Title: ClickHelm – Click Fraud Protection &amp; Bot Blocking
Author: ClickHelm
Published: <strong>3 ตุลาคม 2026</strong>
Last modified: 3 ตุลาคม 2026

---

Search plugins

![](https://ps.w.org/clickhelm/assets/banner-772x250.png?rev=3726360)

![](https://ps.w.org/clickhelm/assets/icon-256x256.png?rev=3726360)

# ClickHelm – Click Fraud Protection & Bot Blocking

 By [ClickHelm](https://profiles.wordpress.org/clickhelm/)

[Download](https://downloads.wordpress.org/plugin/clickhelm.6.92.0.zip)

 * [Details](https://th.wordpress.org/plugins/clickhelm/#description)
 * [Reviews](https://th.wordpress.org/plugins/clickhelm/#reviews)
 *  [Installation](https://th.wordpress.org/plugins/clickhelm/#installation)
 * [Development](https://th.wordpress.org/plugins/clickhelm/#developers)

 [Support](https://wordpress.org/support/plugin/clickhelm/)

## Description

ClickHelm watches who arrives on your site from Google Ads and works out which of
them are
 costing you money without ever becoming a customer.

**No limit, no time limit, no card, and nothing to unlock.** There is no visit cap,
no site
 count and no key to enter. Everything described below runs on every install,
for as long as you keep the plugin.

**It recognises the person, not the address.** Identity comes from a device fingerprint
resolved
 on your own server, so the same visitor is still the same visitor after
clearing their storage, switching browser, or moving from home WiFi to mobile data.
An address on its own tells you little: it changes when a phone’s data is turned
off and on.

#### What it shows you

 * **Dashboard** — the traffic you paid for, what it cost, and which visitors are
   worth a second
    look today, ranked, each with the reasoning in plain language
 * **Visitors** — everyone seen, searchable and filterable, with the evidence behind
   each score:
    the fingerprint, the addresses, the networks, and what they did 
   on each visit
 * **Google Ads** — spend, waste and profit per campaign, ad group, keyword and 
   placement, with
    your own click log beside the clicks Google actually charged
   you for
 * **The exclusion list** — every address worth excluding, ready to copy into Google
   Ads
 * **Possible Duplicates** — fingerprints that probably belong to someone you already
   know

#### What this edition does not do

**It does not block anyone.** It shows you who is costing you money and leaves the
acting to you.
 Copying addresses into Google Ads by hand works, and is what the
exclusion list is for.

Automatic blocking, your own rules, the breakdown reports and heatmaps are a separate
plugin sold
 from clickhelm.com. **None of that code is in this one** — it is not
here and switched off, it is not here at all.

#### What it measures

Revenue is read from the actual WooCommerce order on the server, so it counts even
when a
 shopper blocks scripts, and it is the real total rather than an estimate.
That is what makes genuine per-campaign profit and loss possible.

Calls, WhatsApp taps, form submissions, thank-you pages and your own buttons all
count as
 leads, so the plugin works for a service business as well as a shop.

#### Email

A weekly or monthly report summarising what the plugin saw, what it cost you, and
which
 visitors are worth a look, with a link straight to each one. Switch it on
under Settings, and tell it not to write when there is nothing to say.

#### Privacy

Visitor data stays in your own database. One thing can leave it, and only if you
say so: visitor
 IP addresses, for address classification. They go to api.clickhelm.
com, which asks proxycheck.io and keeps none of them. **It is off until you switch
it on** – the setup asks, in plain words, and Settings has the switch. Say so in
your site’s privacy policy if you do switch it on. Old data is cleaned up automatically
on a schedule you set.

### External services

Every request below leaves from your own server. Nothing is ever sent from a visitor’s
browser.
 This plugin does not check a licence, does not look for its own updates–
updates come from WordPress.org like any other plugin here – and sends no usage 
reports. The one thing our server learns about your site is described under Address
classification below: that it asked, and when.

**Google Ads** (googleads.googleapis.com), only with a licence, and only if you 
connect an account

If you choose to connect Google Ads, the plugin reads your own campaign reporting
once a day –
 click identifiers, campaign and keyword names, and cost figures – 
so it can compare the clicks recorded on your site against the clicks Google actually
charged you for.

