The problem
Cloudflare protects your site only for traffic that goes through Cloudflare. If your server’s IP address leaks, attackers can send requests to it directly and skip Cloudflare’s protection entirely. The usual fixes require server or firewall access, which shared hosting providers often don’t give you.
The solution
Bypass Guard uses a shared secret to tell proxied traffic from direct traffic:
BYPASS-GUARD-TOKEN.403 Forbidden.Because the header is added at Cloudflare’s edge, a request that hits the origin directly arrives without it, unless the sender already knows the token.
Built-in safety against locking yourself out
Logging
Every blocked request is logged with its date and time, IP address, request method, URL and user agent. You can view and clear the log on the settings page. This helps you confirm that the filter works, spot scanners that found your server’s IP, and find legitimate services that were blocked by mistake.
The log keeps the 500 most recent entries, so a flood of requests cannot fill your database. Token values are never logged, not even incorrect ones.
The logged IP address is the one that actually connected to your server. Headers such as CF-Connecting-IP or X-Forwarded-For are ignored for blocked requests, because anyone bypassing Cloudflare can set them to any value.
Is this plugin right for you?
This plugin is a fallback for when better options are not available. Check with your host whether you can use either of these first:
Both work at the server or network level, protect everything (including images and cached pages) and do not depend on a shared secret. Many shared hosting plans allow neither, and that is the situation this plugin is built for. You can also use it alongside them as an extra layer.
Limitations
The plugin runs inside WordPress, so it only sees requests that WordPress itself handles:
advanced-cache.php drop-in and server-level caches such as LiteSpeed Cache, Varnish or nginx FastCGI cache. Cached pages may still be served to direct requests.If you can edit your server configuration or .htaccess file, checking the same header there as well closes the first two gaps.
Source code and contributions
Bypass Guard for Cloudflare is developed openly on GitHub. Bug reports, feature requests and pull requests are welcome:
https://github.com/agabor/bypass-guard-for-cloudflare
Disclaimer
Bypass Guard for Cloudflare is an independent open source project. It is not affiliated with, endorsed by or supported by Cloudflare, Inc. “Cloudflare” is a trademark of Cloudflare, Inc. and is used here only to describe the service this plugin works with. No Cloudflare logos, artwork or documentation are included in this plugin.