Nivoli Edge

Nivoli Edge

Details
View on WordPress

Nivoli Edge puts Cloudflare’s edge in front of your WordPress site and adds the WordPress layer Cloudflare alone does not have. Three things happen before a request reaches PHP:

Pages served from the edge. Full-page HTML caching with Surrogate-Key / Cache-Tag headers on every cacheable page and surgical purges when content changes: only the pages featuring the changed post refresh, never the whole cache. Logged-in visitors, carts and checkout always bypass. Works with Nivoli, Fastly, Cloudflare Enterprise, or your own webhook.

Images served from the edge. URLs rewrite through Cloudflare Image Resizing into right-sized WebP/AVIF variants on the fly. No uploads, no duplicate copies, no migration, no theme changes.

Attacks stopped before PHP. Ten shields run at the edge, earlier than any security plugin can: login, comment and search flood limits; XML-RPC block; login country lock; wp-admin IP lock; AI-crawler block; the stray-PHP lock (every .php request except the real WordPress entry points gets a 404); the WordPress surface lock (user enumeration via the REST users list, ?rest_route= and ?author=N, plus readme.html, license.txt, the installer and debug.log); and a security-headers pack. Wordfence or Sucuri keep inspecting what gets through. They simply see far less, and your server never boots PHP to refuse a request.

And the numbers to prove it, inside WP admin. What the edge answered and what it refused, broken and heavy images found from real traffic with one-click fixes, dead URLs with a 404 inbox, an audience view without a tracking script, and a monthly report by email.

One plugin, one API key. Everything that runs on your own server is free; the managed edge is the part you cannot self-host.

Free (everything that runs on your own infrastructure)

  • Images: URL rewriting through your own Cloudflare zone: right-sized AVIF/WebP via native WP filters (the_post_thumbnail, srcset, Gutenberg, WooCommerce), the_content + full-page scan, catch-all optimization.
  • Rules: presets + size-name / filename-glob bindings, one-click Size mapping from your theme’s registered sizes.
  • Page caching: tag headers + surgical tag purge on save/delete/comment, dispatched to Fastly, Cloudflare Enterprise, or your own webhook. Activity log + trace mode.
  • Audit & automation: coverage audit with weekly regression email, runtime-misses log, fake-image detection & repair, pre-warm on save and after purges, purge-failure alerts, weekly header self-test, printable client report.
  • Tools: ?cfdebug=1 overlay, live pipeline probe, Tinify source compression (your own API key), WP-CLI (status / activate / purge / probe / audit).

The managed service (optional)

Everything above is fully functional without an account. Connecting your Nivoli API key links the plugin to the managed edge, which adds what only a hosted service can do:

  • Edge shields, enforced before PHP: XML-RPC block, login country lock and the security-headers pack on every plan; login, comment and search flood limits, the stray-PHP lock, the WordPress surface lock, the wp-admin IP lock and the AI-crawler block from the Growth plan up. Each has an off switch, the two locks have a monitor mode that lists what blocking would have stopped, and an attack-surface strip shows what every shield did in the last 14 days. Underneath them, Cloudflare’s managed WAF rulesets, including the WordPress rule set, run in front of every managed site.
  • URL rules and the 404 inbox: block or redirect legacy paths at the edge with a cached 410 or 301, one rule per family of URLs, with per-rule fire counts; live 404s your server keeps answering are listed with one-click redirect or block.
  • Origin shield: if your server goes down, the edge keeps serving the last good copy of every cached page (up to 7 days) and emails you when the shield engages and when your origin recovers.
  • Managed page cache: full-page HTML caching with no Cloudflare Enterprise plan required. Bundled in every plan; fair-use, doesn’t touch your image quota. Static assets (stylesheets, scripts, fonts) served from the edge with URL versioning so purges reach browsers.
  • Managed image CDN: we run the Cloudflare zone; no CF account, plan, or DNS work. Custom hostname (img.yoursite.com), CDN-level watermarking.
  • Edge insights: usage & quota, cache-hit / bandwidth / origin-offload stats, 48-hour hourly traffic chart, Top URLs (most-missed / most-requested), audience (humans vs bots, countries, referrers, devices, no tracking script), broken-image alerts with “where used”, heaviest images with one-click Tinify shrinking, and a monthly report by email.
  • Edge controls: per-path cache duration (TTL), query-param manager, cache protection (purge-IP allowlist), and dynamic content (WooCommerce cart and checkout safety, plus how the edge treats the Cache-Control headers your site sends).
  • Agency: multi-site fleet view, one API key across sites, white-label client reports, priority support.

Requirements

  • Free: a Cloudflare zone with Image Resizing enabled for the image half (Pro+ plan or per-1000 pricing); a tag-aware edge (Fastly / CF Enterprise / your webhook) for the page-cache half. If Image Resizing isn’t enabled the rewritten URLs 404; the Tools tab has a one-click probe to verify.
  • Managed: none of the above; the managed edge provides both. Just an API key from your Nivoli account.

External services

The free tier’s core image rewriting sends no data to any external service; it only rewrites <img> URLs in your site’s HTML so browsers fetch through your own Cloudflare zone. Beyond that, the plugin contacts external services only for the specific, opt-in features listed below.

Nivoli managed edge (api at html-caching-admin.nivoli.workers.dev, dashboard at console.nivoli.com): used only if you enter an API key. On activation and on a daily background re-check it sends your API key, this site’s URL, the plugin version, and the list of broken-image file paths you have marked handled (so the monthly report can exclude them; these are addresses the CDN already sees in its own traffic) to validate the key and provision your managed CDN/page-cache tenant; it then reads back the aggregate usage statistics shown on the dashboard. If you configure monthly reports or alerts, the recipient email address and optional report branding (a name and logo URL) are stored with your account. No visitor data is ever sent. Terms: https://nivoli.com/terms · Privacy: https://nivoli.com/privacy

Cloudflare (api.cloudflare.com): used only if you configure the Cloudflare Enterprise page-cache backend with your own API token, to dispatch tag-based cache purges when your content changes. Terms: https://www.cloudflare.com/terms/ · Privacy: https://www.cloudflare.com/privacypolicy/

Fastly (api.fastly.com): used only if you configure the Fastly page-cache backend with your own API token, to dispatch surrogate-key purges on content change. Terms: https://www.fastly.com/terms/ · Privacy: https://www.fastly.com/privacy/

TinyPNG / Tinify (api.tinify.com): used only if you add your own Tinify API key and click “Shrink original” on an image, to compress that source file. Only the image you choose is sent. Terms & Privacy: https://tinify.com/terms

Details

Plugin code:
nivoli-edge
Plugin version:
1.48.3
Author:
Outdated:
No
WP version:
6.2 or higher
PHP version:
7.4 or higher
Test up to WP version:
7.1
Total installations:
0
Last updated:
2026-09-03
Rating:
Times rated:
0
cache
cloudflare
image-optimization
performance
security