[WordPress] 外掛分享: WAF Manager for Cloudflare

首頁外掛目錄 › WAF Manager for Cloudflare
WordPress 外掛 WAF Manager for Cloudflare 的封面圖片
全新外掛
安裝啟用
尚無評分
8 天前
最後更新
問題解決
WordPress 6.0+ PHP 8.0+ v1.0.22 上架:2026-07-23

內容簡介

WAF Manager for Cloudflare 是一款專為 WordPress 設計的外掛,讓使用者能夠輕鬆部署經過實戰測試的 Cloudflare WAF 規則,強化網站安全性,無需進入 Cloudflare 控制台。

【主要功能】
• 一鍵部署五項預設安全規則
• 自訂允許的機器人和 IP 列表
• 阻擋攻擊性爬蟲和敏感路徑
• 管理大型雲端供應商的挑戰
• 自訂 Cloudflare 規則語法表達式

外掛標籤

開發者團隊

⬇ 下載最新版 (v1.0.22) 或搜尋安裝

① 下載 ZIP → 後台「外掛 › 安裝外掛 › 上傳外掛」
② 後台搜尋「WAF Manager for Cloudflare」→ 直接安裝(推薦)
📦 歷史版本下載

原文外掛簡介

This is the WordPress.org edition, and it contains the WAF Rules Builder only.
The full version, WP WAF Manager, adds DNS management, zone analytics, zone controls and cache purge, IP access rules, security events, email routing, and multi-account support. It is available free on GitHub, or from wpwafmanager.com for automatic updates and priority support. The full version is fully compatible with this edition and runs on the same site.
WAF Manager for Cloudflare lets you deploy a set of battle-tested Cloudflare WAF (Web Application Firewall) rules to any of your Cloudflare zones in one click, right from your WordPress admin — no Cloudflare dashboard or Rules expression language required.
WAF Rules Builder
Deploy five pre-configured, battle-tested security rules to any Cloudflare zone in one click, based on the open-source wafrules.com ruleset:

Allow Good Bots — Whitelist Cloudflare verified bot categories (Googlebot, Bingbot, uptime monitors, payment processors) plus a custom IP allowlist, a custom user agent allowlist, and your own custom Cloudflare expressions
Block Aggressive Crawlers — Block SEO scrapers, exploit scanners (SQLMap, Nikto, Masscan, Nmap), and sensitive WordPress paths (xmlrpc.php, wp-config.php, install.php)
Block Web Hosts & TOR — Block traffic from cloud hosting ASNs (DigitalOcean, Vultr, Hetzner, OVH, Contabo, and more) and TOR exit nodes
Challenge Large Cloud Providers — Managed challenge for AWS EC2, Google Cloud, and Azure traffic
Challenge VPN & wp-login — Managed challenge for NordVPN, ExpressVPN, Surfshark, and other VPN providers plus the WordPress login page

Each rule is fully customizable with checkboxes — no need to write a single line of Cloudflare expression syntax. Additional builder features:

Live expression preview as you toggle options
Custom Allow Expressions — add your own Cloudflare rules language expressions to Rule 1 to always skip the WAF, for cases the built-in allowlists don’t cover (specific webhook paths, Cloudflare managed IP lists, request headers, and so on)
Deploy to any single Cloudflare zone, or select multiple zones to deploy to at once
Automatic Cloudflare Free plan compatibility (restricted phases are stripped and retried automatically)

Plugin Settings

Access control — minimum role picker (Administrator recommended)
User access allowlist — restrict the plugin to specific administrator accounts
Keep data on uninstall toggle (on by default)
Test Connection — verify your Cloudflare API credentials instantly

Requirements

WordPress 6.0 or later
PHP 8.0 or later
A Cloudflare account with at least one active zone
An API Token with: Zone → WAF → Edit and Zone → Zone → Read

External services
This plugin connects to the Cloudflare API to read your zones and to create, read, and deploy WAF rules on your behalf. This service is required for the plugin to function — without a Cloudflare account and API credentials, the plugin has nothing to manage.
Requests are sent to the Cloudflare API at https://api.cloudflare.com only from your WordPress admin, and only when you take an action that requires it: verifying credentials, testing the connection, listing your zones, listing existing rules, previewing rules, or deploying rules.
The data sent consists of the Cloudflare credentials you enter (an API Token, or an account email plus Global API Key), the zone IDs you select, and the WAF rule definitions you build in the plugin. No data about your site’s visitors and no personal data about your WordPress users is sent. The plugin does not send data to any other third-party service.
Cloudflare is a third-party service operated by Cloudflare, Inc. By using this plugin to connect to Cloudflare, you are subject to their terms and policies:

Terms of Service: https://www.cloudflare.com/terms/
Privacy Policy: https://www.cloudflare.com/privacypolicy/

Trademarks
This plugin is independent and is not affiliated with, endorsed by, or sponsored by Cloudflare, Inc. Cloudflare is a registered trademark of Cloudflare, Inc., referenced here only to describe what this plugin is compatible with. No endorsement or affiliation is implied.

延伸相關外掛

文章
Filter
Apply Filters
Mastodon