Website Security
Cloudflare Setup & Hardening
We put your website behind Cloudflare's global security network — configuring DNS, SSL, WAF rules, bot protection, and caching. Your site goes from exposed to enterprise-grade protected in under 2 hours.
How It Works
We Scan Your Current Setup
Before touching anything, we run a full external assessment — SSL grade, security headers, exposed files, DNS records, and subdomain enumeration. This establishes your baseline and tells us exactly what needs to change.
We Migrate DNS to Cloudflare
Your nameservers move to Cloudflare. Every existing DNS record is preserved and verified — MX records for email, A records for subdomains, CNAME records for services. We confirm propagation before proceeding. Typical downtime: zero.
We Harden the Security Stack
SSL Full (Strict), HSTS with preload, Bot Fight Mode, page rules for admin paths, security headers, browser integrity checks, script monitoring. Every setting is configured with your specific stack in mind — not default templates.
We Verify Everything
Post-hardening verification: every sensitive path tested, SSL grade confirmed, headers re-scanned, email delivery verified. You get a completion report documenting every change with before/after proof.
Before & After
Before Cloudflare
- Origin server IP exposed to attackers
- No DDoS protection
- No WAF rules blocking exploits
- Bot traffic consuming server resources
- SSL managed manually (often expired)
- No security headers (HSTS, CSP, etc.)
- Admin paths (/wp-admin) unprotected
- Legacy subdomains leaking origin IP
After Our Setup
- Origin IP hidden behind Cloudflare proxy
- Enterprise-grade DDoS mitigation
- Custom WAF rules + managed rulesets
- Bot Fight Mode blocking scrapers
- SSL Full (Strict) + auto-renewing certs
- All security headers configured (grade A)
- Admin paths cached bypassed + high security
- Legacy DNS records cleaned up
What We Configure
Every setting tuned to your specific infrastructure — not a one-size-fits-all template.
DNS Migration
Nameservers moved to Cloudflare. All existing records (MX, A, CNAME, TXT) preserved, verified, and proxied where appropriate. Email records set to DNS-only to prevent mail disruption.
SSL Full (Strict)
End-to-end encryption with origin certificate validation. TLS 1.2 minimum enforced. Always Use HTTPS + Automatic HTTPS Rewrites enabled. No more mixed content warnings.
HSTS + Security Headers
12-month max-age with preload and subdomains. X-Content-Type-Options, X-Frame-Options, Referrer-Policy, CSP — all configured at the edge for instant global coverage.
Bot Protection
Bot Fight Mode activated. Browser Integrity Check enabled. Script monitoring for injected malware/skimming scripts. Email Address Obfuscation to prevent scraping.
Page Rules
Cache bypass for /wp-admin and /wp-login.php to prevent session lockouts. High security level on authentication paths. Performance optimization for static assets.
DNS Cleanup
Remove legacy subdomains (cpanel, webmail, ftp) that expose your origin IP. Remove unused mail records from previous hosting. Tighten your DNS footprint.
Sample Completion Report
Every engagement includes a completion report documenting what was changed and verified.
Website Infrastructure Hardening
Cloudflare migration, SSL/TLS configuration, security stack activation, and .htaccess hardening.
Overview
Comprehensive website infrastructure hardening across the client's domain. The work included DNS migration to Cloudflare, SSL/TLS configuration, security stack activation, PHP runtime upgrade, and Apache .htaccess hardening. A full backup was completed before any server-side changes. The site remained functional throughout all changes.
| Control | Before | After | Status | |
|---|---|---|---|---|
| Nameservers | ns1.bluehost.com | → | cloudflare.com | Complete |
| SSL/TLS Mode | Not set | → | Full (Strict) | Complete |
| HSTS | 6mo, no preload | → | 12mo + preload + subs | Complete |
| Bot Protection | Off | → | Bot Fight Mode ON | Complete |
| PHP Version | 7.4 (EOL 2022) | → | 8.2 | Complete |
| Sensitive Files | Accessible | → | All 403 (blocked) | 6/6 pass |
What You Get
- Full DNS migration to Cloudflare with record-by-record verification
- SSL Full (Strict) with HSTS preload and minimum TLS 1.2
- Bot Fight Mode and Browser Integrity Check enabled
- Page rules for admin path protection and cache optimization
- Legacy DNS records and exposed subdomains cleaned up
- Security headers configured at the edge (CSP, X-Frame-Options, etc.)
- PHP version upgrade if needed (EOL versions replaced)
- .htaccess hardening (XML-RPC blocked, directory listing disabled, upload execution blocked)
- Post-hardening verification with HTTP path testing
- Completion report documenting every change with before/after proof