Cloudflare Docs
Visit WAF on GitHub
Set theme to dark (⇧+D)

Cloudflare Web Application Firewall

Get automatic protection from vulnerabilities and the flexibility to create custom rules.
Available on all plans

​​ Features

​​ Custom rules

Create your own custom rules to protect your website and your APIs from malicious incoming traffic. Use advanced features like WAF attack score and uploaded content scanning in your custom rules.

​​ Rate limiting rules

Define rate limits for incoming requests matching an expression, and the action to take when those rate limits are reached.

​​ Managed rules

Enable the pre-configured managed rulesets to get immediate protection. These rulesets are regularly updated, offering advanced zero-day vulnerability protections, and you can adjust their behavior.

​​ Exposed credential checks

Monitor and block use of stolen/exposed credentials for account takeover.

​​ Security Events

Review mitigated requests (rule matches) using an intuitive interface. Tailor your security configurations based on the activity log.

​​ Security Analytics

Business and above

Displays information about all incoming HTTP requests, including those not affected by security measures.

​​ More resources