It changes two things in the account, and only when you switch them on in the plugin:
it can add
 ClickHelm’s tracking template to the account, and it can keep an account-
level IP exclusion list made from the visitors you blocked (never anybody you did
not block, and never exclusions you added yourself). It never touches campaigns,
ads, budgets or bids. Our server builds those two changes itself and refuses any
other kind.

The request is routed through api.clickhelm.com because Google requires credentials
that cannot
 be shipped inside a plugin; the reporting data is passed straight through
to your site and is not stored on our server. You can disconnect at any time.

What is read and why: https://clickhelm.com/google-ads-data
 Terms: https://clickhelm.
com/terms Privacy: https://clickhelm.com/privacy

**Address classification** (api.clickhelm.com, then proxycheck.io)

This one is off until you switch it on, and the setup asks. A visitor arriving from
a data centre, a VPN
 or a commercial proxy is the cheapest kind of fraudulent click
there is, and telling them apart from a real customer cannot be done on your own
server – it needs a database of who owns which network, kept current by somebody
whose job that is.

So the plugin sends visitor IP addresses to api.clickhelm.com, which passes them
to
 proxycheck.io under our account and hands the answer back: country, network 
operator, and whether the address belongs to a VPN, proxy, Tor exit or data centre.
Each address is looked up once and remembered on your site, so a returning visitor
costs nothing.

Our server keeps none of the addresses. They are relayed and discarded within the
request; what
 it records is how many were classified, never which – together with
the address of the site that asked, the plugin version and the time. That record
is what enforces each site’s daily allowance, and it is kept for nothing else. You
do not need an account anywhere and there is no key to enter.

The same answer can carry short notices from ClickHelm – that a new version is out,
or something
 about security – which the plugin shows at the top of its own screens,
never elsewhere in WordPress, in whichever of English or Arabic you read ClickHelm
in. Nothing is sent to ask for them, and each can be dismissed.

Because visitor IP addresses leave your server, say so in your site’s privacy policy.

Terms: https://clickhelm.com/terms
 Privacy: https://clickhelm.com/privacy proxycheck.
io terms: https://proxycheck.io/terms proxycheck.io privacy: https://proxycheck.
io/privacy

## Screenshots

[⌊The dashboard. What the ads cost over the period, what came back, and how much
of the spend
went on visitors worth a second look - each one listed underneath with
the reasoning in plain
language.⌉⌊The dashboard. What the ads cost over the period,
what came back, and how much of the spend
went on visitors worth a second look -
each one listed underneath with the reasoning in plain
language.⌉[

The dashboard. What the ads cost over the period, what came back, and how much of
the spend went on visitors worth a second look – each one listed underneath with
the reasoning in plain language.

[⌊Every visitor the plugin has seen, searchable and filterable, with the risk score,
the
networks they arrived on and whether they became a lead.⌉⌊Every visitor the 
plugin has seen, searchable and filterable, with the risk score, the
networks they
arrived on and whether they became a lead.⌉[

Every visitor the plugin has seen, searchable and filterable, with the risk score,
the networks they arrived on and whether they became a lead.

[⌊One visitor in full: why they scored what they scored, the device behind the fingerprint,
the
addresses they have used and the ad clicks they arrived on.⌉⌊One visitor in 
full: why they scored what they scored, the device behind the fingerprint, the
addresses
they have used and the ad clicks they arrived on.⌉[

One visitor in full: why they scored what they scored, the device behind the fingerprint,
the addresses they have used and the ad clicks they arrived on.

[⌊Google Ads by campaign - clicks, people, leads, what share was wasted and what
that cost,
from your own click log priced at the rate you set.⌉⌊Google Ads by campaign-
clicks, people, leads, what share was wasted and what that cost,
from your own click
log priced at the rate you set.⌉[

Google Ads by campaign – clicks, people, leads, what share was wasted and what that
cost, from your own click log priced at the rate you set.

