- Visitors 24h
- –
- Page views
- –
- Bandwidth
- –
- Blocked
- –
- Bot hits
- –
- CPU now
- –
Protection
Under attack challenges every visitor with a proof-of-work page a browser solves in about a second; scripts can't.
Performance & scaling
Replicas are rolled one set at a time with no downtime. Each replica gets the full memory and CPU shown.
Replicas follow whichever target asks for the most. Workers busy counts requests waiting for a PHP worker too: it catches sites that wait on slow APIs or queries while their CPU stays low. Response ms adds a replica while 95% of PHP responses take longer and the site is busy.
Pages that ask WordPress whether the visitor is on a phone are always cached separately for phones and computers; separate mobile cache does it for every page, for themes that detect phones on their own. Editors also get a Purge cache button in WordPress's admin bar.
JPEG and PNG uploads get smaller AVIF/WebP copies, served to browsers that accept them at the same URL. New uploads are converted within a minute, everything else nightly. AVIF is the smallest but slow to make.
Insights
CDN
Put the site behind Cloudflare's free CDN: static files are served from a data centre near each visitor. Real visitor IPs reach the shield and analytics automatically. With an API token, Cloudflare's cache is also purged whenever the site's cache is.
- Add the domain to Cloudflare and turn the proxy on (orange cloud) for its A/AAAA records.
- Set SSL/TLS to Full (strict). Flexible causes an endless redirect.
- Create an API token (My Profile → API Tokens) with Zone: Read, Cache Purge: Purge and, optionally, Zone Settings: Read (and Cache Rules: Edit for edge caching), limited to this zone.
The site stays on this server; its CSS, JavaScript, images and fonts are linked to the CDN's hostname, which fetches them from here once and serves them from near each visitor.
- Create a pull zone whose origin is
. - Give it a hostname of its own (e.g.
, a CNAME to the zone) with TLS on. - For purges, the bunny.net API key (Account settings → API) and the pull zone's ID.
Edge caching: Cloudflare keeps pages the page cache serves (never for logged-in visitors, carts or other personal cookies) and is purged with it. Those visits no longer reach this server, so they skip the shield and aren't counted in the statistics.
Uploads offload
Copies the media library to S3-compatible storage (AWS S3, Cloudflare R2, Backblaze B2, MinIO, …): new uploads within a minute, everything nightly; deleted uploads are deleted there too. Uploads missing on this server are served from the storage's public URL, so local copies can be removed after a while to save disk.
- Create a bucket and a key that may write, read and delete objects under the prefix (and nothing else).
- Make the prefix publicly readable (a bucket policy allowing
s3:GetObject, not listing), or put a CDN in front of it. - Saving writes a test object, fetches it through the public URL and deletes it; settings that don't work aren't saved.
Local copies are only removed once the bucket holds an identical copy that the public URL serves. Offloaded images whose local copy was removed are served in their original format (AVIF/WebP negotiation needs the file on disk). Deleting the site leaves the bucket's objects in place.
Security
Per visitor address. Challenges are a proof-of-work page a browser solves in about a second; scripts can't.
Plugins
Checks each plugin against wordpress.org (closed or abandoned), compares its files with the published release (modified or nulled copies) and measures what it costs to load the front page. Runs nightly; takes 10–30 seconds.
Updates
Every update takes a snapshot first; if the site stops working afterwards it is restored automatically.