Platform Setup Guide
Follow the instructions below for your website platform. Each section covers two things: how to install the tracking snippet, and how to configure your Content Security Policy (CSP) if you have one.
WordPress
Script Setup
The easiest way is to use a free plugin that lets you paste code into your site's <head> without editing theme files.
- 1In your WordPress dashboard, go to Plugins → Add New Plugin.
- 2Search for WPCode (also listed as "Insert Headers and Footers"). Install and activate it.
- 3In the left menu, go to Code Snippets → Header & Footer.
- 4Paste your AdLeak Shield tracking snippet into the Header box.
- 5Click Save Changes.
Alternative: edit theme files directly
Go to Appearance → Theme File Editor → header.php. Paste the snippet directly before the closing </head> tag, then click Update File. Note: theme updates may overwrite this — a plugin is safer for long-term use.
Content Security Policy (CSP)
Most WordPress sites don't have a CSP configured — if you haven't deliberately set one up, you can skip this section. If you do have a CSP, add the following two directives.
The two values you need to allow:
Option A — via .htaccess (Apache)
Open the .htaccess file in the root of your WordPress installation and add:
Option B — via plugin
Install the free plugin HTTP Headers by JL Faucher. Under Settings → HTTP Headers → Security, find Content-Security-Policy and add the two values above to the script-src and connect-src fields.
Shopify
Script Setup
Shopify themes use a single master template file called theme.liquid. Adding the snippet there puts it on every page automatically.
- 1In your Shopify admin, go to Online Store → Themes.
- 2Next to your active theme, click the three dots (⋯) then Edit code.
- 3In the file list on the left, under Layout, click theme.liquid.
- 4Use Ctrl+F (or Cmd+F on Mac) to search for
</head>. - 5Paste your tracking snippet on the line directly above
</head>. - 6Click Save in the top right corner.
Content Security Policy (CSP)
No action required.
Shopify fully controls the HTTP headers for your storefront and does not allow merchants to set custom CSP headers. Shopify's default policy permits external scripts embedded in your theme to make fetch requests to third-party URLs, so the tracking snippet works without any changes on your end.
Wix
Script Setup
Wix provides a built-in Custom Code section in your site settings — no Velo or coding knowledge required.
- 1Log in to your Wix dashboard and select your site.
- 2In the left sidebar, go to Settings.
- 3Scroll down to the Advanced section and click Custom Code.
- 4Click + Add Custom Code in the top right.
- 5Paste your tracking snippet into the code box.
- 6Set Add Code to Pages to All Pages and set Place Code in to Head.
- 7Give it a name (e.g. AdLeak Shield) and click Apply.
- 8Publish your site for the change to take effect.
Content Security Policy (CSP)
No action required.
Wix manages all HTTP response headers on your behalf and does not provide access to CSP configuration. Custom code added through Wix's Custom Code section is permitted to make external requests by default, so the tracking snippet works without any changes.
Hand-coded / Custom
Script Setup
Paste the snippet into the <head> section of every page. If you use a shared template (PHP include, Jinja base template, Blade layout, etc.), add it once to that file and it will apply everywhere.
- 1Open your HTML file or shared header template in a text editor.
- 2Find the closing
</head>tag. - 3Paste your tracking snippet on the line directly above
</head>. - 4Save and deploy your changes.
Content Security Policy (CSP)
If you have a CSP configured, you need to allow the tracker script source and the data endpoint. Add these to your existing policy:
Add to script-src
https://adleakshield.comAdd to connect-src
https://adleak-functions-ajbraxdhf4hwgudf.westeurope-01.azurewebsites.netApache — .htaccess
Nginx — server block
Node.js / Express
Or use the helmet package: npm install helmet then configure contentSecurityPolicy in its options.
Meta tag (quick test only)
Privacy wording for your website
Most websites describe their analytics in their privacy policy. Here is wording you can use, covering exactly what AdLeak Shield collects and what happens to it. Edit the part in square brackets, and check it against the rest of your policy before publishing.
Add to your privacy policy:
Advertising performance measurement We use AdLeak Shield to measure what happens after someone clicks one of our Google Ads. It records which advert and search term brought you to our website, the pages you viewed, how long you stayed, how far you scrolled, the links and buttons you clicked, and whether you contacted us. AdLeak Shield does not use cookies and does not store anything on your device. To take these measurements, a script on our pages observes how you interact with them while you are here, including whether you are using a mobile, tablet or desktop-sized screen. To tell one visit apart from another, it uses your IP address and your browser's user-agent string — information your browser sends with every request it makes. These are combined into a one-way code using a secret that changes every day and is deleted after 48 hours, after which the code can no longer be linked back to you. Your full IP address is never stored: it is shortened first (for example 82.12.34.xxx), and used once to work out your approximate town and country. We rely on our legitimate interests in understanding and improving the effectiveness of our advertising. Records are deleted automatically after 90 days. AdLeak Shield acts as our data processor. It uses this information only to provide this measurement service to us, and for no purpose of its own. How to object If your browser sends a Global Privacy Control signal, your visit is not recorded at all. Some browsers let you turn this on in their privacy settings, and browser extensions are available that send it. You can also object at any time, or ask what we hold about you, by contacting us at [YOUR CONTACT EMAIL].
Version 21 September 2026. We will email you if this wording changes.
This is a description of what our software does, not legal advice. Whether your site needs a consent banner or anything else depends on your business, and is a question for you and your own advisers.