{
  "slug": "bw-lead-ai",
  "name": "BW Lead Attribution Intelligence",
  "version": "1.10.3",
  "download_url": "https://plugins.bowden.works/wp-content/uploads/plugin-updates/bw-lead-ai-1.10.3.zip",
  "download_hash": "sha256:39cfd36532be58aa41daec76951980d983ddb3420aaf750446b724bed46c35bb",
  "download_size": 537038,
  "requires": "6.0",
  "tested": "",
  "requires_php": "7.4",
  "last_updated": "2026-08-14",
  "homepage": "https://plugins.bowden.works/bw-lead-ai/",
  "author": "Bowden Works",
  "description": "Capture traffic source, attribute it to every lead, and understand where your leads are coming from.",
  "changelog": "## [1.10.3] - 2026-08-14\n\n### Security\n- **The enquirer's details no longer travel in a URL.** The generated\n  cross-domain tag reported a submission by putting the person's name, email\n  address and phone number in the confirm URL's query string. It worked — and it\n  wrote all three, in plaintext, into the web server access log of every host the\n  request passed through, on every submission. Those logs are rotated, backed up\n  and shipped around by tooling that has no idea it is carrying personal data,\n  and the exposure outlives the decision because nobody remembers the logs\n  contain it.\n\n  It could not be fixed on the receiving end: an access-log line is written\n  before any of that server's code runs. The tag now sends the details in the\n  request body instead. The URL carries the opaque token, which is what it was\n  designed to carry.\n\n  **Regenerate and re-paste the tag on the destination site to pick this up.**\n  A tag already installed keeps working exactly as before — including sending\n  details in the query string — until it is replaced. Nothing breaks if you\n  wait; nothing improves either.\n\n  Also fixed in the same place: on a browser without `sendBeacon`, the fallback\n  now carries the details too. It would otherwise have recorded the enquiry with\n  no name on it, silently, on exactly the browsers nobody tests."
}
