Free tool: The Cloudflare Hardening Checklist
Every hardening step from the book in one interactive list: tick through it for each site you protect, with progress saved in your browser. Open the checklist.
How to Stop wp-login Brute Force Attacks with Cloudflare (Free Plan)
Bots guess passwords on wp-login.php around the clock. Turn them away before they reach your server with one rate limiting rule, a custom rule for xmlrpc.php, and Bot Fight Mode.
How to Block WordPress Comment Spam Before It Reaches Your Site
Spam scripts skip your page and post straight to wp-comments-post.php. Put Turnstile on the form, a Managed Challenge on the endpoint, and watch the moderation queue go quiet.
Cloudflare's Free Plan: The Security You Actually Get
Unmetered DDoS protection, free SSL, a managed WAF ruleset, custom rules, and Bot Fight Mode: the honest inventory of the $0 tier, what stays paid, and what to switch on first.
What Is xmlrpc.php and Why Is It Being Hammered?
WordPress's old remote-control socket lets one request carry hundreds of password guesses. What the file does, who still needs it, and the one free rule that shuts the door.
Security Plugins vs the Edge: What Runs Where (and Why It Matters)
A plugin blocks the attack after your server has already paid for it; the edge blocks it before it arrives. Follow one malicious request to see what each layer should own.
Prefer the whole playbook in one sitting?
The ebook walks you from connecting your domain to a complete hardening checklist: 22 chapters, real dashboard screenshots, honest free-versus-paid flags, and a full WordPress case study. See the overview or start with the free preview chapter.