{"id":353110,"date":"2026-08-18T04:09:18","date_gmt":"2026-08-18T04:09:18","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/myvitalassistant\/"},"modified":"2026-08-18T04:08:45","modified_gmt":"2026-08-18T04:08:45","slug":"myvitalassistant","status":"publish","type":"plugin","link":"https:\/\/en-nz.wordpress.org\/plugins\/myvitalassistant\/","author":23548354,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"1.5.4","stable_tag":"1.5.4","tested":"7.0.4","requires":"6.3","requires_php":"7.4","requires_plugins":null,"header_name":"MyVitalAssistant","header_author":"Vital Consulting","header_description":"Serves MyVitalAssistant's ad-attribution tracking from your own domain, so Safari stops deleting your visitors' attribution after seven days. Captures form submissions from Contact Form 7, WPForms, Gravity Forms, Fluent Forms, Ninja Forms, Formidable, Elementor, and Keap's own Opt-in Forms plugin so attribution reaches your CRM without any field wiring.","assets_banners_color":"","last_updated":"2026-08-18 04:08:45","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"https:\/\/help.myvitalassistant.com\/cookie-lifetime","header_author_uri":"https:\/\/vitalconsulting.net","rating":0,"author_block_rating":0,"active_installs":0,"downloads":24,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"1.5.4":{"tag":"1.5.4","author":"vitalconsulting","date":"2026-08-18 04:08:45"}},"upgrade_notice":[],"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3651998,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3651998,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":[],"assets_blueprints":{},"all_blocks":[],"tagged_versions":["1.5.4"],"block_files":[],"assets_screenshots":[],"screenshots":[]},"plugin_section":[],"plugin_tags":[232,9067,168755,550,286],"plugin_category":[36,45],"plugin_contributors":[276195],"plugin_business_model":[],"class_list":["post-353110","plugin","type-plugin","status-publish","hentry","plugin_tags-analytics","plugin_tags-attribution","plugin_tags-keap","plugin_tags-tracking","plugin_tags-woocommerce","plugin_category-analytics","plugin_category-ecommerce","plugin_contributors-vitalconsulting","plugin_committers-vitalconsulting"],"banners":[],"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/myvitalassistant\/assets\/icon-128x128.png?rev=3651998","icon_2x":"https:\/\/ps.w.org\/myvitalassistant\/assets\/icon-256x256.png?rev=3651998","generated":false},"screenshots":[],"raw_content":"<!--section=description-->\n<p>This is the companion plugin for <a href=\"https:\/\/myvitalassistant.com\">MyVitalAssistant<\/a>, a marketing attribution service for businesses that run Keap or HighLevel alongside Google and Meta ads. It requires a MyVitalAssistant account and does nothing until you connect one on its settings page.<\/p>\n\n<p>It does three things.<\/p>\n\n<p><strong>Serves tracking from your own domain.<\/strong> The MyVitalAssistant tracking script normally loads from a tracking subdomain. Safari treats a first party name answering from a third party network as cloaking and caps its cookie at seven days, which quietly erases the ad click that earned each visitor. This plugin claims one path on your site, \/vt\/, and forwards it to the MyVitalAssistant collector, so the browser only ever talks to your own domain and the attribution cookie lives its full term.<\/p>\n\n<p><strong>Carries attribution into your forms.<\/strong> When a visitor submits a form built with Contact Form 7, WPForms, Gravity Forms, Fluent Forms, Ninja Forms, Formidable, Elementor Pro, or Keap Opt-in Forms, the plugin sends the submitted email, name, and phone along with the visitor's attribution cookie to your MyVitalAssistant account, which writes the attribution onto the contact in your connected CRM, Keap or HighLevel. No hidden fields to wire.<\/p>\n\n<p><strong>Optionally syncs WooCommerce orders.<\/strong> If you paste an order sync key from your MyVitalAssistant account, paid orders, status changes, and refunds are sent across so your sales reach your CRM and your books with the ad that earned them already attached. This is off until you paste the key. The payload is built field by field on an allow list; order meta beyond WooCommerce's own attribution fields and known CRM ids never leaves your server.<\/p>\n\n<p>Nothing is stored on your site beyond the plugin settings and a small activity log of the last 100 captures. No database tables are created.<\/p>\n\n<h3>External services<\/h3>\n\n<p>This plugin is a connector for the MyVitalAssistant service, operated by Vital Consulting. It sends data to the collector endpoint you configure, which is https:\/\/t.myvitalassistant.com unless support tells you otherwise.<\/p>\n\n<p>The plugin contacts no external service at all until you connect your account on its settings page. Connecting is the deliberate opt in: every call listed below starts only after you have registered with the service and configured the plugin, and stops the moment you deactivate.<\/p>\n\n<p>What is sent, and when:<\/p>\n\n<ul>\n<li><strong>Visitor tracking beacons.<\/strong> When a page loads, the tracking script sends the page URL, referrer, any ad click ids and UTM parameters on the URL, and an anonymous visitor id, through your own \/vt\/ path to the collector. This runs on every public page view once the plugin is connected.<\/li>\n<li><strong>Form captures.<\/strong> When one of the supported form plugins accepts a submission, the plugin sends the submitted email, name, and phone plus the visitor's attribution cookie to the collector, so the lead's contact in your connected CRM receives its attribution.