App for Cloudflare®
Unlock advanced Cloudflare features without being a network administrator or developer. Works with any Cloudflare plan (including Free), no Automatic Platform Optimization (APO) subscription needed. Cache HTML at network edge Preload JavaScript and CSS View/set all Cloudflare settings Fixes Cloudflare Flexible SSL redirect loops Fixes situation when IPs are coming through as Cloudflare IPs rather than user IPs Cloudflare web analytics support Cloudflare analytics on dashboard Purge cache Automatic image transformations (automatically serve AVIF/WebP versions to browsers that support them) Turnstile CAPTCHA system for registrations, logins, password reset, comments and/or third party plugins View Page rules, Cache rules, Firewall rules, IP Address rules, User Agent rules View Zero Trust Network Access setup View DMARC statistics Included tools: HTTP request trace, IP address details, domain details, WHOIS Directly cache HTML App for Cloudflare® can automatically cache your HTML pages at Cloudflare data centers in 330+ cities. “Standard” WordPress caching plugins can’t escape the laws of physics because information can’t travel faster than the speed of light (even if the page is cached, the cache exists on your physical origin server, which can be over 20,000 km from an end user). Caching content in Cloudflare data centers makes your website faster by putting your website cache closer to end-users (95% of the world’s population is within 50ms of a Cloudflare data center). This can be done without Cloudflare Workers or even a Page Rule (done with a single Cache Rule on Cloudflare’s side, and custom code in the plugin). Preload JavaScript and CSS Speed your site up by using the option that instructs browsers to preload JavaScript and CSS used to render the page being viewed. Can be used on its own, or in conjunction with Cloudflare’s Early Hints function. Manage all Cloudflare settings All Cloudflare settings can be changed directly within your WordPress admin area. Includes Easy config function that will optimally set your Cloudflare zone settings for WordPress. Fixes Cloudflare Flexible SSL redirect loops Automatically fixes HTTPS redirect loops when using Cloudflare’s Flexible SSL option (traffic between user and Cloudflare is encrypted, but traffic between Cloudflare and origin server is not). Handles user IP addresses Automatically handles the situation where your web server is passing Cloudflare IP addresses rather than the IP address of the user making the request. Turnstile CAPTCHA Cloudflare Turnstile CAPTCHA support for registration, login, password reset, comment forms, WooCommerce, Contact Form 7, Elementor Pro, HTML Forms, MetForm and/or WPForms. Single-click setup (done transparently via API call). Network analytics View network stats for your website directly within your WordPress admin area with a dashboard widget. View rules & firewall Quickly review your site’s Cloudflare rules and firewall settings from within your WordPress admin area. Includes: Page rules Cache rules Firewall custom rules IP address rules User agent blocking DMARC management Track third parties that are sending email on your behalf (for example an email provider you have authorized like Gmail or Outlook). You can also see unauthorized email senders or spammers sending email on behalf of your domain. Multisite network support You can have a network-wide Cloudflare API token that can be overridden on a per site basis. In the case where a multisite network operator has the site domains in a single Cloudflare account, they can allow the site users to use Cloudflare features for their individual site without disclosing the underlying API token. Additionally, a single Pro license for the main network site allows the media from all sites in the network to be stored in the cloud, within a single Cloudflare R2 bucket. Image Transformations Supports Cloudflare’s Image Transformation service, which allows Media images to automatically be served in the best format that a browser supports (AVIF, WebP, etc). Additionally, smaller images can be automatically served to users on very slow network connections. No web server configuration required. Store media in the cloud [Premium] Easily and seamlessly store your WordPress media in the cloud with Cloudflare R2. This allows you to offload resources (both bandwidth and disk space) from your server. The first 10GB is free, and only costs $0.015 per GB thereafter (ex. if you had 100GB of media, it would cost $1.35 per month to store it in the cloud). Includes the ability to migrate existing media from local filesystem to R2 (or from R2 to local filesystem). Works with individual media, or all media in bulk (includes web-based migration as well as a shell/WP-CLI option). Automatically convert uploaded images to AVIF or WebP This is done with a free companion plugin, Image Shift (includes the ability to apply watermarks). Protect admin area [Premium] Utilize Zero Trust Network Access to authenticate users before they access your WordPress admin area. Manage rules & firewall [Premium] The premium version unlocks the ability to manage (create, delete, suspend and unsuspend) Cloudflare rules and firewall definitions. In addition to defining your own rules, you can deploy useful rules with a single click: Block traffic from certain countries (or Tor exit nodes widely used by spammers and hackers) Block AI scrapers & crawlers (block bots from scraping your content for AI applications like model training) Force a challenge before users can register (bot/spammer mitigation) Cache static content Automatically block the IP address(es) of spammers for a period of time Backup & restore [Premium] You can backup and restore some of your most important Cloudflare configuration settings: Zero Trust Access Policies Firewall Rules Firewall IP Access Rules Firewall User Agent Blocking Page Rules Cache Rules Backups can be restored to different zones (for example if you had extensive configuration for a zone, you could give another zone the same configuration through a backup restore). Other features API calls are done exclusively through API Tokens (with the minimum required permissions) and not a Global API Key. Global API Keys are an incredibly bad idea from a security standpoint. Ability to purge Cloudflare cache from WordPress admin (or via WP-CLI). Ability to copy Cloudflare zone settings from a different zone on the same Cloudflare account. Cached pages are automatically purged when a post/page is edited (just the necessary pages, not all pages). Stale content is not served to users. Ability to designate an individual admin user to manage settings (maybe you don’t want all admins to have the ability to change things in Cloudflare). Ability to use WordPress filters to add your own logic to things (for example, maybe you don’t want to cache a certain page or post for whatever reason). All JavaScript is native (no dependencies on jQuery or anything else). No third-party PHP libraries used (no dependencies on other libs).
