1 Introduction
I first learned about Cloudflare around the beginning of last year, which was almost a year ago. During this year, I have been using a Free account to enjoy many of Cloudflare's features for free (CDN cache acceleration, WAF, DDoS protection, Tunnel, Workers, R2, etc.). To be honest, my feelings have been quite mixed: on one hand, it feels great to get them for free, but on the other hand, I feel a bit guilty about it (back then, because I always used pirated software, I felt I owed Microsoft, so I bought a Surface Pro 4 with my own money to pay off that debt~). At the same time, I am also very curious about the extra features available to Pro subscription users. After all, if a Pro user pays annually, $20/month is not that expensive—you can save that much just by skipping one big meal a month. The key question is, compared to regular Free users, are the extra features for Pro subscription users really worth $20? (I believe most webmasters using Cloudflare Free accounts have this same doubt).
With doubts, I searched the internet for a long time and found that there are almost no articles verifying this issue in detail. Generally, someone just asks a question in some forums, and then someone replies with a few simple words, which are also highly subjective:




In fact, even Cloudflare's own official website writes it very briefly:

So, how is the actual experience of Pro users? Will subscribing to Pro make you a god, or is it actually throwing money down the drain, just getting a paid icon as mentioned earlier?
I am not someone who just echoes others. After all, Comrade Mao Zedong said: "Practice brings true knowledge." So, with these doubts, I spent a huge sum of 25 USD to subscribe to Pro, and started this one-month trial journey as a Pro user.
Note: I will summarize from four perspectives: fundamentals, performance optimization, security, and operations visibility.
2 Fundamentals
1 Connectivity
1.1 Changes in Domain Name Resolution Anycast IP
When I was using a Free account before, the resolved address of my blog domain ”blog.tangwudi.com” was ”104.21.x.1":

As a result, the resolved IP changed after upgrading to Pro:

The reason I paid attention to this issue is that I saw someone asking about it before:

However, even though the resolved IP changed after I upgraded to Pro myself, I still cannot determine the changes in resolved IPs for others after they upgrade to Pro. Therefore, I cannot draw a conclusion. I can only say that upgrading to Pro indeed ”has a high probability” of changing the resolved IP. I hope more friends who subscribe to Pro can leave a comment about your situation.
Note 1: Around December last year, my blog had access issues for some domestic broadband users. PT players should also remember that in December last year, many web pages or tracker servers of PT sites using Cloudflare (Free accounts) had access issues? In fact, it was because the IP range ”104.21.x.1" was blocked by the three major domestic operators. Telecom and Unicom had regional access difficulties, while Mobile was the most extreme, basically inaccessible nationwide. This situation only began to recover slowly after January.
Note 2: According to the current situation, those who get 3 IPs are highly likely Pro users, while those who get 7 IPs (104.21.*.1) and two IPs (104.* and 172.*) are highly likely Free users.
1.2 Connection Rate Comparison
1.2.1 Selection of Comparison Objects Using Free Accounts
So, is there any difference in the actual connection speed after upgrading to Pro? I used ITDOG's website speed test to compare my site with two websites using Cloudflare Free accounts (the famous PT sites ”Mouzhong” and ”Moutian”), because their resolved IP addresses were the same as mine when I was on the Free account (actually, having the same resolved IP doesn't necessarily mean it's a Free account, but my blind guess is that it is~).
Mouzhong:

Moutian:

1.2.2 Domestic Access Speed Test (TTFB)
blog.tangwudi.com:

Mouzhong:

Moutian:

Conclusion: The TTFB time for domestic access to the domain corresponding to the Pro account is at least half that of the domain corresponding to the Free account.
Note: TTFB time and the end-user's perception of website speed cannot be generalized, but for the same website, a shorter TTFB time definitely means a better access experience.
1.2.3 International Access Speed Test (TTFB)
blog.tangwudi.com:

Mouzhong:

Moutian:

