CQI Referrer Attribution
Know where every visitor came from, including ChatGPT, Gemini, and Perplexity. No JavaScript, no cookie banner trigger, no page speed cost.
Use with caution
CQI Referrer Attribution works, but test it on a staging site before relying on it in 2026. It runs on 20+ sites and was last updated 3 months ago, and scores 58/100 on our health check.
- Momentum β downloads up 108.1% vs the previous 30 days
- Small user base (20+ active installs)
- Very few reviews so far
How does it stack up?
Side-by-side on installs, updates, ratings & supportDaily downloads
Download spikes usually follow a new release β each site that auto-updates counts as a download.
Rankings
Where CQI Referrer Attribution stands todayWordPress.org search rankings
Live position in the plugin search, top 100| Keyword | Position |
|---|---|
| ai traffic | >100 |
| attribution | #28 |
| marketing attribution | #18 |
| referrer | #41 |
| traffic channels | #64 |
Version adoption
Share of active sites per release.
About CQI Referrer Attribution
From the official readme Β· v1.10.0Description
Most analytics plugins guess where your traffic came from by running a script in the visitor’s browser, after the page has already loaded, and after any ad blocker or privacy extension has had a chance to block it. CQI Referrer Attribution classifies every visit on the server, before the page is even sent, so the data is complete and the plugin adds no client-side JavaScript, no extra request, and no Core Web Vitals penalty.
It also answers a question most attribution tools still miss: how much of your traffic is coming from AI assistants. ChatGPT, Gemini, Perplexity, Claude, Copilot, and a growing list of others now send real visitors. This plugin classifies that traffic as its own channel, not lumped into Direct or Referral where it disappears.
Nine channels are detected automatically: AI Tools, Organic Search, Social Media, Email, Paid Search, Paid Display, Campaign, Referral, and Direct.
This plugin is fully functional with no licence key, trial period, or usage limit of any kind.
AI Referrer Taxonomy
A built-in registry of AI assistant domains is used to classify AI-referred traffic. The default set includes ChatGPT, Google Gemini, Perplexity, Claude, Microsoft Copilot, Grok, Meta AI, and more. Entries can be added, edited, activated, deactivated, deleted, and exported as JSON.
Dashboard
A 30-day summary showing total sessions with a live counter that updates automatically as new sessions arrive, session change versus the previous 30 days, AI traffic sessions and their share of total traffic, top channel, a channel share donut chart, a source share donut chart, and a sessions-per-day bar chart.
Sessions log
The full Sessions report supports date range, channel, and source filters, pagination, and CSV export. Any session spanning more than one page view can be expanded to show the full page-by-page journey in chronological order.
Sample data
One click on the Settings tab loads 60 realistic synthetic sessions across every channel, spread over the past 30 days, so the Dashboard and Reports are populated immediately on a fresh install. Sample rows are clearly marked and can be removed at any time without affecting real attribution data.
Consent-aware
When CQI Consent is active, attribution is only persisted after marketing consent is granted. Without consent, classification runs in memory only and no cookie or database row is written. The plugin operates in permissive mode when CQI Consent is not installed.
Independent of CQI Consent, the plugin reads the Global Privacy Control signal (the Sec-GPC HTTP header) on every request and does not persist attribution when it is present. This is checked regardless of whether any consent plugin is installed.
When CQI Consent is not installed, the plugin also recognises marketing consent already withheld through Complianz or CookieYes, if either is active on the site, using each plugin’s own consent cookie. Borlabs Cookie is not currently supported, since its consent cookie format is not publicly documented; sites running Borlabs Cookie alone currently operate in permissive mode, the same as a site with no consent plugin at all.
Privacy by design
No personal data is stored. Session tokens are HMAC-SHA256 hashes of an anonymized IP address (last octet zeroed) and the current date. Raw IP addresses are never written to disk. Token rotation is daily. The plugin is registered with the WordPress personal data export and erasure framework.
Excluded channels
Any channel can be excluded from the Dashboard summary, the channel share chart, and the Sessions report. This is most useful for removing Direct / Unknown from view so reports focus on traffic you can actually attribute and act on.
Path exclusions and bot filtering
A built-in guard silently drops requests to /robots.txt, /sitemap.xml, /xmlrpc.php, /favicon.ico, and other system paths before classification runs. Additional path prefixes can be added in Settings, one per line, to suppress noise from any crawlers or automated probes specific to your site.
Public PHP API
Two functions are available for use in themes and other plugins:
cqip_attr_get_channel(), returns the current visitor’s channel slugcqip_attr_get_source(), returns the full attribution array
These function names are intentionally preserved from CQIP Site Services v1.8.0 for backward compatibility on sites migrating from that plugin.
