Set Up Cloudflare CDN on WordPress

Cloudflare is the world's most popular CDN and security service — and it's free. Adding Cloudflare to WordPress delivers faster page loads, reduced bandwidth usage, DDoS protection, free SSL, and improved search rankings. This comprehensive guide walks you through the complete setup from scratch, including troubleshooting and WooCommerce optimization.

1. Understanding Cloudflare CDN: How It Works

A CDN (Content Delivery Network) is a global network of servers strategically located around the world. When a visitor opens your WordPress site, Cloudflare's intelligent routing system serves static files (images, CSS, JavaScript, fonts) from the server closest to that visitor instead of making every request travel all the way back to your origin hosting server.

Think of it like this: instead of all your visitors traveling to your office to pick up documents, Cloudflare sets up local branch offices in major cities worldwide. Visitors get documents from the nearest branch, not the main office. This dramatically speeds up delivery.

Key Benefits for WordPress

For most WordPress blogs and small e-commerce sites, these benefits can double or triple site performance without any coding changes.

2. Account Setup: Creating Your Cloudflare Account

Step-by-Step Registration

  1. Navigate to cloudflare.com and click "Sign up"
  2. Enter your email and create a strong password. Enable 2FA if you plan to store sensitive content
  3. Verify your email address through the confirmation link
  4. Click Add a Site on the dashboard
  5. Enter your domain name (e.g., yourblog.com) and click "Add site"
  6. Cloudflare automatically scans your existing DNS records — wait 1-2 minutes for completion
  7. Review the imported records carefully:
    • Your **A record** (pointing to your hosting) should be present
    • Any **MX records** for email should be listed
    • CNAME records for subdomains should be imported
  8. Select the Free plan (sufficient for most WordPress sites) or upgrade later if needed
  9. Note the 2 Cloudflare nameservers you'll need in the next step (format: `xxx.ns.cloudflare.com`)

At this point, your domain is not yet using Cloudflare — that happens when you change nameservers. Your site remains fully functional during this process.

3. Updating Nameservers at Your Domain Registrar

This is the critical step that points your domain to Cloudflare's servers. After this change, Cloudflare manages your DNS records and starts serving your site.

Step-by-Step Process

  1. Log into your domain registrar account (AsiaGB, GoDaddy, Namecheap, etc.)
  2. Navigate to **Nameserver Settings** or **DNS Management** for your domain
  3. Find the nameserver fields (usually 2-4 of them)
  4. Replace the existing nameservers completely with Cloudflare's:
    • 1st nameserver: `xxx.ns.cloudflare.com`
    • 2nd nameserver: `yyy.ns.cloudflare.com`
    (Copy these exactly — they're unique to your domain and account)
  5. Save the changes — the registrar saves them immediately, but propagation takes time
  6. Return to Cloudflare dashboard and click Done, check nameservers
  7. Cloudflare will verify the change (sometimes takes a few minutes)

Propagation Time Explained: Nameserver changes typically take 15 minutes to 24 hours globally, though 30-90 minutes is more common. During propagation, some users may still use the old nameservers. Your site stays live the entire time — there's no downtime. Check the propagation status at whatsmydns.net by entering your domain.

Common Issues During Nameserver Changes

If your domain stops resolving after changing nameservers, verify you haven't introduced typos. Double-check the exact nameserver names. Also confirm your registrar actually saved the changes — refresh the registrar dashboard to verify.

4. Configuring SSL Mode: The Security Foundation

SSL mode controls how Cloudflare communicates with your origin hosting server. Choosing the wrong mode can cause redirect loops or security warnings. This is one of the most important settings.

SSL ModeSecurity LevelBest ForRisk
FlexibleLowSites with NO SSL on hosting serverIf WP forces HTTPS, causes redirect loop
FullMediumSites with ANY SSL (even self-signed)Self-signed certs cause warnings
Full (Strict)HighestValid SSL from CA (recommended)None — this is the ideal mode

For AsiaGB Hosting: Since AsiaGB provides free Let's Encrypt SSL through DirectAdmin, set Cloudflare to Full (Strict) mode. This ensures maximum security with certificate verification.