<\/li>\n<li><strong>WooCommerce orders.<\/strong> Only if you paste the optional order sync key: order number, status, totals, line items, billing name, email, phone and company, coupon and refund details, and WooCommerce's own attribution meta are sent when payment completes, when status changes, and when a refund is recorded.<\/li>\n<li><strong>Account linking.<\/strong> When you enter your MyVitalAssistant email on the settings page, the plugin sends that email and your site URL once to look up your account.<\/li>\n<li><strong>A daily heartbeat.<\/strong> Once a day the plugin pings the collector with your account id, your plugin version and your WordPress version, so your MyVitalAssistant dashboard can tell you the install is alive and warn you when something needs attention. On a site running WooCommerce it also sends your WooCommerce version, your store currency, and the name, folder and version number of your active commerce and CRM plugins, so the dashboard can warn you when one of those extensions changes what your order data means. That plugin list is sent only when WooCommerce is present, because that is the only situation the warning applies to. No other plugin list, no post content, no user accounts and no customer records are sent by the heartbeat. It also fetches your own home page from your server once a day to warn you if an old hand pasted tracking tag is still present and double counting.<\/li>\n<\/ul>\n\n<p>This data is processed under the MyVitalAssistant <a href=\"https:\/\/myvitalassistant.com\/terms\">terms of service<\/a> and <a href=\"https:\/\/myvitalassistant.com\/privacy\">privacy policy<\/a>. You are responsible for disclosing your use of visitor tracking in your own site's privacy policy, and for any visitor consent your jurisdiction requires.<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Install and activate the plugin.<\/li>\n<li>Go to Settings, then MyVitalAssistant.<\/li>\n<li>Enter the email address you sign in to MyVitalAssistant with and press Save. The plugin looks up your account and connects the site.<\/li>\n<li>Confirm it worked inside MyVitalAssistant under Settings, then Tracking: \"How long your cookie lives\" should read 400 DAYS within a few minutes of your next visitor.<\/li>\n<li>If you previously pasted the tracking script tag into your theme by hand, remove it. The plugin adds its own, and two copies double count every pageview. The settings page warns you if it finds a leftover one.<\/li>\n<li>Optional: paste the order sync key from MyVitalAssistant to send WooCommerce sales across.<\/li>\n<\/ol>\n\n<!--section=faq-->\n<dl>\n<dt id=\"do%20i%20need%20a%20myvitalassistant%20account%3F\"><h3>Do I need a MyVitalAssistant account?<\/h3><\/dt>\n<dd><p>Yes. The plugin is a connector for the service and does nothing until you connect an account. It stays inert if you activate it without one.<\/p><\/dd>\n<dt id=\"what%20data%20leaves%20my%20site%3F\"><h3>What data leaves my site?<\/h3><\/dt>\n<dd><p>See the External services section above for the complete list. In short: visitor tracking beacons, form submissions with their attribution, an optional WooCommerce order feed you switch on deliberately, and a daily heartbeat that reports your versions and, on a store, which commerce plugins are active. Nothing else. Order meta beyond an explicit allow list never leaves your server, and the tracking path forwards only its own attribution cookie, never the rest of your visitors' cookies.<\/p><\/dd>\n<dt id=\"does%20it%20slow%20my%20site%20down%3F\"><h3>Does it slow my site down?<\/h3><\/dt>\n<dd><p>No. The tracking script loads async. Form captures are sent without blocking, with a two second ceiling, and every capture hook is wrapped so a failure can never break a visitor's form submission. Order sends are the one blocking call, capped at three seconds, because a lost sale matters more than a fast redirect.<\/p><\/dd>\n<dt id=\"what%20about%20gdpr%20and%20visitor%20consent%3F\"><h3>What about GDPR and visitor consent?<\/h3><\/dt>\n<dd><p>The plugin tracks visitors on behalf of your business, so the same obligations apply as with any analytics or attribution tool: disclose it in your privacy policy and gather whatever consent your jurisdiction requires. The visitor id is anonymous and the attribution cookie contains no personal information; form submissions carry the personal data your visitor typed, which is sent to your own MyVitalAssistant account.<\/p><\/dd>\n<dt id=\"what%20happens%20when%20i%20deactivate%20or%20uninstall%3F\"><h3>What happens when I deactivate or uninstall?<\/h3><\/dt>\n<dd><p>Deactivating stops everything immediately: no script tag, no proxy, no captures, no daily ping. Uninstalling also deletes the plugin's stored settings and its capture log. Nothing else was ever stored on your site.<\/p><\/dd>\n<dt id=\"can%20i%20use%20it%20without%20woocommerce%3F\"><h3>Can I use it without WooCommerce?<\/h3><\/dt>\n<dd><p>Yes. Order sync is a separate opt in and everything else works without WooCommerce installed.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>1.5.4<\/h4>\n\n<ul>\n<li>The daily heartbeat sends its commerce plugin list only on sites actually running WooCommerce. It used to send it everywhere, including sites with no shop at all, where the warning it feeds could never apply. The External services section now describes exactly what the heartbeat carries.