Nivoli Edge puts Cloudflare’s edge in front of your WordPress site and adds the WordPress layer Cloudflare alone does not have. Three things happen before a request reaches PHP:
Pages served from the edge. Full-page HTML caching with Surrogate-Key / Cache-Tag headers on every cacheable page and surgical purges when content changes: only the pages featuring the changed post refresh, never the whole cache. Logged-in visitors, carts and checkout always bypass. Works with Nivoli, Fastly, Cloudflare Enterprise, or your own webhook.
Images served from the edge. URLs rewrite through Cloudflare Image Resizing into right-sized WebP/AVIF variants on the fly. No uploads, no duplicate copies, no migration, no theme changes.
Attacks stopped before PHP. Ten shields run at the edge, earlier than any security plugin can: login, comment and search flood limits; XML-RPC block; login country lock; wp-admin IP lock; AI-crawler block; the stray-PHP lock (every .php request except the real WordPress entry points gets a 404); the WordPress surface lock (user enumeration via the REST users list, ?rest_route= and ?author=N, plus readme.html, license.txt, the installer and debug.log); and a security-headers pack. Wordfence or Sucuri keep inspecting what gets through. They simply see far less, and your server never boots PHP to refuse a request.
And the numbers to prove it, inside WP admin. What the edge answered and what it refused, broken and heavy images found from real traffic with one-click fixes, dead URLs with a 404 inbox, an audience view without a tracking script, and a monthly report by email.
One plugin, one API key. Everything that runs on your own server is free; the managed edge is the part you cannot self-host.
the_post_thumbnail, srcset, Gutenberg, WooCommerce), the_content + full-page scan, catch-all optimization.?cfdebug=1 overlay, live pipeline probe, Tinify source compression (your own API key), WP-CLI (status / activate / purge / probe / audit).Everything above is fully functional without an account. Connecting your Nivoli API key links the plugin to the managed edge, which adds what only a hosted service can do:
The free tier’s core image rewriting sends no data to any external service; it only rewrites <img> URLs in your site’s HTML so browsers fetch through your own Cloudflare zone. Beyond that, the plugin contacts external services only for the specific, opt-in features listed below.
Nivoli managed edge (api at html-caching-admin.nivoli.workers.dev, dashboard at console.nivoli.com): used only if you enter an API key. On activation and on a daily background re-check it sends your API key, this site’s URL, the plugin version, and the list of broken-image file paths you have marked handled (so the monthly report can exclude them; these are addresses the CDN already sees in its own traffic) to validate the key and provision your managed CDN/page-cache tenant; it then reads back the aggregate usage statistics shown on the dashboard. If you configure monthly reports or alerts, the recipient email address and optional report branding (a name and logo URL) are stored with your account. No visitor data is ever sent. Terms: https://nivoli.com/terms · Privacy: https://nivoli.com/privacy
Cloudflare (api.cloudflare.com): used only if you configure the Cloudflare Enterprise page-cache backend with your own API token, to dispatch tag-based cache purges when your content changes. Terms: https://www.cloudflare.com/terms/ · Privacy: https://www.cloudflare.com/privacypolicy/
Fastly (api.fastly.com): used only if you configure the Fastly page-cache backend with your own API token, to dispatch surrogate-key purges on content change. Terms: https://www.fastly.com/terms/ · Privacy: https://www.fastly.com/privacy/
TinyPNG / Tinify (api.tinify.com): used only if you add your own Tinify API key and click “Shrink original” on an image, to compress that source file. Only the image you choose is sent. Terms & Privacy: https://tinify.com/terms