• We used Pretty Links for affiliate redirects across our websites for years. After concerns about IP logging, we inspected the code of Pretty Links 4.0.15 more closely.

    What surprised us was how much (!new!) tracking functionality is built into what we primarily used as a simple /go/ redirect system.

    In the version we reviewed, Pretty Links can store individual click records, including IP address, referrer, user agent, requested URI, visitor identifier, country and WordPress user ID, where applicable. Its default configuration has click tracking enabled, IP anonymisation disabled and no automatic trimming of old click records.

    We also found that Pretty Links sets tracking-related cookies, including a prli_visitor identifier with a one-year lifetime. Even the simpler click-counting mode contains code to set cookies so they are available if the tracking mode is changed later.

    The plugin also contains IP-based geolocation functionality. IP addresses can be queued for resolution and an external geolocation endpoint is present in the code.

    For us, this feels excessive for something we essentially need to do:

    Redirect a URL and increase a click counter by one.

    Even when you set things on ‘simple’ click count IP’s get logged.

    Now with 4 FTE we have to build replacement plugins, because you are not simply allowing us to remove all that tracking. Extremely unhappy with this.

Viewing 3 replies - 1 through 3 (of 3 total)
  • Plugin Author Caseproof LLC

    (@caseproof)

    Hi Jochem,

    Thanks for digging into the code. It’s fair to want to know exactly what a plugin does with visitor data. Some of the conclusions here aren’t accurate, though, so here’s what Pretty Links actually does.

    You can turn tracking off completely. Uncheck “Track” on a link and Pretty Links just redirects. No cookies are set and nothing about the visitor is stored. You can also make new links untracked by default in the settings. Doing that across your links gives you exactly “redirect a URL” with zero data collection, no custom plugin needed.

    Simple (count) mode doesn’t store IP addresses. It only adds one to the link’s click counter. The IP is checked in memory against your excluded-IP list and bot filter, then discarded. It’s never written to the database. Switching to Simple mode (after a confirmation prompt) also deletes all previously stored click records, IPs included. Simple mode does set a small per-link cookie so it can count unique clicks.

    Most of this isn’t new. Pretty Links 3.x saved the same per-click details (IP, referrer, user agent, URI, visitor ID) and set the same prli_visitor cookie for many years, with the same defaults. 4.0 does add three fields to the detailed click record (country, device type, and the WordPress user ID when the visitor is logged in). Most of what 4.0 added is on the privacy side:

    • an option to anonymize IP addresses before they’re stored
    • automatic trimming of old click records, with a retention window you choose
    • a one-click CookieYes integration that lists every Pretty Links cookie on your consent banner, with its purpose and lifetime

    On geolocation, you have a fair point. In 4.0.15, the default Normal tracking mode looks up each click’s country in the background, using our own geolocation service. We’ve already changed that for the next release: country lookups will only happen in Extended tracking mode, or for links that use Pro’s geo targeting. None of this happens in Simple mode or on untracked links.

    If you’d like a hand setting things up so Pretty Links only redirects, open a ticket and we’ll walk you through it. Since the plugin already does what you need, I’d ask you to reconsider the rating.

    Thread Starter Jochem

    (@jochemvroom)

    Thanks for the clarification. I rechecked the 4.0.15 code and you’re correct on one point: Simple/count mode does not persist the IP address in prli_clicks; the IP is only consulted in memory for exclusion/bot handling. I’ll correct that statement.

    However, I think your description of Simple mode’s cookies is incomplete. In 4.0.15, Simple mode also creates the one-year prli_visitor cookie. The code comment itself says that count mode does not use that value, but still sets the cookie so a later mode switch already has a visitor ID available.

    That remains difficult for us to justify. If we deliberately choose a minimal, count-only mode, we would expect the plugin to collect only what that mode actually needs. A per-link cookie for unique counting is understandable. A persistent one-year visitor identifier that Simple mode itself does not use is not.

    More broadly, this is also about operational trust. We run multiple GDPR-sensitive websites and cannot treat privacy settings as something that may materially change between plugin updates. If an update introduces new cookies, new stored fields, new external lookups, or changes the practical meaning of a tracking mode, that can affect our consent setup, privacy disclosures, retention policies and internal compliance procedures.

    For a plugin in this position, we would expect privacy-relevant behaviour to be:

    • explicit,
    • minimal by default,
    • backward-compatible where possible,
    • and clearly flagged before an update changes data collection or transmission.

    Website owners should not have to re-audit the source code after every update to establish whether a previously privacy-minimal configuration still behaves the same way.

    This is the main reason we are uncomfortable relying on configuration alone. For us, “Simple” should reliably mean aggregate click counting with the minimum data necessary, not a mode whose privacy characteristics can expand over time.

    Plugin Author cartpauj

    (@cartpauj)

    Hi Jochem,

    You’re right that Simple mode also sets the prli_visitor cookie. It’s done that since 3.x. Simple mode’s behavior hasn’t expanded over time: it sets the same visitor and per-link cookies it always has, and it still stores no IP addresses.

    The one real change in data collection was the background country lookup in Normal mode in 4.0. That was removed in 4.0.16, which ships today and will be listed in the changelog.

    If you need zero cookies and zero data collection, turn tracking off on your links. Then Pretty Links only redirects, and that’s been true in every version.

    We’ve answered the technical points in detail, so we’ll leave it here. If building your own solution is a better fit for your compliance process, we understand.

Viewing 3 replies - 1 through 3 (of 3 total)

You must be logged in to reply to this review.