<\/li>\n<li>The tracking path now forwards only its own attribution cookie to the collector. It used to forward the whole cookie header, which on a signed in session included the WordPress login cookie, and nothing on the receiving side ever used it. Attribution is unchanged: the one value it depends on still crosses exactly as before.<\/li>\n<li>Cookies coming back from the collector are checked by name before they are set, because they are written under your own domain rather than ours.<\/li>\n<li>Proxied responses always carry a nosniff header, so a mislabelled body cannot be treated as script running with your site's authority.<\/li>\n<\/ul>\n\n<h4>1.5.3<\/h4>\n\n<ul>\n<li>The Form leads switch names Keap's Opt-in Forms among what it controls. It always did control them, and the description listed the other seven, so turning it off did more than it said.<\/li>\n<\/ul>\n\n<h4>1.5.2<\/h4>\n\n<ul>\n<li>The Keap Opt-in Forms listener now verifies the request's nonce before it reads anything, using the same check and the same action string that plugin's own handler runs as its first statement. This plugin accepts exactly the set of requests Keap accepts and never one Keap would reject.<\/li>\n<li>That listener is only registered when the Keap Opt-in Forms plugin is actually installed. On every other site the endpoint does not exist at all.<\/li>\n<li>Leads from Keap opt-in forms carry the person's name again. The payload sends the Keap application's name ahead of the contact's, and the older code took the first one it saw.<\/li>\n<li>Formidable Forms submissions are read through Formidable's own entry API instead of the raw request. No superglobal is touched, and the values arrive keyed by the field's real name, so the name and phone number recorded alongside a Formidable capture are the submitted ones rather than blank.<\/li>\n<\/ul>\n\n<h4>1.5.1<\/h4>\n\n<ul>\n<li>A failed order send now retries once, two minutes later. The collector stores orders under one key per order, so a retry can never duplicate a sale.<\/li>\n<li>Deactivating the plugin clears any pending retry.<\/li>\n<\/ul>\n\n<h4>1.5.0<\/h4>\n\n<ul>\n<li>Review round from the wordpress.org plugins team, applied in full. Every function, option, hook, and constant now carries the myvita prefix; live sites migrate their stored settings automatically and clean both prefixes on uninstall.<\/li>\n<li>The Keap Opt-in Forms listener refuses crafted requests: it captures nothing unless the Keap plugin's own handler is registered behind it, holds a burst cap so admin-ajax floods cannot pollute the capture log, and accepts only scalar form values.<\/li>\n<li>The Update URI header is gone, per directory policy for hosted plugins.<\/li>\n<\/ul>\n\n<h4>1.4.0<\/h4>\n\n<ul>\n<li>Settings panel for what this plugin sends: visitor tracking, form leads, and WooCommerce order sync each get their own switch.<\/li>\n<li>The daily heartbeat reports the store environment (WooCommerce version, currency, commerce extensions by name and version only) so the dashboard can warn when an extension changes what order data means.<\/li>\n<\/ul>\n\n<h4>1.3.2<\/h4>\n\n<ul>\n<li>The enqueued script carries the plugin version, so Plugin Check runs completely clean.<\/li>\n<\/ul>\n\n<h4>1.3.1<\/h4>\n\n<ul>\n<li>Plugin Check pass. The tracking script is enqueued through the script strategy API with async, superglobal reads are unslashed, and the form listener hooks document why another plugin's nonce is not ours to verify.<\/li>\n<li>Now requires WordPress 6.3, where the script strategy API arrived.<\/li>\n<\/ul>\n\n<h4>1.3.0<\/h4>\n\n<ul>\n<li>First release in the WordPress.org directory. Earlier versions were distributed directly by MyVitalAssistant.<\/li>\n<li>First party tracking path with full cookie lifetime in Safari.<\/li>\n<li>Form capture for Contact Form 7, WPForms, Gravity Forms, Fluent Forms, Ninja Forms, Formidable, Elementor Pro, and Keap Opt-in Forms.<\/li>\n<li>Optional WooCommerce order sync with an allow listed payload.<\/li>\n<li>Daily heartbeat and stray tag detection.<\/li>\n<\/ul>","raw_excerpt":"First party ad attribution for MyVitalAssistant accounts. Keeps visitor attribution alive in Safari and carries it into your CRM with your leads.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/en-nz.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/353110","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/en-nz.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/en-nz.wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/en-nz.wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=353110"}],"author":[{"embeddable":true,"href":"https:\/\/en-nz.wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/vitalconsulting"}],"wp:attachment":[{"href":"https:\/\/en-nz.wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=353110"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/en-nz.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=353110"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/en-nz.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=353110"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/en-nz.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=353110"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/en-nz.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=353110"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/en-nz.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=353110"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}