How to Set SSL Mode

  1. Go to **SSL/TLS** in your Cloudflare dashboard
  2. Click **Overview** tab
  3. Change the dropdown from "Flexible" to "Full (Strict)"
  4. Wait 5 minutes for the change to propagate

Critical: Avoid Flexible Mode with WordPress HTTPS — If your WordPress site forces HTTPS (via .htaccess or plugin) but Cloudflare is set to Flexible, visitors will experience ERR_TOO_MANY_REDIRECTS. This happens because: (1) Cloudflare sends HTTP to your origin, (2) WordPress redirects to HTTPS, (3) Cloudflare receives HTTPS, strips it back to HTTP, (4) WordPress redirects again — infinite loop. Always use Full or Full (Strict) with WordPress.

5. Installing WordPress Plugins for Cloudflare Integration

While not strictly required, plugins help WordPress communicate correctly with Cloudflare by handling two important tasks: automatically purging cache when you update content, and ensuring WordPress logs show visitor IPs correctly instead of Cloudflare's IP.

Option 1: Official Cloudflare Plugin (Recommended)

  1. In WordPress, go to **Plugins → Add New**
  2. Search for "**Cloudflare**" (official plugin by Cloudflare, Inc.)
  3. Click **Install** then **Activate**
  4. Navigate to **Cloudflare settings** (usually under **Settings** menu)
  5. You'll be prompted to authenticate — log in with your Cloudflare account credentials
  6. Enable **Automatic Cache Purge** — this purges Cloudflare's cache whenever you publish/update a post
  7. Verify the plugin shows "Connected" status

This plugin automatically handles everything. When you update a post, it tells Cloudflare to purge that specific URL from cache, so visitors see your new content immediately.

Option 2: Manual IP Configuration (No Plugin Alternative)

If you prefer not to install plugins, add this code to your wp-config.php file (via FTP or File Manager) right after the database configuration lines:

// Trust Cloudflare real IP
if (isset($_SERVER['HTTP_CF_CONNECTING_IP'])) {
    $_SERVER['REMOTE_ADDR'] = $_SERVER['HTTP_CF_CONNECTING_IP'];
}

This tells WordPress to log the visitor's real IP address, not Cloudflare's proxy IP. Without this, comments and analytics show all visitors from Cloudflare's data centers instead of their actual locations.

However, you'll still need to manually purge Cloudflare cache when you update posts (see Step 7), so the plugin is usually better.

6. Setting Up Page Rules for WordPress

Page Rules let you customize how Cloudflare treats specific URLs. For WordPress, you need rules to prevent caching of dynamic content like the admin panel and login page.

URL PatternCloudflare SettingResult
yourdomain.com/wp-admin/*Cache Level: BypassAdmin panel always fresh, never cached
yourdomain.com/wp-login.phpCache Level: BypassLogin page always fresh, never cached
yourdomain.com/wp-json/*Cache Level: BypassAPI requests not cached (WP REST API)
yourdomain.com/*.phpCache Level: BypassAll dynamic PHP pages bypass cache
yourdomain.com/blog/*Cache Level: Cache EverythingBlog posts cached aggressively

How to Create Page Rules

  1. Go to **Rules** → **Page Rules** in Cloudflare dashboard
  2. Click **Create Page Rule**
  3. Enter the URL pattern (e.g., `yourdomain.com/wp-admin/*`)
  4. Select **Cache Level** and choose **Bypass**
  5. Click **Save and Deploy**
  6. Repeat for each URL pattern above

Special Rules for WooCommerce

If running a WooCommerce store, add these additional rules:

Without these rules, customers might see outdated cart totals or old product information, causing lost sales.

7. Advanced: Cache Rules for Fine-Grained Control

Page Rules are limited (free plan allows 3). Cache Rules offer more flexibility with advanced conditions. Use these for sophisticated caching strategies:

Recommended Cache Rules

  1. Skip cache for logged-in users
    • Condition: Cookie contains `wordpress_logged_in`
    • Action: Bypass Cache
    • Result: Users see personalized, always-fresh content
  2. Aggressive cache for images and assets
    • Condition: URL path matches `/wp-content/uploads/*` or `/wp-content/themes/*`
    • Action: Cache, set TTL to 30 days
    • Result: Images/CSS/JS stay cached for a month
  3. Cache homepage longer
    • Condition: URI path equals `/` or `/index.html`
    • Action: Cache, set TTL to 1 hour
    • Result: Homepage refreshes hourly but stays cached in between

8. Purging Cache After Updates

Every time you publish or update WordPress content, you need to purge Cloudflare's cache so visitors see the new version, not the old cached version.

Method 1: From Cloudflare Dashboard

  1. Go to **Caching** → **Configuration**
  2. Click **Purge Cache** button
  3. Choose **Purge Everything** to clear all cache
  4. Confirm — this takes effect within seconds

**Purge Everything** clears your entire cache, which is simple but may temporarily reduce performance as everything gets re-cached. More precise is "Purge by URL" (mention specific pages).