Conclusion: The TTFB time for international access to the domain corresponding to the Pro account is on a completely different scale compared to the domain corresponding to the Free account (0.0x seconds vs. 0.x seconds or even x seconds), making comparison meaningless. However, a few tenths of a second for a Free account doesn't feel slow to humans, so the impact is actually not that significant for general personal sites using Free accounts. The key still lies in whether the caching rules are configured reasonably and the website's own optimization.
1.2.4 Cloudflare Pro vs. Free: Core Differences in Access Speed
From the previous TTFB test results initiated from “domestic” and ”abroad”, Cloudflare Pro account 与 Free account indeed has a significant difference in access speed between them. However, Cloudflare has never officially and explicitly claimed that the Pro account is superior to the Free account in terms of access speed or routing, so where exactly does the acceleration effect of the Pro account come from?
In fact, the acceleration effect brought by Cloudflare's paid plansis not achieved simply by changing IP addresses or providing special routing,but relies more on underlying network optimization, traffic scheduling priority upgrades, and more advanced caching strategies.These optimizations are mainly reflected in:
PoP (Edge Data Center) allocation for visitor traffic
Cloudflare has over 300 PoPs (edge data centers) worldwide, but different tiers of accounts have different priorities in traffic scheduling.:
Free account: Low priority, potential routing detours
• Free account traffic is easily scheduled to more distant PoPs during high loads,thereby increasing access latency.
• Some high-performance PoPs may not be open to Free accounts,but are instead prioritized for paid accounts.
• When domestic users access Free account sites,routing detours may occur,leading to an increased TTFB.
Pro account: Higher priority access to high-performance PoPs, reducing routing detours
• Pro account traffic, during load balancing, enters the nearest PoP with priority,reducing latency caused by routing detours.
• Although Pro accounts still cannot specify PoPs like Enterprise accounts, they aremore likely to enter Cloudflare's premium nodes,reducing access jitter.
• For overseas users, the PoP selection optimization of the Pro account is more obvious, which can significantly reduce TTFB.。
Real-world Impact
• Domestic Access: There is little difference between Pro and Free accounts because Cloudflare has no PoPs in China, and all traffic must be routed overseas.
• Overseas Access: Pro accounts are usually allocated to closer PoPs, resulting in a lower TTFB compared to Free accounts and a better experience.
Origin Requests Optimization
After a visitor's request enters Cloudflare,if there is a cache miss, Cloudflare still needs to request data from the origin server.The origin pull strategies differ across different accounts:
Free account: Origin pull path may be longer
• Free account's cache tier is lower,and the hit rate is not as good as the Pro account, resulting in more requests needing to pull from the origin.
• The origin pull path may take a detour,because origin requests from Free accounts do not necessarily choose the optimal path.
• This causes the Free account'sdynamic content loading (such as API requests, database queries) to potentially be slower than the Pro account.。
Pro account: Optimized origin pull paths, reducing origin server pressure
• Better cache management strategies, reducing unnecessary origin pulls and improving site performance.
• The origin pull path is usually more optimized, which, although not as good as the Enterprise account's ability to use Argo Smart Routing, is still superior to the Free account.
• Optional Argo Smart Routing to further improve origin pull speed and reduce network jitter。
Real-world Impact
• If the site mainly relies on static content (such as blogs, image sites), the Pro account has higher caching efficiency, reducing origin pulls and improving access speed.
• If the site is dominated by dynamic content (such as APIs, database queries), the Pro account's origin pull optimization may improve stability, but will not reduce the frequency of origin pulls.
1.2.5 Analysis of Official Promotional Strategies
Although the Pro account brings actual speed improvements in PoP selection and origin pull optimization, Cloudflare always emphasizes the “functional improvements” of the Pro account, rather than pure acceleration effects. So why doesn't Cloudflare officially promote “faster access speeds with Pro accounts” directly, but instead always emphasizes functional differences? I think it might be based on the following three reasons:
Limited by the network environment, different users have different experiences:
• Cloudflare's acceleration effect depends on multiple factors such as the user's geographical location, ISP operator, and site content type。
• For overseas users, the PoP optimization of the Pro account indeed brings faster access speeds.
• For domestic users, since Cloudflare has no PoP in mainland China, the speed improvement of the Pro account is not obvious, and the official team does not want to mislead users.
PoP allocation is dynamically scheduled, and 100% consistency cannot be guaranteed:
• Cloudflare will dynamically adjust PoP allocation based on real-time load conditions, even with a Pro account, it cannot 100% ensure that it always goes through the nearest PoP.
• This dynamic scheduling method means Cloudflare cannot give a fixed acceleration commitment, and can only distinguish between Pro and Free accounts from a functional level.
Cloudflare prefers to emphasize security and optimization features:
• Cloudflare's core business is not just CDN acceleration, but a comprehensive network security and optimization platform。
• The true value of a Pro account lies in stronger WAF rules, better DDoS protection, and more flexible caching policies, and Cloudflare also prefers to emphasize these features.
2 Number of Rules
This part consists of features already provided by the Free account, but with a smaller supported quantity. After upgrading to Pro, the corresponding configuration limits are also significantly increased. Here is a simple list of some commonly used ones:
Number of Page Rules
- Free account: 3 rules:

- Pro account: 20 rules:

Number of WAF Custom Rules
- Free account: 5 rules:

- Pro account: 20 rules:

Number of Rate Limiting Rules
- Free account: 1 rule:

And can only block for 10 seconds when the rate limit is exceeded:

- Pro account: 2 rules:

And can block for up to 1 hour after the rate limit is exceeded, as well as support custom response types:

Number of Cache Rules
- Free account: 10 rules:

- Pro account: 25 rules:

The above lists the ones I commonly use; I won't list the other less commonly used ones one by one. According to the official statement, the Pro plan has a total of 155-65=90 more rules than the Free plan:

Note: Having one more rate limiting rule is a huge help for me. It can be used to protect sensitive WordPress paths, such as setting a separate rate limit for ”/wp-admin/admin-ajax.php”. Previously, I had to split this part of the traffic separately and send it to the intranet Chaitin WAF for rate limiting (see article:Home Data Center Series - Solving the Protection Dilemma of WordPress AJAX: Using Cloudflare Tunnel to Achieve Normal Website Access and ”Shunted” Protection of Attack Traffic), and now it can finally be handled in the cloud. As for the number of other rules, having a few more or less doesn't really affect me much: just use ”or” more in the same rule~.
3 Performance Optimization
1 Image Optimization
1.1 Overview
Image optimization is a very important part of website optimization, and this feature is not available in Free accounts:

Note: Image resizing needs to be used in conjunction with Cloudflare Images (paid), and also requires modifying the image links (specifying width and height), which is not suitable for a lazy person like me, so it won't be covered in this article.
But after enabling Pro, both Polish and Mirage become available:

1.2 Polish
Cloudflare's image optimization featuresPolishcan automatically compress and optimize images on the website to improve page load speed and reduce bandwidth consumption: it optimizes images through both lossless and lossy compression, while supporting WebP format conversion, thereby providing more efficient image rendering. Polish also intelligently selects the most appropriate image format and quality based on the visitor's device and network conditions, further improving the user's browsing experience. Once Polish is enabled, image loading speeds will be significantly faster, especially on mobile devices, improving the overall performance and responsiveness of the website.
Compared to the image resizing feature, the biggest advantage of Polish is that it requires no hassle: images do not need to be stored on Cloudflare Images, and can be stored directly on your own server or other supported cloud storage (such as Cloudflare R2). Polish automatically optimizes and compresses images during transmission without requiring you to manually adjust the source files. Note that the Polish optimization feature only applies to domains proxied through Cloudflare, so you need to ensure that the domain of the image hosting service is proxied through Cloudflare.
How efficient is Polish's optimization? Take an image stored on my R2 as an example, with an original size of 234kB:

After being optimized by Polish, it was converted to webp format, and the size is only 130kB, which is 104kB less:

The image was directly converted to webp format and the size was reduced by nearly 45%, which is a very powerful optimization. Crucially, I didn't do anything except turn on a switch~~, so this is an optimization feature perfectly suited for lazy people.
Note 1: The prerequisite for the Polish feature to take effect is that the image has already been cached by the CDN; the Polish feature will not work on uncached images.
Note 2: Another meaningful parameter is Cf-Bgj, where imgq:100 indicates that the image quality has not been reduced, because I selected the ”Lossless” mode for Polish.
1.3 Mirage
Cloudflare's Mirage feature is an image acceleration tool optimized for mobile devices and low-bandwidth networks. It helps reduce page load times, especially in slow network environments, by intelligently adjusting how images are loaded and their quality. Mirage dynamically delivers adapted image sizes and quality based on the user's device screen size, resolution, and network conditions, thereby effectively reducing bandwidth consumption and improving user experience. It can also lazy-load images (load on demand), ensuring that images are only loaded when the user needs them, further optimizing website performance. Overall, Mirage makes web pages load faster on mobile devices, improving the overall access speed and smoothness of the website.
However, the effect of Mirage is not as easy to observe as Polish (it requires a slow network, and Chrome Developer Tools' device and network simulation might not work well), and there is no obvious indicator, so I won't bother with it just for a screenshot.
Note: Actually,Polish Polish is also effective for mobile devices. Polish's image optimization feature not only compresses and optimizes images, but also intelligently selects the appropriate image format and quality based on the visitor's device and network conditions. For example, Polish can convert images to a lighter WebP format, which is particularly beneficial for loading speeds on mobile devices, as WebP files are typically smaller than traditional JPEG or PNG files while maintaining good image quality. However, Polish focuses more on optimizing image size and format, unlike Mirage Mirage, which performs additional intelligent processing specifically for mobile devices (such as dynamically adjusting image sizes and loading on demand). Therefore, Polish can still improve image loading speeds on mobile devices, but if deeper mobile optimization is needed (such as lazy loading and device adaptation), Mirage or other technologies might be more appropriate.
2 Content Optimization
2.1 Overview
In content optimization, except for APO, all other features are available in the Free version, so I will mainly introduce APO. However, I can also mention Rocket Loader in passing, as this feature is also quite important:


2.2 Rocket Loader
Cloudflare's Rocket Loader is a feature that shortens page load times by lazy-loading non-critical JavaScript scripts on web pages. It postpones the loading of non-critical scripts, prioritizing resources crucial for page rendering, thereby reducing page blocking time. Through this lazy-loading method, Rocket Loader ensures that page content is presented to users faster, improving overall loading speed and user experience.
Some local WordPress plugins actually implement similar features, such as WP Rocket, which can delay the execution of non-critical JS files and optimize/combine JS scripts (it can also optimize and combine CSS).
I previously did a specific comparison and found that the difference between using WP Rocket and Rocket Loader was not significant. Naturally, I would prefer to install one less plugin and implement it via Cloudflare's cloud instead. Combined with Zaraz's third-party script cloud loading and management, this can greatly ”lighten the load” for WordPress. Of course, WP Rocket has other very practical features, which are related to the APO feature introduced in the next section.
2.3 APO (Automatic Platform Optimization)
The seventh part of the Cloudflare tutorial series I wrote earlier (see:Home Data Center Series Cloudflare Tutorial (7): Introduction to CF Worker Functions and Practical Operation, Verification, and Related Technical Principles of Implementing ”Beggar's Version of APO for WordPress” Based on Worker to Accelerate Website Access) In the article about using Workers to accelerate website access, the APO feature was actually already introduced:

Simply put, it only takes two steps:
Enable the APO feature switch in the Cloudflare dashboard:

Install and enable a Cloudflare plugin in WordPress (requires a very simple initial setup):

After completing these two steps, you can enjoy the global CDN optimization provided by Cloudflare based on Workers, automatically covering HTML, JavaScript, CSS, and image resources in WordPress, with support for unlimited traffic. Most importantly, after enabling APO, the improvement in website performance is not limited to caching and optimization, but also brings other significant benefits:
First, APO automatically enables smart caching for your WordPress site, eliminating the need to manually configure complex page rules or caching strategies. Traditional optimization methods usually require using plugins like WP Fastest Cache or WP Rocket to handle local caching, JS, and CSS optimization, as well as manually setting up cache rules in the Cloudflare dashboard, and potentially even configuring Workers and KV to achieve optimization. In contrast, APO automatically completes these optimization tasks through Cloudflare's automation mechanism, which not only saves tedious configuration but also reduces the possibility of human error, greatly simplifying the optimization process.
Secondly, APO also avoids the complex caching logic that often needs to be adjusted in traditional optimization. In the past, caching strategies for WordPress were often not fine-grained enough, requiring manual setup of cache rules for different resources, or using Workers and KV to achieve more precise control. After enabling APO, Cloudflare automatically handles all caching and optimization, whether it is images, HTML, or JavaScript, automatically achieving smart caching and optimization without the need for manual intervention.
Most importantly, APO ensures that website resources load quickly no matter where users are located through Cloudflare's global CDN network, significantly improving page response speed and user experience. Especially for global visitors, APO's optimization effect is particularly prominent, effectively reducing regional latency and improving access speed.
Overall, after enabling APO, your WordPress site will not only enjoy more efficient caching strategies and optimization, avoiding the hassle of manual configuration, but also automatically receive Cloudflare's powerful global network support and unlimited traffic capabilities (previously, when using Worker-based optimization, the biggest worry was encountering DDoS attacks, because the free quota of 100,000 requests/day is really not durable~), greatly simplifying performance optimization work and making the website run more smoothly and efficiently.
Note 1: You can also subscribe to the APO feature separately in a Free account ($5/month). So, if you had already subscribed to APO in a Free account before, subscribing to the Pro annual membership is equivalent to only paying an extra $15 per month. Thinking about it this way, doesn't it instantly feel like a great bargain?
Note 2: APO is a feature designed specifically forWordPresswebsites. Cloudflare mainly provides this service through deep integration with WordPress (after all, WordPress has a huge global market share and a great user base). Therefore, for other Pro subscribers who do not use WordPress to build their websites, this feature is useless, which is quite a waste.
Note 3:APO and theRocket Loader mentioned in the previous section can take effect simultaneously and complement each other to improve website performance. APO optimizes and caches static resources (HTML, CSS, JavaScript, and images) of WordPress websites through Cloudflare's global CDN network, accelerating page loading and reducing origin server load; while Rocket Loader It mainly optimizes the loading order of JavaScript. By delaying the loading of non-critical scripts, it ensures that page content is rendered first, reducing render blocking. When used together, APO provides site-wide caching and resource optimization, while Rocket Loader focuses on optimizing script loading, which can significantly improve website loading speed and user experience. However, WordPress locally usually also has related optimization options. For example, the Argon theme I use already has a built-in image Lazyload feature:

It is recommended to turn off local optimization options and let Cloudflare handle everything to prevent mutual interference.
2.4 Protocol Optimization
I won't say much about this part. The only Pro-exclusive option is ”Enhanced HTTP/2 Prioritization”, while the others can be used in the Free plan. You can just read the comments yourself; basically, just turn them all on. However, webmasters who care about domestic user access should be cautious about enabling the ”HTTP/3" option. After all, QUIC UDP port 443 traffic is too conspicuous (crucially, this part of the traffic has to cross a certain wall) and is too easily targeted.

2.5 Others
The Pro-exclusive feature in this part is Automatic Signed Exchanges (SXG) Feature:

Enabling Automatic Signed Exchanges (SXG) this feature, Google no longer acts solely as a traditional search engine forwarding access requests to the website, but also serves as a cache server to directly respond to user requests with cached content. This means Google can ensure the integrity and validity of cached content through secure signed exchanges with visitors, while significantly accelerating page loading speed. This not only reduces latency during page loading but also effectively improves Core Web Vitals located in Largest Contentful Paint (LCP) metrics, thereby enhancing user experience and indirectly improving SEO rankings.
The specific effect after enabling is that an additional source domain ”blog-tangwudi-com.webpkgcache.com” appears:

Correspondingly, the number of requests from ”google.com” will decrease.
4 Security
1 WAF
For Pro users, in addition to the increased number of supported WAF custom rules, the most critical change is the managed rules.

Cloudflare WAF for Free users provides the so-called “Free Managed Rules”, which officially ”provide some basic WAF protection, mainly targeting common attack types such as SQL injection and cross-site scripting (XSS) for default protection.” But in reality, these protection effects are relatively limited, and can even be said to be practically non-existent. Previously, I mainly relied on SafeLine Community Edition(now renamed to Personal Edition) to block most attacks in the intranet, and then used the Wordfence plugin in WordPress for a second layer of filtering to ensure security. Usually, only after SafeLine WAF intercepted multiple repeated attack behaviors would I manually add custom rules in Cloudflare WAF to block them.
From this perspective,Free users 's WAF functionality can actually be seen as an almost transparent component. By default, it does not provide much protection, and what really works depends entirely on subsequent manual intervention and rule addition by the user.
However, it's different after upgrading to a Pro user:

For Pro users, Cloudflare WAF provides two important managed rulesets:Cloudflare Managed Ruleset 和 Cloudflare OWASP Core Ruleset, and these two rulesets play an important role in protecting websites from various cyber attacks:
Cloudflare Managed Ruleset
Overview: The Managed Ruleset provided by Cloudflare is a series of pre-configured rules used to defend against common web attacks, such as SQL injection and cross-site scripting (XSS). Through these rulesets, Cloudflare automatically updates and optimizes protection strategies without requiring manual configuration by the user.
Features:
• Automatic Updates: Rules are updated at any time to cope with new security threats.
• Efficient Protection: Covers common attack methods, such as cross-site request forgery (CSRF), file upload vulnerabilities, etc.
• No Manual Intervention: The Cloudflare Managed Ruleset does not require additional configuration by the user; the system will enable it automatically.
• Regular Optimization: Based on global network traffic and security trends, Cloudflare continuously optimizes these rules to improve detection accuracy and reduce false positives.
Applicable Scenarios: For users who do not have much time or resources to manage WAF settings, the managed ruleset provides a very convenient and effective protection solution.
Currently, there are 34 WordPress-related rules in the managed ruleset. As a WordPress user, I instantly feel a lot safer:

Cloudflare OWASP Core Ruleset (CRS)
Overview:OWASP Core Ruleset is based on the recommendations and best practices of OWASP (Open Web Application Security Project) . It covers the most common OWASP Web security risks and protects websites from attacks such as SQL injection, XSS, and command injection through these rules.
Features:
• Comprehensive Attack Protection: CRS is designed to protect against the most common and dangerous Web security vulnerabilities listed in the OWASP Top 10.
• Deep Protection: Compared to the Cloudflare Managed Ruleset, the CRS ruleset has a wider scope of protection, covering more complex attack types such as XML External Entity Injection (XXE) and Remote File Inclusion (RFI).
• Flexibility: OWASP CRS provides flexible configuration options, allowing users to enable or disable specific rules as needed, and even customize rules to suit specific website application scenarios.
• Open Source Support: CRS is open-source, meaning rules can be modified and extended based on actual needs.
Applicable Scenarios: If deeper Web application security protection is needed, or if the website application involves sensitive data, CRS is an ideal choice, especially suitable for users who need to comply with certain security compliance requirements (such as PCI-DSS).
Through these two rulesets, Cloudflare Pro users can obtain more powerful and flexible security protection, effectively reducing potential cyber attack risks. Taking myself as an example, I have enabled the 2 managed rulesets for some time now, and the packets intercepted on my intranet SafeLine WAF have decreased significantly compared to before (the Community Edition does not allow selecting a time range, so I can only see today's interceptions~):

