Cloudflare WAF rules for WordPress

Deploy 5 curated firewall rule groups to your own Cloudflare account in one click. Hostile traffic is dropped at the edge, before it ever reaches your server.

Uses your own Cloudflare account and API token. Your zone stays yours.

5
rule groups, each individually toggleable
Edge
threats stop at Cloudflare, not at your PHP server
1 click
deploy, update or remove the rules from your dashboard
Free
the entire WAF module ships in the free plugin

What it does

A web application firewall at the edge filters requests before they consume your hosting resources. Instead of asking you to write Cloudflare rules by hand, the plugin ships five curated groups and deploys them to your zone through the Cloudflare API.

The five rule groups

Each group is a switch, and the important choices inside each group are switches too:

  • Allow good bots: Cloudflare-verified crawler categories plus named allowlists for backup, monitoring, image, SEO and security services you actually use
  • Block crawlers & WP paths: aggressive crawlers, exploit scanners (Nikto, sqlmap, masscan, nmap), sensitive WordPress paths like XML-RPC and wp-config, and common injection patterns
  • Block web hosts & TOR: traffic originating from hosting providers and TOR exit nodes, which is rarely human
  • Challenge cloud providers & countries: present a challenge instead of a hard block
  • Challenge VPN & login: extra friction exactly where attacks concentrate

How it works

Connect your Cloudflare API token, pick your groups, deploy. The plugin creates and updates its ruleset through Cloudflare's Rulesets API, can remove its rules just as cleanly, and gives you preview, live-rules and analytics views so you can see what the rules are actually doing.

Everything runs against your own Cloudflare account. The plugin never proxies your traffic and only talks to api.cloudflare.com with the token you provide.

Documentation

Cloudflare setup

Connect your account and token.

Read the guide →

Rule groups overview

What each group covers and when to use it.

Read the guide →

Preview & deploy

See rules before they go live.

Read the guide →

WAF analytics

What the rules blocked and challenged.

Read the guide →

Cloudflare WAF questions

Do I need a Cloudflare account?

Yes. The rules are deployed to your own Cloudflare zone with your own API token. The plugin manages the rules; Cloudflare enforces them.

Is this really free?

The whole WAF module (all five rule groups, deployment, preview and analytics) ships in the free plugin.

What if a rule blocks something I need?

Groups and their sub-options toggle individually, the allow-good-bots group has named allowlists for common services, and you can add your own IP and user-agent exceptions. Rules can be removed as cleanly as they were deployed.

Related features

Free

CAPTCHA

reCAPTCHA or Turnstile on your auth forms.

Learn more →
Free

Vulnerability scanner

Plugins, themes and core checked against WPScan and Patchstack.

Learn more →
Pro

Incident detection

Attack patterns detected and assembled into timelines.

Learn more →

All features →

Secure your site today

Install the free plugin from WordPress.org and set up real protection with the guided setup wizard. Upgrade to Pro whenever you need more.