Filter and action hooks
These hooks let other plugins extend this plugin’s behaviour. They are not used by this plugin itself; they exist for add-ons such as CQI Referrer Attribution Pro.
cqi_referrer_attribution_logo_url(filter), the mark shown in the admin page headercqi_referrer_attribution_plugin_name(filter), the page title shown in the admin page headercqi_ra_session_logged(action), fires after each session is recorded, receives the new row’s ID and datacqi_ra_admin_tabs(action), fires inside the admin page’s tab navigation, after the built-in tabscqi_ra_unknown_tab_handled(filter), fires when an unrecognized tab slug is requested, lets an add-on render its own tab bodycqi_ra_sessions_view_filters(filter), the Sessions report’s query filters, before the session log is queried; also applied before CSV export runscqi_ra_sessions_filter_bar(action), fires inside the Sessions filter bar, after the built-in filter fieldscqi_ra_sessions_table_header(action), fires inside the Sessions table header row, after the built-in columnscqi_ra_sessions_table_row(action), fires inside each Sessions table row, after the built-in columns, receives the row objectcqi_ra_dashboard_log_id_in(filter), restricts Dashboard metrics to a specific list of session row IDs
What is CQI?
CQI (Content Quality and Intelligence) is a methodology standard that is followed, not a technology stack. Implementations can exist for static PHP sites, WordPress, page generators, and other document management systems. Its purpose is to encourage structured content that benefits human and machine readers.
Installation
- Upload the
cqi-referrer-attributionfolder to/wp-content/plugins/. - Activate the plugin through the Plugins menu in WordPress.
- Go to Attribution in the WordPress admin menu to view the Dashboard.
No configuration is required after activation. Classification begins on the next front-end page request.
Frequently asked questions
Does this plugin use JavaScript to track visitors?
No. Classification is entirely server-side. No tracking scripts are added to the front end.
Does this plugin store personal data?
No. Session tokens are one-way cryptographic hashes (HMAC-SHA256) of an anonymized IP address and the current date. Raw IP addresses are never stored. Tokens cannot be reversed to identify an individual.
I have CQIP Site Services installed. Can I run both?
Not at the same time, if CQIP Site Services has its own Referrer Attribution module active. Both write to the same database tables, since this plugin was extracted from that module and preserves its table and option names for migration compatibility. If CQIP_SS_ENABLE_REFERRER is set to true in your wp-config.php, this plugin detects that and refuses to activate, showing an admin notice with the exact line to add to wp-config.php to resolve it. Existing attribution data carries over automatically once the conflict is resolved.
How does the AI channel work?
When a visitor arrives via a referrer that matches an entry in the AI Referrer Taxonomy, the session is classified as the AI Tools channel. The matched platform name (e.g. βChatGPTβ) is stored as the source. The default taxonomy includes 19 domain entries covering 16 distinct platforms, since ChatGPT, Google Gemini, and Microsoft Copilot are each matched against two domains (for example, both chatgpt.com and openai.com resolve to ChatGPT). The full default set: ChatGPT, Google Gemini, Perplexity, Claude, Microsoft Copilot, You.com, Phind, Poe, Character.AI, Hugging Face, Mistral, Groq, Grokβ¦
Will this work with GDPR / UK-GDPR?
The plugin does not store personal data and is registered with the WordPress personal data export and erasure framework. When CQI Consent is active, attribution is only persisted after marketing consent. As with any tool that processes visitor data, your own legal assessment of your siteβs practices is advisable.
What happens if a visitor does not have a referrer?
Visits with no referrer and no UTM parameters are classified as the direct channel.
Can I remove Direct / Unknown, or any other channel, from reports?
Yes. Go to Attribution > Settings > Excluded channels and check any channels you want removed. Excluded channels are removed from the Dashboard summary cards, the channel share chart, and the Sessions report, including CSV export. This is commonly used to exclude Direct / Unknown so reports focus on attributable traffic.
What happens to my data if I delete the plugin?
By default, nothing is removed. Your attribution data, settings, and AI taxonomy stay in the database in case you reinstall later. If you want a clean removal, enable Attribution > Settings > Data and Storage > Delete data on uninstall before deleting the plugin. With that enabled, deleting the plugin permanently removes the attribution log, all plugin settings, and the AI taxonomy. This cannot be undone.
How do I stop bot probes and crawler noise appearing in the session log?