Even if there are intercepted packets, they are basically due to rate limiting:

As for the Wordfence plugin on WordPress, the real-time traffic is basically left with only login events. After observing for another 2 days, it can also be uninstalled (the WordPress lightweighting project has taken another big step forward~).
Note: For friends who are familiar with WAF rules, you can modify the rules in the managed ruleset according to your actual needs. For those who are not familiar, generally keeping the default configuration is fine. This default configuration is also considered Cloudflare's recommended best practice suitable for the vast majority of users.
By the way, someone previously made a Traditional Chinese mirror site of my website:

After a brief investigation, I found that it was implemented using a reverse proxy. By disguising itself as a Googlebot in the UserAgent, it easily bypassed the free managed WAF rules of the Free account. Before upgrading to Pro, I dealt with this by manually adding a rule in the WAF custom rules: ”Block all requests that contain the word Googlebot in the UserAgent but do not belong to Google's ASN.”
Now, after upgrading to Pro, there is no need to add any rules; it is directly blocked by the managed rules:

2 Bots
2.1 Free Users” ”Bot Fight Mode"

For Cloudflare Free users, enabling “Bot Fight Mode” , Cloudflare will perform basic automated traffic identification and mitigation. For example, Cloudflare can identify some common automated attack behaviors, such as malicious crawlers, brute force attacks, etc., and will use CAPTCHA 或 JavaScript Challenges to verify whether the traffic is a malicious automated request. In this case, automated traffic will be treated asmalicious traffic, and protect the website through challenges or blocks.
However, Cloudflare will by default allow another type of traffic, namely “Definitely Automated” traffic, which does not exhibit obvious malicious behavior but is still initiated by automated programs. For example:
• Web crawlers: They do not necessarily perform malicious operations, but frequently access the website to collect data.
• Automated scripts: Used to request data on a large scale, but do not contain brute force or other offensive behaviors.
“Definitely Automated” traffic is traffic completely generated automatically by scripts or tools, usually without user participation or interaction. The identification of this type of traffic is relatively complex. Cloudflare Free accounts can only perform basic screening of this traffic through relatively loose rules, without any way to exercise fine-grained control over it.
In short, after enabling “Bot Fight Mode” , Cloudflare will block those obviously malicious automated traffic (such as attempting to log in via brute force, crawling sensitive data, etc.) and confirm the legitimacy of the requests through challenge mechanisms. However, for “Definitely Automated” traffic, because this type of traffic lacks malicious characteristics and does not have high-frequency or malicious request behaviors,Free usersthere is no permission to customize the handling of this “Definitely Automated” traffic , sothis traffic is allowed to pass through by default, and will not trigger blocking or verification.
2.2 Pro Users” ”Standard Bot Protection Settings"
After upgrading to a Pro user, the bot features here become much more abundant:

In the detailed configuration interface of Bot Protection, there is finally an option for how to handle ”Definitely Automated” traffic:

