

Rule 1 (Allow Good Bots) — allowlist IP addresses and CIDR ranges, custom user agents, and your own Custom Allow Expressions in the Cloudflare rules language.
This is the WordPress.org edition, and it contains the WAF Rules Builder only.
The full version, WP WAF Manager, adds DNS management, zone analytics, zone controls and cache purge, IP access rules, security events, email routing, and multi-account support. It is available free on GitHub, or from wpwafmanager.com for automatic updates and priority support. The full version is fully compatible with this edition and runs on the same site.
WAF Manager for Cloudflare lets you deploy a set of battle-tested Cloudflare WAF (Web Application Firewall) rules to any of your Cloudflare zones in one click, right from your WordPress admin — no Cloudflare dashboard or Rules expression language required.
Deploy five pre-configured, battle-tested security rules to any Cloudflare zone in one click, based on the open-source wafrules.com ruleset:
Each rule is fully customizable with checkboxes — no need to write a single line of Cloudflare expression syntax. Additional builder features:
This plugin connects to the Cloudflare API to read your zones and to create, read, and deploy WAF rules on your behalf. This service is required for the plugin to function — without a Cloudflare account and API credentials, the plugin has nothing to manage.
Requests are sent to the Cloudflare API at https://api.cloudflare.com only from your WordPress admin, and only when you take an action that requires it: verifying credentials, testing the connection, listing your zones, listing existing rules, previewing rules, or deploying rules.
The data sent consists of the Cloudflare credentials you enter (an API Token, or an account email plus Global API Key), the zone IDs you select, and the WAF rule definitions you build in the plugin. No data about your site’s visitors and no personal data about your WordPress users is sent. The plugin does not send data to any other third-party service.
Cloudflare is a third-party service operated by Cloudflare, Inc. By using this plugin to connect to Cloudflare, you are subject to their terms and policies:
This plugin is independent and is not affiliated with, endorsed by, or sponsored by Cloudflare, Inc. Cloudflare is a registered trademark of Cloudflare, Inc., referenced here only to describe what this plugin is compatible with. No endorsement or affiliation is implied.