This article provides a practical Cloudflare baseline for WordPress websites.
Overview
WordPress sites are common targets for login attacks, plugin vulnerability scans, XML-RPC abuse, and unwanted bots. Cloudflare can reduce noise, but WordPress itself must still be updated and secured.
Recommended Steps
- Keep WordPress core, themes, and plugins updated.
- Use Full (strict) SSL/TLS and confirm WordPress site URLs use HTTPS.
- Add a Managed Challenge or stricter rule for
/wp-login.php. - Protect
/wp-adminwith Access, trusted IP restrictions, or challenge rules. - Consider restricting or rate limiting
xmlrpc.phpif the site does not need it. - Enable suitable Cloudflare Managed Rules for WordPress.
- Test admin login, checkout, forms, cron, and API integrations after applying rules.
Common Mistakes to Avoid
- Blocking
wp-adminin a way that also blocksadmin-ajax.phpfor public features. - Using a security plugin and Cloudflare rule that conflict with each other.
- Forgetting payment gateway callbacks or form submissions.
- Assuming Cloudflare replaces WordPress maintenance.