[⌊The exclusion list: the addresses worth excluding, grouped by campaign, ready 
to paste into
Google Ads, with a plain note on what excluding an address does and
does not do.⌉⌊The exclusion list: the addresses worth excluding, grouped by campaign,
ready to paste into
Google Ads, with a plain note on what excluding an address does
and does not do.⌉[

The exclusion list: the addresses worth excluding, grouped by campaign, ready to
paste into Google Ads, with a plain note on what excluding an address does and does
not do.

## Installation

 1. Upload the plugin folder to `/wp-content/plugins/`, or install the zip from Plugins
    Add New  Upload Plugin.
 2. Activate it. The database tables are created automatically.
 3. Open **ClickHelm  Settings** and set your average cost per click, so the plugin
    can show what traffic is costing you rather than hiding every money figure.
 4. Open **ClickHelm  Google Ads  Setup & names** and paste the tracking template into
    Google Ads. Without it, Google does not tell the plugin which campaign a click 
    came from, and that information cannot be recovered afterwards.

## FAQ

### Can it get my money back from Google?

It can help you ask, and Google decides. Google credits the invalid clicks it detects
by
 itself, automatically. For the ones it missed you can ask it to investigate 
any click from the last 60 days, through its Click Quality form, and it wants evidence
only your website has: each click’s IP address, browser and click id, and why it
looks invalid. **Google Ads  Refund claim puts that together – an evidence file,
and a letter in English to paste into the form. Nothing guarantees a refund, and
be wary of anything that promises one. What the plugin does by itself is stop the
same person costing you again, and show you which campaigns and keywords are worth
cutting.

### Does this plugin block anyone?

No. It identifies, scores and explains, and the acting is yours: the exclusion list
gives you
 every address worth excluding, ready to paste into Google Ads. Automatic
blocking is a separate plugin from clickhelm.com, and none of its code is in this
one.

### The same person keeps coming back under a new fingerprint.

Open **Possible Duplicates**. The plugin has probably already spotted the match 
and is waiting
 for you to confirm it — lower the confidence threshold in Settings
to catch more. Confirming a match folds the two together, so the history and the
score follow the person rather than the browser they happened to use.

### Does it work with page caching?

Yes. Nothing this plugin does depends on a page being uncached: the visit is recorded
from the
 browser, so a cached page is measured exactly like an uncached one.

### Will it slow my site down?

The tracking script is small and loads without blocking the page. Everything else—
the
 scoring, the matching, the address classification — happens after the request
the visitor sees, on a schedule.

### What happens to my data if I delete the plugin?

Nothing, unless you asked for it. Deleting leaves your visitors and their history
intact
 so a reinstall picks up where you left off. To erase everything, tick the
option under Settings  Housekeeping first.

## Reviews

There are no reviews for this plugin.

## Contributors & Developers

“ClickHelm – Click Fraud Protection & Bot Blocking” is open source software. The
following people have contributed to this plugin.

Contributors

 *   [ ClickHelm ](https://profiles.wordpress.org/clickhelm/)
 *   [ Hany Mahfouz ](https://profiles.wordpress.org/hanymahfouz/)

[Translate “ClickHelm – Click Fraud Protection & Bot Blocking” into your language.](https://translate.wordpress.org/projects/wp-plugins/clickhelm)

### Interested in development?

[Browse the code](https://plugins.trac.wordpress.org/browser/clickhelm/), check 
out the [SVN repository](https://plugins.svn.wordpress.org/clickhelm/), or subscribe
to the [development log](https://plugins.trac.wordpress.org/log/clickhelm/) by [RSS](https://plugins.trac.wordpress.org/log/clickhelm/?limit=100&mode=stop_on_copy&format=rss).

## Changelog

#### 6.92.0

 * **Classifying a visitor’s address is now off until you ask for it.** The setup
   asks in plain
    words what is sent and what saying no costs, and Settings carries
   the switch. It was on from the first page view of a fresh install, which is what
   WordPress.org’s guideline 7 forbids and what their review pulled us up on – rightly.
 * **Heatmaps are out of this edition entirely.** The recording, the settings and
   the flag that
    held them shut are all gone from the file rather than disabled
   inside it.
 * The plugin’s own description on the Plugins screen described the paid edition–
   blocking, rules
    and automatic Google Ads exclusions, none of which are here.
   It describes this one now.
 * This edition no longer deactivates another copy of ClickHelm, and no longer carries
   the code
    that did.
 * The one script printed into the page markup moved into the plugin’s own JavaScript
   file.
 * Translations come from translate.wordpress.org for this edition, so no catalogues
   ship inside
    it and nothing loads them early.
 * The readme no longer says the address record is used to count how many sites 
   run the free
    edition. It is not, any more.