Compared to Free users, Pro users can configure the handling behavior for ”Definitely Automated” traffic. If you are worried about false positives, you can set it to ”Managed Challenge”.
Although Pro users 在 “Definitely Automated” traffic 's identification capability has significantly improved compared to Free users , it still faces some difficulties:“Definitely Automated” traffic's characteristic is that this traffic usually does not have obvious malicious behavior or attack signatures, so accurate identificationstill presents certain difficulties. In particular, some low-frequency automated traffic whose behavior is relatively similar to normal users may be misidentified as normal requests, making 100% accurate identification impossible. In this case, relying solely on automatic identification features is not enough to completely prevent all malicious automated traffic (simply put,Definitely Automated rules mainly target those relatively simple bots with obvious behavioral patterns, which are usually low-end crawler scripts 或 basic automated tools, which typically do not possess complex anti-detection capabilities and are easily detected by Cloudflare's standard rules).
However, combining it with Pro users 的 WAF Managed Rulesets, especially protection rules targeting common attack patterns (such as SQL injection, cross-site scripting, etc.), can greatly improve the protection against “Definitely Automated” traffic , enhance identification accuracy, and reduce the risk of false positives (the previous blocking of malicious reverse proxy traffic from mirror sites is an example). Therefore, by flexibly configuring WAF rules and enabling Bot Protection,Pro users can more effectively deal with these hard-to-distinguish automated traffic and improve overall security protection capabilities.
By the way, Cloudflare Business and above users have access to the more advanced ”Bot Management“, which can analyze and identify traffic based on technologies such as machine learning, behavioral analysis, and fingerprinting. It can more accurately distinguish automated programs (such as crawlers, malicious reverse proxies, etc.) and take corresponding actions (such as challenges, blocks, etc.). Unfortunately, at a price of at least $200 a month, I can't afford it even if I sell a kidney~.
At the same time, WordPress users have another advantage. After turning on the ”Optimize for WordPress” switch, Cloudflare will target WordPress common attacks and malicious automated traffic to perform some specific optimizations, including but not limited to the following aspects:
- Prevent brute force login: WordPress login page /wp-login.php and admin dashboard /wp-admin/ are often targeted by attacks, especially through brute-force attempts to obtain administrator passwords. After enabling this option, Cloudflare will more aggressively detect such automated traffic targeting login pages and use CAPTCHA 或 JavaScript Challenges to block these malicious requests.
- Restrict access to common entry points: Some common exposed interfaces in WordPress sites (such as /wp-login.php, /wp-admin/, /xmlrpc.php, etc.) are frequently attacked by malicious crawlers and automated scripts. This option helps Cloudflare optimize protection for these interfaces, reducing the risk of attacks from malicious automated traffic.
- WordPress-specific malicious traffic identification: For some unique behaviors of WordPress, after enabling this option, Cloudflare will use rules and algorithms specifically optimized for WordPress to improve identification efficiency and avoid falsely blocking normal traffic.
- Automatically handle WordPress-specific attack patterns: WordPress often becomes Automated scripts 和 the target of crawlers, and this traffic may not only be malicious but also large-scale data scraping. After enabling this option, Cloudflare will pay special attention to the patterns of such traffic and perform targeted optimization.
In short, WordPress users have won big again.
3 Changes in Security Strategy Thinking for Pro Users
From the Free user's WAF managed rules, which are almost non-existent, and rudimentary bot attack identification, to the Pro user's two major WAF managed rule sets and the highly effective identification and unified handling of ”definitely automated” traffic, this has prompted me to completely reorganize my site-wide security strategy.
One thing I was previously quite torn about was that if the home data center went down entirely (power outage, network disconnection), although the detection script running regularly on the Tencent Cloud Lighthouse server would detect it and automatically enable the backup connector of the home data center's Cloudflare Tunnel, thereby turning the disaster recovery site of the blog on the Tencent Cloud server into the main site to restore service (see article:Home Data Center Series: Flexibly utilizing Cloudflare Tunnel to achieve automatic takeover by disaster recovery site when the main WordPress site fails), however, security would be greatly compromised because the home data center has an internal intranet WAF for secondary filtering.
But now, due to the huge improvement in security for Pro users (which is actually just highlighted by Free users serving as a foil~), even if the disaster recovery site on Tencent Cloud becomes the main site, security issues do not need to be considered in the short term.
At the same time, the originally highly complex WAF custom rules(which used to be the main line of defense for my website security), I have also thoroughly organized and optimized: clearing out a large number of outdated or no longer needed rules, shifting the security focus from relying on these tedious custom rules to more efficient and automated protection solutions. Today, the custom rules that originally bore the main responsibility for protection have turned into “auxiliary police”, while the real line of defense is handed over to “managed challenges for ”definitely automated" traffic 和 WAF's 2 major managed rule setsThis shift allows me to respond to various automated traffic attacks more intelligently and precisely through Cloudflare, while reducing excessive manual intervention and rule maintenance, further improving security and management efficiency.
Note: Even if Pro users enable WAF's two major managed rule sets and the identification of ”definitely automated” traffic, they cannot assume they can rest easy. After all, it is just one of many services provided for $20, it won't perform miracles, it's just much better than the Free tier. Therefore, my intranet WAF is still in place (heterogeneity of security devices is still meaningful). For friends using WordPress, it is still highly recommended to install the Wordfence plugin if possible (although it might add a few dozen milliseconds of ”Total Blocking Time”).
5 Operations Visibility
Many people might not care about this part, as I believe most people do not frequently visit Cloudflare's web dashboard. However, for those in the O&M (Operations and Maintenance) industry, or after-sales engineers who often need to troubleshoot faults, a backend system that can provide detailed monitoring, statistics, log queries, and analysis functions is crucial:
When the website encounters attacks , being able to respond quickly,identify the source, type, and scope of the attackand formulate corresponding defensive measures
When the website experiences access anomalies , you can immediately check traffic conditions, cache hit rates, and error logsto quickly locate the problem
When needing tooptimize performance , you can analyze website bottlenecks through detailed traffic data, adjust caching strategies, WAF rules, or optimize content delivery
Compared to the Free version, Pro users get a significant boost in O&M visibility, which can be summarized in the following 3 aspects:
More detailed analytical data
Pro users can get HTTP Traffic 和 Security Analytics more detailed statistics than the Free version, including:
• Richer metrics(such as request volume, data transfer volume, page views, etc.)
• Advanced filters(Filter data by dimensions such as country/region, IP, data center, edge status code, etc.)
This data is highly helpful for analyzing access patterns, optimizing cache, and adjusting security policies, as can be seen from the comparison of the ”HTTP Traffic” and ”Web Analytics” content in the ”Analytics & Logs” section for Pro and Free users below.
HTTP Traffic:
Free version:


Pro version:



Web Analytics:
Free version:

Pro version:

It can be seen that the Pro version provides much richer information in both the ”HTTP Traffic” and ”Web Analytics” sections.
WAF Event Logs & Rule Matching Details
The Free version's WAF can only display the total number of blocked requests and cannot view specific block details, whereas the Pro version's WAF Event Logs provide complete attack records, including:
• Triggered specific rules(such as OWASP rules, managed rules, IP restrictions, etc.)
• Attack source IP, country/region, User-Agent
• Detailed HTTP request information(such as request URL, parameters, request body, etc.)
This is very important for analyzing attack patterns and adjusting defense strategies, especially for troubleshooting false positives , allowing precise determination of which traffic should be allowed or which rules should be adjusted, as can be seen from the comparison of the ”Security” - “Events” interface content for Pro and Free users below:
Free version:

Pro version:



