How to Install a Cloaker on Your Site: JS Tag or PHP File, Step by Step

Installing a cloaker takes a few minutes, yet this is the step where money is lost most often: the code sits in the wrong place, the cache serves an old page, the host blocks requests. Here are both installation methods and how to verify them.

Setup and Configuration11 min read
How to Install a Cloaker on Your Site: JS Tag or PHP File, Step by Step
Contents
  1. Where your site lives when you install a cloaker
  2. Two installation methods compared
  3. JS cloaker: installing with a tag
  4. PHP cloaker: installing a file on the server
  5. WordPress: a plugin instead of manual installation
  6. How to check that the cloaker is installed
  7. Cloaker installation mistakes
  8. Installation and landing page speed
  9. Which method to choose for your case
  10. The bottom line

A cloaker only works when it stands in front of your page: a visitor arrives from an ad link, the filter checks the visit and decides what to show, the offer or the White Page. Until the code is installed, none of your flow settings apply, so bots, scanners and spy tools see exactly what a buyer sees, and you pay for their clicks. That is why installing the cloaker is the first technical step after you create a flow, and it deserves some care. If you have not chosen a service yet, start with the article on what to check before you buy a cloaker.

Where your site lives when you install a cloaker

A common beginner misconception is that a filtering service takes your landing page onto its own servers and some third-party address goes into the ads. Not in ArtisanClo. Your site stays with you: your hosting, your domain, your files. A small piece of code or a file is added to the page, and everything else (checking the visit, scoring trust, choosing where to send it) happens on the service side. How this cloud setup differs from a self-written script is covered in cloud cloaker vs cloaking script.

Two practical consequences follow:

  • the ad account gets your site's address, not a link to someone else's domain;
  • you are responsible for landing page uptime, the SSL certificate and hosting speed; a filter will not fix a slow server.

If you are new to the topic, first read what cloaking is and the path a click takes. It makes it clearer why the code has to fire before anything else on the page.

Two installation methods compared

The connection window opens from the flow menu: Flows → flow row → More → Connect. The methods are listed as collapsed cards, and one is expanded at a time. One method per flow is enough. A working method is marked in green with an Installed badge.

JS tag PHP file
Where it runs In the visitor's browser On your server, before the page is served
What you need Access to the page <head> Hosting with PHP 7.2 or newer
Depends on blockers and load order Yes No
Tracker mode and Shadow mode Filters like a regular cloaker Supported
White Page as a status code (403/404) Cannot change the status code Supported
Updates Not needed The file does not update itself, you need the fresh version

In short: the tag is faster to install, the file is more reliable. The filtering settings are the same either way: they live in the flow, not in the code on your site, and you can switch the connection method without touching the flow.

JS cloaker: installing with a tag

The JS tag is a single line of script that you paste into the landing page markup. Until the decision arrives, the tag hides the page, and if there is no decision, it sends the visitor to the White Page.

Installing the JS tag step by step

  1. In the Connect window, expand the JS tag method and copy the code.
  2. Paste it as the first line of <head> on every landing page, not just the home page.
  3. Save the file or publish the page, then reload it in the browser.
  4. Click Check my page: the dashboard opens the page itself and looks for the code.

What not to do with the tag

  • Do not add the code through Google Tag Manager or any other tag manager. They run scripts later, and the page is shown to everyone, bots and spy tools included, before the decision.
  • Do not add async or defer, for the same reason.
  • Do not place the code below other scripts: analytics, pixels and widgets must come after it.

Tip. If the tag script fails to load (say, a network or a server-side blocker cuts it), the page will not be hidden, and bots and spy tools will see the offer. So click Check my page again after every change to your site.

Tag limitations

The tag runs in the browser, which means it cannot change the server's status code. If the White Page is set to Status code (200/403/404), a JS tag will leave a blank page in place of the landing. Tracker mode and Shadow mode do not work on the tag either: a flow with a tag filters traffic like a regular cloaker.

PHP cloaker: installing a file on the server

The PHP file is the method for sites hosted with PHP. The decision is made on the server before the browser receives a single byte of the page, so it does not depend on ad blockers or how fast scripts load.

Installing the PHP file step by step

  1. In the Connect window, click Download file.
  2. Put the file in the landing root as index.php.
  3. Rename your own landing page, for example to offer.php.
  4. In the flow's offer card, enter the new landing address, for example:
https://your-site.com/offer.php
  1. Click Check my page: the dashboard verifies that the file responds.

The result looks like this: the ad points to your-site.com, where index.php meets the visitor, asks for a decision and shows either offer.php or the White Page.

Updating the PHP file

The file on your server does not update itself. When a new version is released, the connection window shows a You're running an older file banner listing what your current version cannot do. Download the file again and replace the old one. The fresh version is needed, for example, for a ready-made White Page from the catalog, Offer link parameters rules and the live interaction check.

At the same time, you do not need to re-upload the file after changing flow settings: settings are not stored in the file; they live in the dashboard and apply from the next visit.

What your hosting needs

  • PHP 7.2 or newer;
  • outgoing HTTPS requests allowed (the file has to reach the service);
  • the curl extension or allow_url_fopen enabled.

The file waits up to 4 seconds for an answer. If there is no connection, for a day it serves visits based on the last answer: visitors with an ad click ID go to the offer, everyone else to the White Page. A visit that arrives before the very first answer gets a 503 error.

WordPress: a plugin instead of manual installation

If the landing page is built on WordPress, you can leave the files alone: the plugin installs from the admin panel and works the same server-side way. It is available from the Professional plan; on the trial, the site connects with the JS tag or the PHP file. Step-by-step installation, caching and typical mistakes are covered in a separate article, cloaker for WordPress.