#### 6.91.0

 * Tested against WordPress 7.1.
 * The plugin is credited to the ClickHelm account, which owns it, with its developer
   listed
    alongside so support questions reach a person.
 * **Fixed: an admin page load could erase the campaign behind arrivals it had already
   recorded.**
    The backfill that reads ad parameters out of each stored landing-
   page URL wrote its answer for every field, including the ones the URL said nothing
   about – so any arrival whose campaign came from somewhere else lost it. Measured
   on a test site: one page load erased the campaign, ad group, keyword, match type,
   network and device from 487 of 1,689 arrivals. It now fills blanks and never 
   overwrites.
 * **Fixed: the free edition’s tab strip linked to three screens it does not have.**
   Reports,
    Rules and Your plan were still printed above every screen; opening 
   one answered “you are not allowed to access this page”.
 * The free edition no longer carries the paid features at all. Blocking, rules,
   reports and
    heatmaps used to ship inside it behind a licence check, and the 
   month was capped at 500 visits. Both are gone from this build: the code is not
   there to unlock, and nothing counts down. What the free edition does, it does
   without limit.
 * Percentages, and the three words under every dashboard figure – no change, nothing
   to
    compare, flat – are translated. They were English in every language.
 * The renewal-date arithmetic no longer depends on PHP’s default timezone.
 * A search containing an apostrophe now finds what it should on the Visitors screen.
 * Escaping, unslashing and the code comments that explain both, throughout – for
   the
    WordPress.org review.

#### 6.90.2

 * Housekeeping only: the plugin is credited to its developer’s WordPress.org account.
   Nothing
    in the plugin itself changed.

#### 6.90.1

 * **Fixed: a keyword running in more than one ad group reported clicks as coming
   from before
    ClickHelm was installed.
    The Keywords tab counted only the last
   ad group’s share of the
    charged clicks, so the rest were labelled “before tracking
   started” on sites where every click was inside the window. The rest of the 6.89.0
   keyword fix was correct; this one column is built elsewhere and was missed.
 * **Fixed: every install and every upgrade logged two database errors.** Comments
   written
    inside the table definitions were read as columns, producing two invalid
   statements that added nothing — harmless, but the first thing anybody debugging
   a real problem would meet.

The releases before 6.90.0 are in changelog.txt, which ships with the plugin.

## Meta

 *  Version **6.92.0**
 *  Last updated **1 วัน ago**
 *  Active installations **Fewer than 10**
 *  WordPress version ** 5.6 or higher **
 *  Tested up to **7.1.2**
 *  PHP version ** 7.2 or higher **
 *  Language
 * [English (US)](https://wordpress.org/plugins/clickhelm/)
 * Tags
 * [ad fraud](https://th.wordpress.org/plugins/tags/ad-fraud/)[bot detection](https://th.wordpress.org/plugins/tags/bot-detection/)
   [click-fraud](https://th.wordpress.org/plugins/tags/click-fraud/)[google ads](https://th.wordpress.org/plugins/tags/google-ads/)
   [ppc](https://th.wordpress.org/plugins/tags/ppc/)
 *  [Advanced View](https://th.wordpress.org/plugins/clickhelm/advanced/)

## Ratings

No reviews have been submitted yet.

[Your review](https://wordpress.org/support/plugin/clickhelm/reviews/#new-post)

[See all reviews](https://wordpress.org/support/plugin/clickhelm/reviews/)

## Contributors

 *   [ ClickHelm ](https://profiles.wordpress.org/clickhelm/)
 *   [ Hany Mahfouz ](https://profiles.wordpress.org/hanymahfouz/)

## Support

Got something to say? Need help?

 [View support forum](https://wordpress.org/support/plugin/clickhelm/)