Cloudflare Security & compliance Stability

No managed WAF ruleset on a production zone

Part of the WAF & rate limiting check · fix arrives as a guide

What it is

No managed WAF ruleset is deployed on a zone serving production traffic.

Why it matters

Proxying through Cloudflare is not filtering. Without a ruleset, injection attempts, known exploit paths, and scanner traffic reach your origin exactly as they would have without Cloudflare in front.

How to fix it

Deploy the Cloudflare Managed Ruleset and the OWASP Core Ruleset. Start in log mode to see what would be blocked, review the matches for false positives, then switch to block.

Run them all on your app

Connect your repo and your live services with read-only scopes. The first scan is free, and nothing changes without your approval.