Bypass Guard for Cloudflare

Bypass Guard for Cloudflare

Details
View on WordPress

The problem

Cloudflare protects your site only for traffic that goes through Cloudflare. If your server’s IP address leaks, attackers can send requests to it directly and skip Cloudflare’s protection entirely. The usual fixes require server or firewall access, which shared hosting providers often don’t give you.

The solution

Bypass Guard uses a shared secret to tell proxied traffic from direct traffic:

  1. The plugin generates a random secret token.
  2. You add a rule in Cloudflare that attaches this token to every request it forwards, in a header called BYPASS-GUARD-TOKEN.
  3. The plugin checks each WordPress request. If the header is missing or wrong, the request is answered with 403 Forbidden.

Because the header is added at Cloudflare’s edge, a request that hits the origin directly arrives without it, unless the sender already knows the token.

Built-in safety against locking yourself out

  • The filter cannot be switched on until the plugin has seen at least one request carrying the correct token. This proves your Cloudflare rule works before anything gets blocked.
  • Until then, the settings page shows a step by step setup guide with copy buttons for the header name and token.
  • WP-CLI commands are never filtered, so you always keep command line access.
  • Deactivating the plugin always switches the filter off.

Logging

Every blocked request is logged with its date and time, IP address, request method, URL and user agent. You can view and clear the log on the settings page. This helps you confirm that the filter works, spot scanners that found your server’s IP, and find legitimate services that were blocked by mistake.

The log keeps the 500 most recent entries, so a flood of requests cannot fill your database. Token values are never logged, not even incorrect ones.

The logged IP address is the one that actually connected to your server. Headers such as CF-Connecting-IP or X-Forwarded-For are ignored for blocked requests, because anyone bypassing Cloudflare can set them to any value.

Is this plugin right for you?

This plugin is a fallback for when better options are not available. Check with your host whether you can use either of these first:

  • Authenticated Origin Pulls (mutual TLS): your web server only accepts connections that present Cloudflare’s client certificate.
  • A firewall that only allows Cloudflare’s IP ranges: your server refuses connections from anywhere else.

Both work at the server or network level, protect everything (including images and cached pages) and do not depend on a shared secret. Many shared hosting plans allow neither, and that is the situation this plugin is built for. You can also use it alongside them as an extra layer.

Limitations

The plugin runs inside WordPress, so it only sees requests that WordPress itself handles:

  • Static files (images, CSS, JavaScript, uploads) are usually served directly by the web server and stay reachable.
  • Page caches that run before plugins load are not filtered. This includes caching plugins using an advanced-cache.php drop-in and server-level caches such as LiteSpeed Cache, Varnish or nginx FastCGI cache. Cached pages may still be served to direct requests.
  • The token is a shared secret. Anyone who learns it can get past the filter. It is visible to site administrators, to anyone with database access and to anyone with access to your Cloudflare account.

If you can edit your server configuration or .htaccess file, checking the same header there as well closes the first two gaps.

Source code and contributions

Bypass Guard for Cloudflare is developed openly on GitHub. Bug reports, feature requests and pull requests are welcome:

https://github.com/agabor/bypass-guard-for-cloudflare

Disclaimer

Bypass Guard for Cloudflare is an independent open source project. It is not affiliated with, endorsed by or supported by Cloudflare, Inc. “Cloudflare” is a trademark of Cloudflare, Inc. and is used here only to describe the service this plugin works with. No Cloudflare logos, artwork or documentation are included in this plugin.

Details

Plugin code:
bypass-guard-for-cloudflare
Plugin version:
1.0.0
Outdated:
No
WP version:
6.2 or higher
PHP version:
7.4 or higher
Test up to WP version:
7.1.2
Total installations:
0
Last updated:
2026-10-05
Rating:
Times rated:
0
cloudflare
firewall
header
origin
security