Top keywords
- cloudflare36×3.24%
- rules19×1.71%
- cache13×1.17%
- network11×0.99%
- automatically9×0.81%
- firewall9×0.81%
- user9×0.81%
- wordpress9×0.81%
- ability8×0.72%
- ip8×0.72%
- media8×0.72%
- page8×0.72%
SpinupWP
This plugin ensures that the SpinupWP page cache is cleared when your site’s content changes. Not using SpinupWP yet? Sign up here. SpinupWP is a modern server control panel that’s here to help you implement best practices for every server you spin up. Designed for WordPress. This companion plugin should be installed on sites created using SpinupWP to allow the page cache to be cleared when your site’s content changes. Not using SpinupWP yet? Sign up here. Any Provider We support DigitalOcean, Linode, AWS, and any other provider. If your server has an IP address, you can connect SpinupWP. It does need to be a fresh install of Ubuntu though. Latest & Greatest Software SpinupWP will install the latest stable versions of Nginx, PHP, MySQL/MariaDB, and Redis from the standard apt-get repos. No who-knows-what-they-did custom builds of packages. Disconnect from SpinupWP in the future and you can still keep your packages up-to-date with apt-get upgrade. Automatic Security Updates SpinupWP will configure your server to install security updates as soon as they are available to reduce the likelihood of a software vulnerability putting your server at risk. Free SSL/TLS Certificates Serving your site over HTTPS is essential these days, not only for security, but to take advantage of the performance improvements of HTTP/2 as well. When you add a site to SpinupWP, a free Let’s Encrypt SSL/TLS certificate will be acquired, installed, and configured for your site. And SpinupWP will handle certificate renewals as well, so you hardly need to think about certificates. Cache All the Things One of the keys to a great performing WordPress site is caching. All sites are set up with Redis object caching to greatly reduce database requests. And with the check of a box you can enable full-page caching to serve pages lightning fast without even hitting PHP. Git Push-to-Deploy Developers! Developers! Developers! Add a git repository to your SpinupWP site and simply push to master to deploy your code. GitHub, Bitbucket, or a custom git repo will work. You can also configure a build script to run some tasks on the server after deployment is complete. Error Logs WordPress doesn’t enable error logging by default. Probably because the log is saved to a publicly accessible directory and can quickly balloon to take up a lot of hard drive space. SpinupWP enables error logs by default but stores them in a safe place and makes sure they’re rotated regularly like other server logs. Security Security Security Each server provisioned by SpinupWP is security-hardened from the word go. SSH login is disabled for the root user (you login with your user and use sudo instead). The firewall only allows connections to Nginx and SSH and failed attempts are monitored and blocked when the reach a threshold. Nginx is configured to defend against XSS, clickjacking, MIME sniffing, and other attacks. Software security updates are installed automatically. Scheduled Posts Published on Schedule For every site you add via SpinupWP, a server-side cron job will be configured to make sure that your WordPress site’s cron is executed every minute, as it should be. WP-CLI Preloaded If you love WP-CLI (we do! ❤) you’ll be very pleased to find it available on the command line the first time you login to your server. Security Isolation for Sites For each site that you add to your server via SpinupWP, a new system user is created for that site. All site files are owned by the site user and a PHP-FPM pool is configured to run as that user as well. Each site only has access to its files and so if only one site has a security vulnerability and gets infected with malware for example, only the files for that one site can be infected. SFTP Access for Your Clients If you’re hosting a site for someone else, you can easily give them SFTP/SSH access to just that site. And because of the security isolation between sites, they will only have access to files for that site. Professional Guidance & Best Practices SpinupWP will actively point you in the right direction and offer suggestions for maintaining your server. And because it provides detailed feedback about the operations it runs on your server, you can learn what is happening with your server. New release of Ubuntu just came out, should I upgrade? We’ll add a notice to the app about that, why we don’t recommend upgrading your existing servers, and how you can spin up a new server with the new release of Ubuntu and migrate your sites to that server instead. Should I install Varnish to improve page caching performance? We’ve benchmarked Varnish and Nginx FastCGI Cache performed better. Varnish would add complexity too, so one less moving part is another reason. Much of the time SpinupWP will suggest things that you may not have even thought of. Email deliverability for example. SpinupWP will strongly encourage you to configure an email sending plugin for the best email deliverability. SpinupWP’s guidance is especially helpful for those new to managing a server, but can also help those who’ve been at it a while, providing transparency to our decisions. Scheduled Backups of Site Files & Database All server providers (DigitalOcean, Linode, etc) offer automated backups of your entire server for a fee. These services are great and we highly recommend having backups of your whole server. But what happens if some media or data was deleted by accident from your WordPress site? You’re not going to restore your entire server just to get that data back. That’s where site backups come in. Site backups are full backups of your site files (media, themes, and plugins) and database. They allow you to easily restore a single site or just some files or data from a single site. With SpinupWP’s site backups, you choose your preferred provider to stash your backups whether that’s Amazon S3, DigitalOcean Spaces, or Google Cloud Storage. You plug in your account details and SpinupWP will send your site backups there in an easy-to-see format. Teamwork Makes the Dream Work Create a new team account, invite a member of your team, and allow them to spin up their own servers. Or just only allow them to add sites, the permissions you give them is up to you. Features Page cache purging Persistent object caching Ensures debug.log files aren’t saved in a publicly-accessible location