Christopher Abraham home
Christopher Abraham

SEO consultant: technical SEO, indexing, schema, and AI search

Cloudflare for WordPress: setup, plans, and what to budget

If I could make one change to most of the WordPress sites I'm asked to look at, it would be putting them behind Cloudflare. It makes them faster, safer, and cheaper to run, and the free plan alone covers a lot of ground. My own experience and every AI assistant I've put the question to agree. For the record, Cloudflare pays me nothing for saying so, which, given how often I say it, is a little sad.

Two ways to use Cloudflare

Every DNS record in Cloudflare shows a cloud. A gray cloud means DNS only: Cloudflare tells browsers where your server is, then steps aside. An orange cloud means proxied: visitors reach Cloudflare's network first, and it serves what it can from the data center nearest them before passing the rest to your host. The speed and protection only apply to orange records.

What the free plan does once you're proxied

The paid features that matter for WordPress

Even though Cloudflare can cost nothing, when a WordPress site runs through it I recommend budgeting about $50 a month for Cloudflare's paid services, starting with Pro. WordPress almost always benefits. I pay for Pro on my own main site.

Setting it up

  1. Add the site in a free Cloudflare account. Cloudflare scans your existing DNS records; compare them against your current DNS provider line by line, especially mail records, before going further.
  2. Change the nameservers at your registrar to the two Cloudflare gives you. Or transfer the domain to Cloudflare Registrar, which charges the registry's wholesale price with no markup on renewals.
  3. Turn the website records orange. Leave mail records gray.
  4. Set SSL/TLS to Full (strict), which requires a valid certificate on your host; most hosts provide one free. Flexible mode can trap WordPress in an endless redirect loop.
  5. Switch on Always Use HTTPS, then HSTS once every page loads securely.
  6. Install the official Cloudflare WordPress plugin, connect it, and turn on APO if you have it, so your cache clears automatically when you publish or edit.
  7. Check the bot and AI crawler settings. Make sure search engines and the AI crawlers you want, such as the ones behind ChatGPT search and Perplexity, aren't blocked. I let them in; being cited by AI assistants is part of being found.
  8. Turn on Crawler Hints under Caching.
  9. Test your home page and a post in PageSpeed Insights before and after.

What to leave alone

When Cloudflare isn't the right layer

If a site runs on a hosted builder such as Shopify, Squarespace, or Wix, the builder already provides a CDN and certificates. Cloudflare can still hold the domain and answer DNS, but keep those records gray and follow the builder's own connection instructions. Some managed WordPress hosts also bundle Cloudflare or their own CDN; ask before stacking two.

For the rest of the WordPress basics, see WordPress SEO 101, and for what the speed scores mean, my Core Web Vitals guide. Want Cloudflare set up on your site without the guesswork? Tell me about it.

Sources