Similarly, it can be seen that the Pro version provides much richer information in the ”Security” - “Events” section.
Detailed DDoS Attack Reports
The Free version only provides basic DDoS protection, while the Pro version's DDoS monitoring reports allow you to view:
• Specific attack patterns (such as SYN Flood, UDP Flood, HTTP Flood)
• Attack peak QPS, number of blocked requests
• Targeted URLs or ports
When suffering a DDoS attack, this data can help webmasters more clearly understand the scale of the attack and adjust Cloudflare rules for optimized defense. This part of the functionality also relies on ”Security - Events”, so I won't repeat the screenshots. However, in the end, as the saying goes, this part varies from person to person, and not everyone will be interested.
Note: Pro users also have an advantage in operations and maintenance. Compared to Free users who can only post on community forums for help, Pro users can directly submit tickets to open cases:

However, I haven't experienced it yet, I'll find an opportunity to try it out~.
6 Who is the Pro version suitable for? Is it worth upgrading?
In the previous articles, I introduced in detail the multiple improvements of Cloudflare Pro version compared to the Free version. However, it needs to be emphasized again that the Pro version is not suitable for all sites. Its main advantages are reflected in dynamic sites that require frequent origin pulls, especially for WordPress users. To illustrate the value of the Pro version more intuitively, the following is a summary from the perspectives of both static and dynamic sites:
Static Sites: Free version is enough
For completely static websites, such as blogs generated by Hugo, Hexo, Jekyll, or document sites and corporate official websites with pure HTML/JS/CSS, Cloudflare Free version can already provide sufficient protection and optimization. Static sites do not involve databases and backend APIs, so the security risk is low, and the default DDoS protection of the Free version is sufficient to cope with common attacks. In addition, such sites can usually achieve full-site caching, and the access speed itself is already very fast, so the dynamic optimization features of the Pro version are of little significance. If the site's images have already been manually optimized to WebP or compressed using TinyPNG, the additional improvements of Polish and Mirage in the Pro version are also relatively limited. Therefore, most static site users do not need to upgrade to the Pro version.
Dynamic Sites (especially WordPress): Pro version offers significant improvements
For dynamic sites such as WordPress blogs, e-commerce, and forums, the value of Cloudflare Pro version is very obvious. APO (Automatic Platform Optimization) can reduce origin requests for dynamic pages, significantly lower TTFB (Time to First Byte), and improve loading speed. At the same time, the Pro version provides stronger WAF rules, which can effectively defend against common attacks targeting WordPress, such as SQL injection and brute force attacks. Bot Management can also reduce spam comments and malicious crawlers, further optimizing site operations. In addition, the Pro version provides more detailed logs and security analytics, helping webmasters better monitor traffic and optimize performance. Therefore, for long-term operated dynamic sites, the Pro version is a worthwhile investment.
Based on the previous analysis, the following table has been compiled for friends who are considering subscribing to the Pro version:
| Site Type | Free version Cloudflare | Pro version Cloudflare | Is it worth upgrading? |
|---|---|---|---|
| Pure static site (full site caching) | Basic protection + high cache hit rate | Limited improvement (unless relying on Polish, Mirage) | Not recommended |
| Lightweight dynamic site (small blog) | May be limited by cache and WAF rules | Provides WAF managed rules to reduce spam traffic | Optional |
| WordPress site (including dynamic interactions) | Vulnerable to attacks, TTFB may be high | APO + WAF protection + Bot protection, dual boost in performance and security | Recommended |
| E-commerce / Forum / API site | Poor performance under high concurrency, high security risks | Stronger caching strategies + protection rules | Highly recommended |
| Frequently suffers from DDoS or malicious traffic | Basic DDoS protection only | WAF managed rules + detailed attack analysis | Recommended |
7 Summary: An Unexpectedly ”Awesome” Experience
Actually, I feel like I've boarded a pirate ship: I originally just wanted to subscribe to Cloudflare Pro for a month to experience the various improvements of the Pro version and write a summary to call it a day. I didn't expect that after all this tinkering, I actually feel the Pro version is completely tailored for me, and I've even started seriously considering subscribing to the annual plan. Although I'll have to tighten my belt, this investment is quite worth it as it can significantly reduce the time and effort spent on daily blog maintenance.
However, I still want to emphasize once more:The Pro version does not directly improve access speeds for domestic users in ChinaThe reason I emphasize this again is that I've seen many people in various forums have this misunderstanding, thinking that after upgrading to the Pro version, domestic access speeds will significantly improve. Then, after upgrading, they find there is actually no difference and say Pro is useless. We must remember an unchangeable fact: Cloudflaredoes not have its own nodes in mainland China, so the direct speed optimization brought by the Pro version can only be reflected in the access of overseas users.
For domestic sites, to truly improve access speed, you still need to rely on Cloudflare APO, page optimization, caching strategies, and other means, and you might even need to use domestic CDNs. If you are willing to obtain an ICP filing and particularly value domestic access speed, then perhaps using a domestic CDN directly would be a better solution. After all, even with Cloudflare's Enterprise version, using domestic JD Cloud nodes still requires going through the ICP filing process. And if you are willing to get an ICP filing, why go through such a hassle to mess with Cloudflare?
Ultimately,whether Cloudflare Pro is right for you depends on your needs: If your site's audience is mainly overseas users, or if it is a dynamic site (especially WordPress), the various optimizations of the Pro version are definitely worth getting. But if your website visitors are mainly from mainland China and you have already optimized access speed through other means, then the Free version might already be enough.
Hello, blogger, I really like this article, it is very wonderfully written.
Also, I'd like to share a piece of information with you, which I also saw shared by others. After subscribing to the Cloudflare Pro plan, if you cancel the subscription and opt out (I think it's like going to a food market to buy vegetables, where if bargaining fails, you deliberately turn around and walk away), Cloudflare will then offer you a retention deal, hoping you will renew. Considering whether you might be too poor to afford the fee, they will halve the price of the same Pro plan for you. You can go and test it out.
