WordPress Bot Protection with Cloudflare: My Exact WAF Rules (Copy/Paste)

This video training is reserved for ONEPass members only.

This resource is about implementation.

In the public article, I explained why bot protection matters and why Cloudflare is the most effective place to stop it. Here, we’re skipping theory and going straight to execution.

Below, you’ll find the exact Cloudflare WAF security rules I use on my own sites and on client sites, designed to work within the limits of a free Cloudflare account. These rules are intended to be copied, pasted, and enabled as-is, with only minimal adjustments if your site has unique requirements.

Alongside this page is a companion video. In that video, I walk through:

  • Where these rules live inside a standard Cloudflare account
  • The correct order to create them
  • Which rules are skip, challenge, or block
  • How to safely test and deploy them
  • What to tweak if something legitimate gets caught

If you follow the steps shown, you’ll end up with a layered Cloudflare WAF setup that blocks the majority of automated WordPress bot traffic before it ever reaches your server.

I will also point the way to some common exclusions and modifications you may need to make to these rules.

 

Oops! You don’t have permission to view this resource!

Duration

22m 37s

Date Published

February 9, 2026

Categories

Latest Content

  • The Shift That Makes Automation (and AI) Actually Work

    February 9, 2026
  • Independent Analytics Review: A Better Way to Own Your Website Analytics

    February 3, 2026
  • Train Your AI Like A Team Member

    February 2, 2026
  • How To Survive Solopreneurship

    January 26, 2026
  • Ship Quickly. Break Things.

    January 19, 2026
  • The Online Course Model Is Broken

    January 12, 2026
  • Up Your Game With AI

    January 5, 2026
  • WordPress Plugin Ecosystems: Seamless Integrations or Risky Silos?

    December 22, 2025