WordPress Cloaking: How to Set Up Traffic Filtering With a Plugin

WordPress is the most common engine for white pages, pre-landers and content landing pages. A WordPress cloaking plugin installs from the admin panel without touching theme files, but this engine has its own traps, caching above all.

Setup and Configuration10 min read
WordPress Cloaking: How to Set Up Traffic Filtering With a Plugin
Contents
  1. Why a separate plugin when there is a JS tag and a PHP file
  2. Before you install: what to prepare
  3. Installing the cloaking plugin on WordPress
  4. Caching is the cloaker's worst enemy on WordPress
  5. Security plugins and hosting: when the check gets a 403
  6. If the plugin is not available: the JS tag in the theme template
  7. How to test a cloaker on WordPress
  8. WordPress as a White Page and as a landing page
  9. A landing page inside a large site
  10. WordPress, theme and plugin updates
  11. Common mistakes when connecting a cloaker to WordPress
  12. In short

People choose WordPress for speed: a theme, a couple of plugins, and within an hour you have a white page, a pre-lander or a full landing page. A WordPress cloaking plugin is just as simple: instead of editing files by hand, you install the plugin, enter a key and choose a flow. But WordPress is also where you most often hear “everything is set up and bots still see the offer”, and the culprit is almost never the filter. It is the cache. Let us go through installation, configuration and testing in order.

Why a separate plugin when there is a JS tag and a PHP file

ArtisanClo has two basic connection methods: a JS tag as the first line in <head>, and a PHP file that meets the visitor on the server. Both are described in detail in how to connect a cloaker to your site.

On WordPress both are awkward:

  • The PHP file assumes the file goes into the site root as index.php and the landing page gets renamed. In WordPress, index.php is the engine core and must not be replaced.
  • The JS tag has to go strictly as the first line in <head>. Most “insert code into header” plugins output code through the standard hook, after the theme's styles and scripts, and that is already too late.

The plugin solves both problems: it runs inside WordPress and asks for a decision before the theme starts rendering the page. Your site stays on your hosting; ArtisanClo hosts nothing and does not take over your domain.

The WordPress plugin is available from the Professional plan. During the free trial, connect the site with the JS tag or the PHP file. Plan details are on the pricing page.

Before you install: what to prepare

  1. A flow in the dashboard. Create one under Flows → Create flow: mode, source, offer URL, White Page, countries and strictness. How to do it is covered in cloaker setup step by step.
  2. An account API key. It is issued from the menu under your avatar, in the API integration section. There is one key per account; the access level is chosen when you issue it.
  3. WordPress administrator access, so you can upload and activate plugins.
  4. A list of caching and security plugins on the site; you will need it during testing.

Installing the cloaking plugin on WordPress

  1. In the ArtisanClo dashboard, open Flows → the flow row → More → Connect and expand the WordPress method.
  2. Click Download the plugin; an archive will be saved.
  3. In the WordPress admin, go to Plugins → Add New → Upload Plugin, choose the archive and install it.
  4. Click Activate.
  5. Open Settings → ArtisanClo.
  6. Paste the API key and choose the flow this site belongs to.
  7. Save the settings.
  8. If the site has a caching plugin, clear the cache.

That is it. From now on every visit to the page is checked against the chosen flow's rules: a real person sees the offer, while a bot, a scanner or a spy tool sees the White Page.

Caching is the cloaker's worst enemy on WordPress

Page caching speeds up a site precisely by not running PHP for repeat visitors: the server returns pre-saved HTML. For a cloaker that is a disaster. If the first visit was a real person, the page with the offer gets saved, and every visitor after that receives it, bots and spy tools included. If a bot came first, buyers will see the White Page too.

Symptoms that point to caching:

  • everyone sees the page, even bots;
  • the click log shows fewer visits than the ad platform shows clicks;
  • decisions do not change right after you edit the flow.

Where to look for the cache

Layer Examples What to do
Caching plugin Page cache and optimization plugins Exclude the landing page URL from caching
Host-level cache Built-in server cache at many hosts Turn it off for the site or exclude the page via the panel or support
CDN HTML caching on the CDN side Do not cache the landing page HTML
Object cache Redis, Memcached for WordPress Usually harmless: it caches data, not finished pages

After any change, clear the cache at every layer and test the link in a new incognito window.

Tip. Script optimizers that combine and defer JavaScript can also get in the way, especially if you added the JS tag by hand. Exclude the cloaker code from combining and deferred loading, or switch to the plugin.

Security plugins and hosting: when the check gets a 403

Security plugins and host-level firewalls (WAF, ModSecurity) sometimes mistake the check page's service requests for an attack and respond with 403. From the outside it looks like this: some visits reach neither the offer nor the White Page, and odd rejections show up in the log.

What to do:

  • add the landing page URL to the security plugin's exceptions;
  • if the filter is on the hosting side, ask support to disable it for this site;
  • check that the host does not block outgoing HTTPS requests from the server: the plugin, like the PHP file, needs to reach the service. That is how any cloud cloaker works.

If the plugin is not available: the JS tag in the theme template

If your plan does not include the plugin, or you prefer the manual route, add the JS tag straight into the template:

  1. Copy the code from the Connect window.
  2. Open the theme's header file (usually header.php; work in a child theme so an update does not wipe your edit).
  3. Paste the code right after <head>, before any <link>, <script> and the standard header hook call.
  4. Save, clear the cache and click Check my page.