Go to Attribution > Settings > Path Exclusions. Add one path prefix per line. Any request whose URL starts with a listed path is silently dropped before classification runs. Common entries are /robots.txt, /sitemap.xml, /feed/, and any path your monitoring tools or uptime checkers hit. The plugin also has a built-in guard that automatically excludes /xmlrpc.php, /wp-cron.php, /wp-signup.php, /favicon.ico, and other WordPress system paths regardless of your exclusion list.
What is the channel priority order?
When more than one signal is present on a session, this priority order applies: UTM parameters (utm_medium determines email, social, paid search, paid display, or campaign) AI Referrer Taxonomy match Known search engine referrer (organic search) Known social platform referrer Referral (any other external domain with a referrer) Direct (no referrer, no UTM parameters)
How are Paid Search and Paid Display detected?
Both are detected from the utm_medium URL parameter, not from the referrer header. utm_medium set to cpc or ppc is classified as Paid Search. utm_medium set to display is classified as Paid Display. Any other utm_medium value is classified as Campaign. If your paid traffic does not carry UTM parameters, those sessions are classified by referrer instead, typically landing in Organic Search, Referral, or Direct depending on the source. Tagging every paid URL with UTM parameters is required for accurate Paid Search and Paid Display classification.
Changelog
The Dashboard's Conversions and Conversion Rate cards have been replaced with AI Traffic Sessions. Both removed cards always showed zero on every site; this plugin has never included conversion tracking.
1.10.0
- Note on versioning: the last publicly released version was 1.8.0. Versions 1.9.0 and 1.9.1 (same-session multi-page attribution, the is_first_touch flag, and the First Touch column) were completed as internal builds but were never publicly released. This release supersedes both and is the first public release since 1.8.0; their changelog entries below are kept as an accurate build record and are not being removed or rewritten.
- Added: Session Journey. The Sessions report now shows a Touches count for every session and, for any session with more than one page view, an expand control revealing the full page-by-page path in chronological order. Free tier, no licence gate, matching how Refer App (the standalone edition of this product) already ships this on its own Reports tab.
- Added: a live session counter on the Dashboard. The Sessions card now polls every 30 seconds and updates in place, with a brief highlight, when a new session is recorded, without a full page reload.
- Added: a “By Source” donut chart on the Dashboard, alongside the existing channel breakdown, showing session share by specific source domain rather than channel category.
- Added: a “Sessions Per Day” bar chart on the Dashboard, covering the same 30-day window as the rest of the Dashboard.
- Changed: the Dashboard’s single channel-share pie chart is now a donut, sitting alongside the new source donut and daily bar chart in a three-panel layout.
- Added: one-click sample data on the Settings tab. Loads 60 synthetic sessions spread across the past 30 days, across every channel, for a populated Dashboard, Reports, and channel share chart on a fresh install. Sample rows use a reserved session token prefix and can be removed at any time with no effect on real attribution data.
1.9.1
- Added: a “First Touch” column on the Sessions report and in its CSV export, showing whether each row is the page that first brought the visitor to your site or a page they viewed afterward in the same visit. Surfaces the is_first_touch data added in 1.9.0 directly in the free Sessions report.
1.9.0
- Added: same-session first-touch and last-touch attribution. Previously, a returning page view within the same browsing session (while the attribution cookie was still valid) was correctly attributed to the original entry channel, but no log row was written for it at all β the Sessions report only ever showed a session’s first page, never anything browsed afterward, and there was no way to see which page a same-session conversion actually happened from. Every page view in a session now gets its own row, carrying the session’s real entry channel, source, and UTM data forward, each marked with a new is_first_touch flag (true only for the session’s first page). This uses the existing daily-rotating session token exactly as it already works: no new identifier, no cross-day linking, no change to this plugin’s privacy design. Cross-day, multi-visit attribution remains explicitly out of scope.
- Fixed, audited as part of this change: every session-count query in this plugin counted rows rather than distinct sessions. With a session now able to span multiple rows, this would have inflated every session count (Dashboard, Trends, Insights’ Attribution Coverage) in proportion to how many pages each visitor browses. All four affected queries now count DISTINCT session tokens; the one query that should still count rows (the Sessions report’s own pagination total, where each row is correctly its own line) was identified and deliberately left unchanged.
- A real bug was caught and fixed before it ever shipped, by tracing the code directly rather than trusting the comment written alongside the first draft: the returning-visit code path was overwriting each new row’s landing_url with the session’s original (first-page) URL instead of the current page’s own URL, which would have made every subsequent page in a session repeat the entry page’s address forever, defeating the entire purpose of recording a row per page.
