacy tracking

Tracked Parameters (8 Total)

  1. referrer – Previous page URL
  2. utm_source – Campaign source (Google, Facebook, etc.)
  3. utm_medium – Marketing medium (CPC, email, social)
  4. utm_campaign – Campaign name
  5. utm_term – Campaign keywords
  6. gclid – Google Click ID
  7. gbraid – Google Brand Engagement (iOS 14+)
  8. wbraid – Web to App Brand Engagement (iOS 14+)

How THE COURIER Works

  1. Visitor arrives with UTM parameters in URL
  2. COLLECTOR captures and stores data in cookies
  3. Visitor submits a Gravity Form
  4. COURIER automatically injects all UTM data into webhook payload
  5. Your CRM receives complete attribution data – automatically!

Perfect For

  • Digital Marketing Agencies – Complete campaign attribution without manual setup
  • E-commerce Sites – Track ROI from every marketing channel
  • Lead Generation – Automatic UTM data in your CRM
  • SaaS Companies – Understand customer acquisition sources
  • PPC Campaigns – Full Google Ads and Facebook Ads tracking

What’s NEW in v2.0.0?

  • 🎯 COLLECTOR System – Advanced cookie tracking engine
  • 📦 COURIER System – Automatic webhook injection (no manual fields!)
  • 🎨 Animated Dashboard – Real-time system diagnostics with animations
  • 📊 Entry Meta Storage – UTM data saved with each form submission
  • 🔧 Excluded Webhooks – Option to exclude specific webhook URLs
  • ✨ iOS 14+ Support – gbraid and wbraid parameter tracking
  • 🚀 Zero Configuration – Works automatically after activation

Gravity Forms Integration (THE COURIER)

🚀 No Manual Field Creation Required!

The COURIER system automatically injects all UTM data into Gravity Forms webhook submissions. Simply:

  1. Enable “Gravity Forms Integration” in plugin settings
  2. Set up your Gravity Forms webhooks as normal
  3. The COURIER automatically adds UTM data to every webhook request

Optional: You can still create visible fields with parameter names (referrer, utm_source, etc.) if you want users to see the data. The COLLECTOR will populate them automatically.

Excluded Webhooks: Configure specific webhook URLs to exclude from UTM injection (useful for internal notifications).

Technical Features

  • Lightweight – Minimal impact on site performance
  • Standards Compliant – Follows WordPress coding standards
  • Secure – Proper data sanitization and validation
  • Translatable – Ready for internationalization
  • Mobile Friendly – Works across all devices and browsers
  • Entry Meta Storage – UTM data stored with each Gravity Forms entry
  • Webhook Automation – Zero configuration webhook injection
  • Animated UI – Real-time system status with smooth animations

Use Cases

Marketing Attribution: Track which campaigns generate the most leads and sales – automatically!

CRM Integration: UTM data flows seamlessly to your CRM via Gravity Forms webhooks.

A/B Testing: Compare performance between different campaign variations.

ROI Analysis: Calculate return on investment for different marketing channels.

Customer Journey: Understand how visitors discover and interact with your site.

External services

BaseCloud UTM Tracker never sends data to BaseCloud. The services below are contacted only when you switch the related Blog Post Conversion Tracker feature on and save the credentials it needs. Conversion and report webhooks send data only to the https URLs you enter yourself.

Google OAuth 2.0 and Google Search Console API

Used by Search keywords to read Search Console query data for your own site.

  • Hosts: oauth2.googleapis.com (access token) and www.googleapis.com (Search Console API).
  • When: only while Search keywords is enabled and a service account key is saved: the initial backfill of your Search Console history runs about every 5 minutes until it is complete, then a daily sync, plus “Test connection” and “Sync now”.
  • Data sent: a JWT signed with your service account key (the service account email and a read-only scope) and the Search Console property with date ranges. Data received: query, page, click and impression rows. No visitor data is sent.
  • Google APIs Terms of Service: https://developers.google.com/terms
  • Google Privacy Policy: https://policies.google.com/privacy

OpenAI, Perplexity and Anthropic crawler IP ranges

Used by the AI crawler log to check that requests claiming to come from these companies’ crawlers come from the IP ranges they publish.

