Cloudflare Security Tune-Up for WordPress
Budget: €8 – €30 EUR
My Elementor-built WordPress site is getting hammered by non-human hits that are spiking server load and dragging performance down. I already run everything through Cloudflare and I want to keep it that way—no extra plugins cluttering the stack—so every security and performance tweak must be done inside the Cloudflare dashboard.
The end goal is simple: let Google, Bing, and Yandex crawl freely while every other suspicious or outright malicious bot is filtered out or challenged, and do it in a way that lifts the strain on my server. Speed is important, but blocking the bad traffic is the priority.
You should have hands-on experience with Cloudflare WAF, Bot Fight Mode, custom Firewall and Rate-Limiting rules, and know how to test that legitimate search-engine bots remain untouched. If you can also squeeze a little more speed out of the cache and page-rule settings while you’re in there, even better.
Deliverables I need from you:
• A hardened Cloudflare configuration (WAF, firewall, rate limits, rules) that stops the current flood of bad requests
• Verification that Googlebot, Bingbot, and YandexBot still pass without issue
• A short handover note explaining what you changed, why, and how to adjust thresholds in the future
If that sounds like your bread and butter, let’s lock this down.
The end goal is simple: let Google, Bing, and Yandex crawl freely while every other suspicious or outright malicious bot is filtered out or challenged, and do it in a way that lifts the strain on my server. Speed is important, but blocking the bad traffic is the priority.
You should have hands-on experience with Cloudflare WAF, Bot Fight Mode, custom Firewall and Rate-Limiting rules, and know how to test that legitimate search-engine bots remain untouched. If you can also squeeze a little more speed out of the cache and page-rule settings while you’re in there, even better.
Deliverables I need from you:
• A hardened Cloudflare configuration (WAF, firewall, rate limits, rules) that stops the current flood of bad requests
• Verification that Googlebot, Bingbot, and YandexBot still pass without issue
• A short handover note explaining what you changed, why, and how to adjust thresholds in the future
If that sounds like your bread and butter, let’s lock this down.