- The Plugin Test Rig gained a new scenario simulating a real two-page browsing session: it genuinely carries the attribution cookie from the first request’s response into the second request, the same way a real browser does, and confirms the second page gets its own row, the same session token, the original channel carried forward, its own distinct landing URL, and the correct is_first_touch flag on both rows.
1.8.1
- Documentation only, no code change: the “How does the AI channel work?” FAQ entry stated the default taxonomy includes 19 entries while naming only two of them, which a careful reviewer correctly flagged as potentially incomplete rather than guessing at what the rest might be. All 19 entries were checked directly against the taxonomy’s own source array: 19 domain entries cover 16 distinct platforms, since ChatGPT, Google Gemini, and Microsoft Copilot are each matched against two domains. The FAQ entry now names all 16 platforms explicitly and explains the domain-count distinction, so this never needs reverse-engineering from source again.
1.8.0
- Added: Direct / Unknown sessions are now excluded by default from the Dashboard’s Channel Share chart and summary cards, with a visible notice stating how many sessions were excluded and a one-click toggle to show them again. Direct/Unknown is usually the largest single channel and tends to visually swamp every genuinely interesting channel on a chart this size. This is a per-view, reversible default (a URL parameter, not a stored setting) β separate from the existing, permanent “excluded channels” setting on the Settings tab, which still applies underneath it and is never silently overridden by this toggle.
- Fixed during the same change: the Dashboard’s summary cards and its pie chart computed their channel breakdown independently in two separate methods, which had no mechanism keeping them in agreement. Both now apply the same exclusion logic from a single source of truth.
- Clarified, not changed: the default AI Referrer Taxonomy’s “19 entries,” stated in the 1.6.0 changelog entry below, is a count of taxonomy rows, not distinct platform names β three platforms (ChatGPT, Google Gemini, Microsoft Copilot) are each matched against two domains, so 19 entries cover 16 distinct platforms. Raised directly by a developer cross-checking the changelog against the platform names actually listed; this entry exists so that distinction is stated plainly going forward rather than left to be inferred.
1.7.0
- Added: CQI_RA_DB::get_channel_breakdown_for_period(), a public method returning a channel breakdown for an arbitrary date range. Not used by this plugin itself; added for an add-on (CQI Referrer Attribution Pro) that needs a previous-period channel breakdown to show attribution coverage change over time, which get_dashboard_metrics() does not provide on its own.
For developers
Is this your plugin? Show off the numbers.
Add a live badge to your site, docs or GitHub README. It updates on its own β no account needed.
Best CQI Referrer Attribution alternatives
All ai traffic plugins βFAQ
CQI Referrer Attribution: quick answers
Straight answers, pulled from live WordPress.org data.
Live data from WordPress.org Β· checked Oct 1, 2026
Is CQI Referrer Attribution free?
Yes. CQI Referrer Attribution is free to download and use from the official WordPress.org plugin directory.
Is CQI Referrer Attribution safe to use in 2026?
CQI Referrer Attribution works, but test it on a staging site before relying on it in 2026. It runs on 20+ sites and was last updated 3 months ago, and scores 58/100 on our health check.
How many websites use CQI Referrer Attribution?
CQI Referrer Attribution is active on 20+ WordPress websites and has been downloaded 1,365 times since it launched in June 2026. It was downloaded 691 times in the last 30 days.
Does CQI Referrer Attribution work with WordPress 7.1?
CQI Referrer Attribution is officially tested up to WordPress 7.0.6, while the latest release is 7.1.2. It may still work, but try it on a staging site first.
What PHP version does CQI Referrer Attribution need?
CQI Referrer Attribution requires PHP 7.4 or higher. Most hosts run PHP 8.x today, so it works on any modern WordPress hosting.
When was CQI Referrer Attribution last updated?
The latest version, 1.10.0, was released on July 10, 2026 (3 months ago).
Who makes CQI Referrer Attribution?
CQI Referrer Attribution is developed and maintained by hdfraser.
What are the best alternatives to CQI Referrer Attribution?
The most popular alternatives to CQI Referrer Attribution are AI Agent Analytics by Sales⦠(40+ installs), A360 Insights (10+ installs) and BotSieve (<10 installs).
Powered by PageForge
Want thousands of pages that rank like these? Build them in an afternoon.
This directory runs on the same engine as PageForge. Turn any spreadsheet, CSV or API into thousands of fast, SEO-ready WordPress pages β with schema, internal links and AI-written copy baked in.
- CSV, Google Sheets & API data sources
- AI content, schema & internal links per page
- Works with Elementor, Gutenberg, Yoast & Rank Math
- Free on WordPress.org β no credit card