Do not add the tag through Google Tag Manager and do not add async or defer: the script would run later, and the page would render for everyone before the decision.

The JS tag has limitations: it cannot change the server response code, and Tracker mode and shadow mode do not apply to it. On the tag the flow filters like a regular cloaker.

How to test a cloaker on WordPress

  1. In the dashboard, click Check my page. The check either finds the connection on your page, reports that the page opened but this connection method did not answer, or says it could not open your page. The last one does not always mean something is broken: some hosts block automated checks.
  2. Open the ad link in incognito.
  3. Find the visit in the Click log; it will show the decision and the reason.
  4. To see the offer yourself, add your address to the IP whitelist in step 4 of the flow (Add my IP).

If every visit in the log comes from the same IP, that is your host's proxy address, not your visitors. Ask the host to pass the real address (real IP / mod_remoteip). Without it, the filter will be judging your server, not people.

The full troubleshooting routine is in cloaker not working: how to check, and the reasons in the log are explained in why a click went to the White Page.

WordPress as a White Page and as a landing page

WordPress is often used to build not just the offer landing page but the white page too. A few practical notes:

  • You do not have to host the White Page on your own WordPress. In the flow you can pick a ready-made page from the ArtisanClo catalog under Or let us show ours — no address, and it opens at your ad URL.
  • A White Page is a real page too: real sections, contacts, a privacy policy. Sometimes a real person gets filtered, for example one on a VPN, and to them a stock theme with “Hello world” and empty categories looks like a broken site.
  • The offer landing page must follow the platform's rules. Claims, disclaimers, a privacy policy and contacts on the page people see are the platform's own requirements, not a formality. See Meta advertising policies and Google Ads policies.
  • Watch your domain: WordPress sites left without updates for a long time sometimes end up on unsafe-site lists. ArtisanClo checks the domains of active flows and notifies you if browsers have flagged a domain.

A landing page inside a large site

Often a WordPress site is not a one-pager but a blog or a store with dozens of pages, and only one of them is used for ads. A few rules that spare you surprises:

  • Dedicate a separate page to the ads. No menu, sidebar or links to the rest of the site: the buyer is not distracted from the offer, and the flow's statistics only cover ad traffic.
  • Exclude that page from caching. The rest of the site can be cached as usual; it does not need the cloaker's decision.
  • One flow, one campaign. If one site runs campaigns on different platforms or geos, it is easier to keep separate pages and separate flows for them, so decision reasons and reports relate to a single ad.
  • Check the URL in the ad. The ad must point to the exact page the flow is connected to, not the homepage.

WordPress, theme and plugin updates

WordPress updates often, and every update is a potential breaking point:

What was updated What can break What to check
Theme A JS tag added by hand to the header template The code is still there and first in <head>
Caching plugin Exclusions get reset The landing page is still not cached
Security plugin New blocking rules No 403 responses for the check
WordPress core Usually nothing A routine connection check

After any update, click Check my page and open the ad link in incognito. It takes a minute and saves you from a week of bots reaching the offer and eating the budget because the theme overwrote the template.

Tip. If you edit the header template by hand, work in a child theme: your code will not disappear when the parent theme updates.

Common mistakes when connecting a cloaker to WordPress

  • Not clearing the cache after installation: the most common reason for “it does not work”.
  • Adding the JS tag through a header plugin: the code is output too late.
  • Choosing the wrong flow in the plugin settings: visits go to another flow, and your dashboard edits “have no effect”.
  • Forgetting about the security plugin: some checks get a 403.
  • Leaving the flow paused or as a draft: in that state every visitor sees the White Page, and the log shows the reason “Flow is not running”.

In short

A WordPress cloaker connects through a plugin: download it from the Connect window, upload and activate it, then paste the API key and choose a flow in Settings → ArtisanClo. Clear the cache right after; on WordPress that is a required step, not a formality. If the plugin is not available to you, put the JS tag as the first line of the header template. Check the result in incognito and in the click log, and see everything the service can do on the features page.

Frequently asked questions

01

Is there a cloaking plugin for WordPress?

Yes, ArtisanClo has a WordPress plugin. You download it from the flow's connection window, install it through the Plugins section and link it to your account with an API key. The plugin is available from the Professional plan.

02

Can I connect a cloaker to WordPress without a plugin?

Yes, with the JS tag: the snippet goes as the first line right after the opening head tag in the theme template. Inserting it through header plugins or tag managers will not work, because they output the code later and the page renders before the decision.

03

Why do bots still see the offer after I installed the plugin?

Most often the page is served from cache: a caching plugin, host-level cache or CDN returns a saved copy without asking for a decision. Exclude the landing page from caching, clear the cache and test the link in an incognito window.

04

Can I put the cloaker on just one page of a WordPress site?

Yes. The flow decides what to show for the page whose URL is in the ad. For a landing page inside a large site, it is easier to keep a separate page without a menu or extra links and exclude that specific page from caching.

05

Do I need to reinstall the plugin after changing flow settings?

No. Flow settings live in the dashboard and apply from the next visit. In the plugin you only choose which flow the site is linked to.

Read next

See your traffic for real

Connect ArtisanClo to your site, see who actually arrives from your ads, and why every click got its decision.