Method 2: Automatic via Plugin

If using the official Cloudflare plugin, it automatically purges when you:

This is why the plugin is recommended — you forget about purging and it just works.

Method 3: Advanced Plugins (WP Rocket, Autoptimize)

Premium caching plugins like **WP Rocket** and **LiteSpeed Cache** include built-in Cloudflare integration. They purge Cloudflare cache automatically AND optimize your site further (minify code, lazy load images, etc.). If using these, the Cloudflare plugin becomes optional.

9. Troubleshooting Common Cloudflare Issues

Issue: "ERR_TOO_MANY_REDIRECTS" After Setup

Cause: WordPress forces HTTPS, but Cloudflare SSL mode is set to Flexible.

Fix: Change SSL mode to "Full" or "Full (Strict)" in Cloudflare dashboard → SSL/TLS → Overview.

Issue: Homepage Works, But Admin Panel Returns Errors

Cause: WordPress or Cloudflare configuration mismatch. May be CORS (Cross-Origin Resource Sharing) issues.

Fix: Clear Cloudflare cache completely (Purge Everything). If persists, check that /wp-admin/* has Cache Level: Bypass in Page Rules.

Issue: Comments Submitted But Not Appearing

Cause: Comment spam checks failing, or cache serving old page version.

Fix: (1) Purge cache for the post. (2) Check spam folder. (3) In WP → Settings → Discussion, verify comment moderation settings.

Issue: Images or CSS Not Updating

Cause: Cloudflare cached old file. Browser also caches, adding another layer.

Fix: (1) Purge Cloudflare cache. (2) Hard-refresh browser (Ctrl+Shift+R on Windows/Linux, Cmd+Shift+R on Mac). (3) Clear browser cache manually.

Issue: Mobile Site Looks Different After Cloudflare

Cause: Cloudflare may be serving cached desktop version to mobile.

Fix: Create a Cache Rule: if URL contains "mobile" or User-Agent contains "Mobile", set Cache Level to "Bypass". WordPress responsive themes usually work fine, but check.

10. Monitoring Performance & Optimization Tips

Check Caching Effectiveness

  1. Go to **Analytics & Logs** → **Caching** in Cloudflare dashboard
  2. View cache hit ratio (should be 50%+ for a blog, 70%+ is excellent)
  3. If low, review your Cache Rules — too many bypasses reduce effectiveness

Monitor Page Performance

Cloudflare should improve metrics within days. If not, check if CSS/JS are being minified (via plugin) and images are optimized.

Advanced: Enable Brotli Compression

  1. Go to **Speed** → **Optimization** in Cloudflare
  2. Enable **Brotli** (modern, more efficient compression than gzip)
  3. Enable **Minify CSS/JavaScript/HTML** (optional but recommended)
  4. Enable **Early Hints** (if compatible with your hosting)

11. Special Considerations for WordPress Multisite

If running WordPress Multisite with multiple subdomains (e.g., site1.yourdomain.com, site2.yourdomain.com):

Cloudflare handles wildcard subdomains elegantly, so Multisite setup is straightforward.

12. Comparing Plans: Free vs Pro vs Business

FeatureFreePro ($20/mo)Business ($200/mo)
Global CDN✓✓✓
SSL/TLS✓✓✓
Page Rules320125
DDoS ProtectionBasicAdvancedEnterprise
WAF (Web Application Firewall)Basic✓✓
Rate Limiting—✓✓
24/7 Phone Support——✓
Best forBlogs, small sitesGrowing businessesCritical, high-traffic apps

For WordPress blogs and small e-commerce, **Free is almost always sufficient**. Upgrade to Pro only if you need more than 3 Page Rules or advanced DDoS protection.

Bottom Line: Cloudflare CDN is the fastest, easiest way to improve WordPress performance at zero cost. Setup takes 30-60 minutes, and the benefits compound forever: faster load times, reduced server bandwidth, stronger security, and better SEO rankings. Every WordPress site should use Cloudflare. The process is beginner-friendly, and this guide covers every step and common issue.

Need Hosting That Works Perfectly with Cloudflare?

AsiaGB Hosting fully supports Cloudflare with free Let's Encrypt SSL on DirectAdmin. Ready for Full (Strict) mode immediately, no additional configuration needed. Start fast from day one.

View Hosting Plans →