All Security Checks
Infrastructure CheckA05:2021

Cloudflare Security Scanner

Audit Cloudflare configuration, WAF settings, and CDN security features.

Cloudflare provides powerful security features, but they need proper configuration. Our scanner checks for WAF enablement, bot management, security headers through Cloudflare, SSL mode, and whether the origin server is properly protected behind Cloudflare.

What This Scanner Does

Detects Cloudflare presence, checks SSL mode (Flexible vs Full Strict), tests for origin IP exposure, verifies WAF and bot management configuration, and checks Cloudflare-specific security headers and page rules.

Why It Matters

Using Cloudflare in "Flexible" SSL mode creates a false sense of security — traffic between Cloudflare and your origin is unencrypted. An exposed origin IP lets attackers bypass Cloudflare entirely. Proper configuration is essential to benefit from Cloudflare's security features.

Common Findings

  • Cloudflare SSL set to Flexible (unencrypted to origin)
  • Origin server IP exposed through DNS history
  • WAF not enabled or using free rules only
  • Bot management not configured

OWASP Top 10 Coverage

A05:2021Security Misconfiguration

Run This Check on Your Site

Get a full security report with AI-powered fix suggestions in 30 seconds. No setup required.

Related Security Checks