If your traffic runs through a tracker, ArtisanClo plugs in there too; see Keitaro and a cloaker and Binom and a cloaker. The list of supported trackers is in the tracker integrations section.

How to check that the cloaker is installed

The Check my page button returns one of three answers:

Check result What it means
Setup found on your page All good
Your page opened, but this setup did not answer on it The code was not found or sits on a different page
Couldn't open your page The site or hosting did not let the check in; this does not necessarily mean the connection is broken

You can check once every 20 seconds. Note that a check resets the earlier Installed and Connected marks; they come back with the first visit. Under each method you see Works now or the date of the last activity.

Then do a live test:

  1. Open the flow's ad link in an incognito window.
  2. Go to the Click log: the visit should appear with a decision and a reason.
  3. If you want to see the offer yourself, add your address to the IP whitelist on step 4 of the flow (the Add my IP button).

Tip. A repeat visit from the same address and browser within a minute is merged with the previous click. If your test visit does not show up in the log, wait a minute or use another device.

If a visit in the log has the reason Before filtering, the flow has a warm-up enabled: the first clicks see the White Page without any checks, and the whitelist will not help here. How to read the reasons is covered in why a click went to the White Page.

Cloaker installation mistakes

Most "the cloaker isn't working" tickets come down to five situations.

Everyone sees the page, even bots

The culprit is almost always the cache: a caching plugin, host-level cache or CDN serves a saved copy of the page instead of asking for a decision for each visitor. Exclude the landing page from caching, clear the cache and test in incognito.

The page flashes before the decision

The tag was added through a tag manager, with async/defer, or is not on the first line. Move it to the very top of <head>.

All visits have the same IP

There is a hosting proxy in front of the site, and the PHP file sees the proxy's address instead of the visitor's. Ask your host to pass the real address (a real IP setting or mod_remoteip). Until that is fixed, the filter is evaluating your server, not people.

The hosting returns 403

The host's security filter (WAF, ModSecurity) mistakes requests from the check page for an attack. Add the landing address to the exceptions or ask hosting support to disable the filter for this site.

The PHP file returns 503 or the page loads slowly

The server cannot reach the service: outgoing connections are blocked or curl is missing. Check the PHP version and network permissions.

A full troubleshooting guide with the order of checks is in cloaker not working: how to check and fix it.

Installation and landing page speed

Any filter adds decision time to page loading, so buyers rightly ask whether they will lose conversions to speed. A few practical points:

  • The tag hides the page until the decision arrives. The earlier it loads, the shorter the pause, which is one more reason to put it on the first line.
  • The PHP file asks for the decision from the server. Here your hosting's connection to the outside world matters: cheap, overloaded hosting slows down both the landing and the check.
  • Min time on page and the live interaction check add waiting on purpose. Turn them on where the platform justifies the strictness, not everywhere by default.
  • A heavy landing page with big images and a dozen analytics scripts usually slows things down more than the filter. Optimizing the page itself often gains more than the choice of connection method.

Which method to choose for your case

  • A landing page on a site builder or someone else's hosting without PHP: the JS tag. The key is the first line of <head>.
  • Your own hosting with PHP: the PHP file. It does not depend on the browser and gives you more options: a status code instead of a White Page, Shadow mode, Tracker mode.
  • WordPress: the plugin, if your plan includes it; otherwise the PHP file.
  • A flow in Tracker mode: only the PHP file; the tag is not shown for it in the connection window.

For Google Ads, Facebook and TikTok the documentation recommends either method; for native networks, the PHP file. Ready-made settings for each platform are collected in the traffic source catalog, and the flow setup itself (filters, White Page, offers) is covered in cloaker setup step by step.

The bottom line

Installing a cloaker means either one line of JS tag at the top of <head>, or a PHP file acting as index.php with your landing renamed. Your site and domain stay with you. After installing, click Check my page, open the link in incognito and find the visit in the click log. When something goes wrong, the cause is most often the cache, a tag manager or a hosting proxy, and the click log usually tells you exactly where.

Frequently asked questions

01

Can I install a cloaker without access to my site's code?

You need at least access to the page head section or to the files on your hosting. WordPress sites have a plugin that installs from the admin panel without editing files. If you have neither, filtering cannot be attached to the page.

02

Do I have to move my site to the cloaker's server?

No. The landing page stays on your hosting and your domain, and your own address goes into the ads. Only a small piece of code or a file is added to the site, and the decision on each visit is made on the service side.

03

Can I add the JS tag through Google Tag Manager?

No. A tag manager runs the script later, so the page is shown to every visitor before the decision arrives. Paste the code directly as the first line of the head, without async or defer.

04

Which cloaker installation method is more reliable?

The PHP file decides on the server before the browser receives the page, so it does not depend on script blockers or load order. The JS tag is easier to install but has to load first. If your hosting supports PHP, the file is the usual choice.

05

Do I need to re-upload the PHP file after changing flow settings?

No. Flow settings live in the dashboard, not in the file, and apply from the next visit. You only need to download the file again when the connection window shows a message about a newer version.

Read next

11 min read

Cloaker Not Working: Troubleshooting by Symptom

When a cloaker is not working, the filter itself is almost never broken: the code is in the wrong place, a cache serves an old page, or the host hides visitor addresses. Here is a symptom-by-symptom check, from everyone sees the offer to clicks but no leads.

See your traffic for real

Connect ArtisanClo to your site, see who actually arrives from your ads, and why every click got its decision.