  • Hosts: openai.com, www.perplexity.ai and claude.com.
  • When: only while the AI crawler log and IP verification are both on: one GET request for each vendor’s public IP-range file about once a week, or when you click “Refresh crawler IP ranges” (which also needs both settings on).
  • Data sent: nothing beyond the request itself.
  • OpenAI Terms of Use: https://openai.com/policies/terms-of-use and Privacy Policy: https://openai.com/policies/privacy-policy
  • Perplexity Terms of Service: https://www.perplexity.ai/hub/legal/terms-of-service and Privacy Policy: https://www.perplexity.ai/hub/legal/privacy-policy
  • Anthropic Privacy Policy: https://www.anthropic.com/legal/privacy

Ahrefs API v3

Used by AI answer citations to read how often AI answers cite your pages (Ahrefs Brand Radar).

  • Host: api.ahrefs.com.
  • When: only while the Ahrefs feature is enabled and an API key is saved: a weekly sync (one request plus one for each selected AI platform), plus “Test connection” and “Sync now”. Calls use Ahrefs API units from your Ahrefs subscription.
  • Data sent: your API key, the target domain, the selected AI platforms and the optional country.
  • Ahrefs Terms of Service: https://ahrefs.com/legal/terms
  • Ahrefs Privacy Policy: https://ahrefs.com/legal/privacy-policy

Privacy Policy

BaseCloud UTM Tracker uses first-party cookies for campaign and content attribution. It never sends data to BaseCloud. Data only leaves your site through integrations you configure yourself: your form and report webhooks, the Meta Conversions API, and the Search Console, Ahrefs and crawler IP-range services described under External services, each only if you enable it.

UTM tracker

  • Stores UTM parameters, click IDs, the referrer and the landing page in first-party, SameSite cookies (duration configurable)
  • Adds them to form submissions and to the webhooks you configure
  • Meta Conversions API (off by default) sends SHA-256 hashed email and phone, IP address and user agent to Meta

Blog Post Conversion Tracker (off by default)

  • Keeps the pages and blog posts a visitor viewed on your site, their first and latest visit source, and visit counts in the browser’s localStorage, with a compact first-party cookie (bc_blog_attr) as a backup
  • When a Gravity Form is submitted, adds that journey to the submission as a hidden field, saves it on the entry and sends it, with the form fields and contact details you choose, to the webhooks you configure
  • Optional consent mode waits for your consent cookie or Google Consent Mode before tracking

Search keywords, AI visibility and reports (off by default)

  • Store aggregated data only: Search Console query, page, click and impression counts; AI crawler hits per page and bot (no IP addresses); AI citation counts from Ahrefs; and one row per conversion with post IDs, channel labels, the landing path and dates. No names, email addresses, IP addresses or form values are added.
  • Contact Google, Ahrefs, OpenAI, Perplexity and Anthropic only as described under External services, and send reports only to the report webhooks you configure.

Website owners should disclose these cookies and any webhook destinations in their privacy policy, and obtain consent where the law requires it (for example GDPR or POPIA).

Support

For support, feature requests, or bug reports, please visit:
* Plugin Support: WordPress.org Support Forum
* Professional Support: BaseCloud Global
* Documentation: Plugin Documentation

About BaseCloud

BaseCloud Global is a technology company focused on creating powerful, user-friendly WordPress solutions for businesses and marketers. Our plugins are designed with performance, security, and usability in mind.

Visit us at basecloudglobal.com for more WordPress solutions.

Plugin Details

Active Installs
90
Total Downloads
1,739
Version
4.3.0
Requires WP
5.0
Requires PHP
7.4
Tested Up To
6.8.8
Added
2025-09-16
Last Updated
2026-09-14 9:53am GMT

Ratings

5
2
4
0
3
0
2
0
1
0