Haha, this “market bargaining” metaphor is indeed very vivid. I have heard of this. According to feedback from some users online, Cloudflare does indeed have a certain probability of offering a “retention offer.” Some people receive discounts like half-price renewals during the process of canceling Pro or preparing to downgrade to Free. However, at present, this seems more like a gray-scale marketing strategy rather than a public, stable official mechanism that everyone can trigger. Different accounts, regions, and subscription histories may yield different results; some people get the discount pop-up, while others get nothing at all.
I haven't tried it myself for now, mainly because my site is already quite heavily dependent on Cloudflare. When I upgraded from Free to Pro before, I encountered a rather noticeable delay in plan status synchronization: even though I had already paid, some Pro features didn't actually take effect until a few days later. So now I have a bit of “awe” towards its billing / plan provisioning system: my biggest worry is not that I won't get the discount, but rather that if I do trigger the downgrade process, Cloudflare might withdraw some Pro capabilities first, and then upgrading again would require waiting a few days or even a week to sync, which would be quite a hassle for the production environment.
If the site is already quite dependent on Cloudflare's various features, I personally still prefer stability first. However, for users who do not rely heavily on Cloudflare Pro features themselves, even if they do downgrade to Free for a short time, the impact probably won't be too significant. In this case, it is indeed worth a try. After all, if you can really trigger the half-price renewal, it can save you a chunk of subscription fees in the long run.
I'd like to ask, from the perspective of a user visitor, which domestic ISP's home fixed broadband is relatively faster for accessing Cloudflare content? (Although it was mentioned in the main text that Cloudflare has no POP in mainland China, so none of them will be very fast. I just wanted to ask, relatively speaking, which one would be better?)
Awesome
Not at all, it's just written in a bit more detail.
Hello author, thank you for this blog post. This is the most useful information on the Cloudflare Pro plan that I have found. Thank you!
A small reminder, I couldn't find it on Bing, only on Google. I suggest strengthening the SEO aspect.
I treat SEO equally for all, but Bing has always had an issue with how I name my articles (because they all start with "xx series"), saying my article titles are repetitive. There's nothing I can do about this, so I just have to let nature take its course.
May I ask if a website connecting to CF needs to set up search engine spider filtering and the like?
For Cloudflare Free subscription users, if you want search engine spiders to crawl your website content, the default policy is fine, because if the WAF of the Free subscription has no manually configured block rules, it is basically fully open by default. If you do not want search engine spiders to crawl your website content, then you need to set up custom rules to block them.
So just using the default is fine, no other extra operations are needed?
Yes, if you don't configure it, the WAF won't take effect at all, just act as if it doesn't exist.
Okay, today I encountered a webmaster tool crawling link prompt “Failed: Blocked due to forbidden access (403)”. I just checked and it seems it might be a CDN setting issue, so I came to look up some information. Thank you for your hard work, boss!
Specific problems require specific analysis. This depends on whether you really have absolutely no WAF, global rate limiting, etc. configured, and the default behavior of Free users and Pro users might be different. You can check the event logs in ”Security” - “Analytics” on the Cloudflare dashboard to see if there are any blocked records.
Okay, I will check the logs to see if there are any blocked records.
I feel that with this monthly payment, it seems one could live quite well with domestic cloud service providers too,
This depends on how you look at the issue. Even without considering ICP filing, comment restrictions, various feature and quota limits, Google search indexing, etc., and even if we calculate the cost strictly based on the provided features and prices, for the same features and quotas, I don't think even 1,000+ RMB would cover it domestically (CDN traffic, DDoS protection, WAF protection, object storage, etc.), let alone in the event of a large-scale DDoS attack. Of course, in terms of access speed, domestic providers indeed have the advantage, but a CDN without secure access is actually meaningless. 20 RMB for 100G of traffic, although not expensive, is really not enough once you are targeted by attacks.
It seems quite good, but the price is a bit expensive.
Yes, a bit expensive, but not extremely expensive, it just depends on whether you need it.
Both Free and Pro will direct traffic from China to Los Angeles or San Jose, though for a period of time it could enter Japan and Hong Kong POPs. Of course, that happened a long time ago. The additional features in Pro are quite nice, well worth the 25u/mo 😀
Annual subscribers only need 20u/mo~~~. Actually, it's mainly for the APO feature for WordPress users, which is worth every penny of the $5. Even if I didn't want other features, I would be very willing to subscribe to APO alone. Previously, I used the Worker optimization method to use the "beggar's version" of the APO feature, with a free request quota of 100,000 per day, but as soon as a DDoS hit, it would go down, which was extremely frustrating.
If there is a Wordfence plugin, it probably wouldn't be scraped/mirrored, right? I was curious at the time why my main site wasn't scraped, while another site with very low traffic was. Later I found out it was because the main site's Wordfence blocked it.
On my end, it indeed wasn't blocked, at least regarding this mirror site. I was also very curious at the time and studied it for a long time, because generally, reverse proxy traffic to my blog is ineffective. Actually, the key is whether Wordfence has the rule ”if the User-Agent masquerades as a Googlebot but the IP address does not belong to Google's ASN, block it”. I think maybe not every mirror site uses this method. Unfortunately, I have already deleted Wordfence, otherwise I could verify this issue.
Screenshot at the time:
![]()
Show Image
From this screenshot, Wordfence indeed has this policy, but why didn't my Wordfence block it? I'm just using the default policy of the Free version, which is really strange. Could it be that you are not using the Free version, or not using the default policy?
Ah, okay, maybe that's the reason. I used a tricky method to let the Free version update Premium rules. Although it shows (Premium Protection Disabled), in fact, Premium rules and real-time IP blacklists, etc., will be enabled.
I know this method, but then I thought better of it, because I'm really not used to fighting on home turf; I've always wanted to keep enemies outside the gates, so I figured I'd delete Wordfence sooner or later and didn't want to bother. Besides, that method requires doing it all over again every time Wordfence updates its version, which is just too much hassle.