Cloudflare
Security & compliance
Stability
No managed WAF ruleset on a production zone
Part of the WAF & rate limiting check · fix arrives as a guide
What it is
No managed WAF ruleset is deployed on a zone serving production traffic.
Why it matters
Proxying through Cloudflare is not filtering. Without a ruleset, injection attempts, known exploit paths, and scanner traffic reach your origin exactly as they would have without Cloudflare in front.
How to fix it
Deploy the Cloudflare Managed Ruleset and the OWASP Core Ruleset. Start in log mode to see what would be blocked, review the matches for false positives, then switch to block.
Run them all on your app
Connect your repo and your live services with read-only scopes. The first scan is free, and nothing changes without your approval.