BetterShield

Change your Cloudflare zone from BetterShield

4 min read

Raise your Cloudflare zone’s security level, carry sign-in lockouts to the edge and deploy the managed ruleset from BetterShield Ultra, each with a way back.

If your site is served through Cloudflare, BetterShield › Ultra › Cloudflare can make three changes to its zone. Each reads what is there first, so putting it back restores what was actually there. It is part of BetterShield Ultra and needs WordPress 7.0 or newer; on an older version, the tab says so.

Connect a token

Ultra keeps no Cloudflare key of its own and has no field for one. WordPress holds the token.

  1. Create an API token in your Cloudflare account.
  2. On Settings › Connectors, add it under Cloudflare. The tab links there with Add one on the Connectors screen while no token is set. Or define BETTERSHIELD_CLOUDFLARE_TOKEN as a constant in wp-config.php, or as an environment variable on the server; either takes precedence over the stored token.
  3. Open the Cloudflare tab. It says where the token comes from, checks it, finds the zone your site’s address belongs to, and shows Connected, on the zone followed by its name.

If Cloudflare refuses the token, or no zone matches the site’s address, the card quotes what Cloudflare said.

What this site may change

The three controls wait until a zone has been found.

ControlWhat it doesThe way back
Challenge every visitorRaise the level asks once more, then sets the zone to Cloudflare’s highest security level: every visitor, shoppers at checkout included, sees a short check before the page loads. The control then shows Raised from here.Put the level back sets the level the zone was on before.
Block a locked-out network at the edgeWith Carry sign-in lockouts out to the edge on, each sign-in lockout on this site is also applied at Cloudflare to that network, so its requests stop reaching the site.The rule comes off when the lockout ends. Remove this block takes one off early, and turning the switch off takes them all off.
Deploy the managed rulesetDeploy it asks once more, then adds Cloudflare’s managed ruleset to the zone’s firewall, running on every request after the rules already there. The control then shows Deployed from here.Put the rules back restores exactly what was there, including no rules at all.

Note: A raised level makes real people wait a few seconds. Use it while someone is working through your sign-in, and put it back after.

Lockouts at the edge

  • The network is the /24 or /64 that Protect › Login & Access already counts by, never a full address.
  • The rule Cloudflare applies is a challenge, a check a person can pass in a browser, not an outright refusal.
  • A network an administrator of this site has signed in from, and the network of the request making the change, are never sent to the edge. The lockout on the site still stands.
  • One rule covers a network, however many lockouts run inside it.
  • Rules are sent from the next dashboard page, WP-CLI run or hourly task, never while a visitor waits.
  • When Pause sign-in after repeated failures is off on Login & Access, there are no lockouts to carry: the switch shows Paused, and any rule still on the zone comes off at the next pass.

The card lists each network blocked from here, or says none is. If Cloudflare refused the last change, the card says so and quotes it.

Safe mode and the record

  • While safe mode is on, nothing new is sent to Cloudflare. Putting a change back still works.
  • Every change and every put-back is in the activity log as Network edge changed and Network edge change put back. A rule Cloudflare refused is logged too.
  • Deactivating Ultra puts back the changes it made to the zone, where it can.

Good to know

  • A change already running on the zone is not started twice, so a double click does not make two.
  • On multisite, when sites share one zone, each site’s lockout rules are its own, and one site never takes off another’s.
  • With Ask for my password before an action that removes a protection on (Settings › General), opening this tab and using its controls asks for your password.
  • What is sent to Cloudflare is listed on What BetterShield contacts.

Close the open doors today

Install the free plugin. The first audit runs when you activate it, and nothing changes until you choose a fix.

Requires WordPress 6.7 or newer and PHP 8.0 or newer.

Get BetterShield