Nivoli Edge puts Cloudflare's edge in front of your WordPress site and adds the WordPress layer on top. Attacks, floods, scanners and code changes are refused before a request reaches PHP, and the settings that refuse them live at the edge, behind an email confirmation, where a compromised WordPress cannot reach them. The same layer serves whole HTML pages and right-sized images from the node nearest each visitor. Keep your optimizer and your security plugin. We sit in front of both.
One real month on one real production site, measured at the edge (the screenshots on this page). Not averages or projections; your numbers depend on traffic shape and cache fit.

What it fixes
In your words, not ours. Each one has a section below with what we do about it.
Attacks and junk
The problemWordfence and Sucuri inspect requests inside WordPress, which means your server already booted PHP to decide it did not want the request. Login floods, XML-RPC abuse, scanners and AI crawlers all cost you compute first.



Takeovers
The problemOne plugin with a hole hands an attacker an administrator account, and no shield stops that: it arrives as a normal request. From there, every security plugin is a settings page they own. They switch it off, install a plugin of their own, edit a theme file, and you find out weeks later, if at all. Our settings page is theirs too.
So the edge refuses to take WordPress at its word. What still holds once someone is inside:


Slow pages
The problemEvery caching plugin still answers from, or renders on, your one server in one location. A reader in Sydney pays the round trip to Amsterdam on every page and every file the page pulls in.


Downtime
The problemA deploy goes wrong, PHP-FPM hangs, the host has a bad hour. Visitors get an error page, and if it lasts, Google starts dropping your pages from the index.
Origin Shield covers cached pages, which means public pages. A signed-in member's page views go to your server and are not covered. Read this before you buy if your audience logs in.
Broken and heavy images
The problemSomewhere in years of posts an image was renamed, a migration saved an error page as a .jpg, a featured image was deleted, and a 9 MB original is still going out full size. Nothing in WordPress tells you. A reader does, eventually.

Alerts ride along: a spike in failing images or a coverage drop is emailed when it happens.
Blind spots
The problemA plugin can only see what reaches PHP. Everything the CDN answered, everything it refused, every bot wave and every slow country, is invisible from inside WordPress.

Free or managed?
Everything that runs on your own server is free, forever, GPL, any number of sites, nothing phones home. Bring your own Cloudflare zone for images and your own Fastly, Cloudflare Enterprise or webhook purge backend for pages. The managed edge is the part you cannot self-host: we run the CDN and the page cache, and add what only the edge can measure and enforce.
| Capability | Your own Cloudflare (free) | Managed edge |
|---|---|---|
| Fast | ||
| Right-sized WebP/AVIF images | ✓ your zone with Image Resizing | ✓ zero setup |
| Full-page cache with surgical purge | ✓ Fastly / CF Enterprise / webhook | ✓ included, no Enterprise plan |
| Static assets from the edge, URL versioning | your zone's own rules | ✓ |
| Stays up | ||
| Origin Shield, incident history | not available | ✓ |
| Alerts: purge failures, broken images, coverage | ✓ | ✓ plus origin down and recovered |
| Defended | ||
| Ten shields before PHP | not available | ✓ the eight attack shields on every plan; AI-crawler block and wp-admin IP lock from Growth |
| Origin lock: the server refuses code changes that skipped the edge | not available | ✓ |
| Cloudflare managed WAF and DDoS absorption | ✓ your zone’s plan decides the rulesets | ✓ included, WordPress rule set on |
| URL rules, redirects, 404 inbox | not available | ✓ |
| Change lock and install lock: weakening a shield or changing code needs an emailed confirmation | not available | ✓ |
| Images | ||
| Broken images from edge traffic, Where used, Heaviest images with Tinify | not available | ✓ |
| Never-loading scan, fake-image repair, coverage audit, misses log | ✓ | ✓ |
| Measured | ||
| Edge analytics and audience | not available | ✓ |
| Monthly report, client reports, agency console | printable report only | ✓ client reports and console from Business |
Read this first if your members log in
Setup
From WordPress.org or the zip in any trial or plan email. Nothing phones home until you connect something.
Managed: paste the license key and the plugin provisions itself. Own zone: confirm the auto-detected image host and pick a purge backend.
One click fetches a real image and a real page through the whole pipeline and shows you the headers. The Dashboard then shows what the edge carries for you.
Questions? support@nivoli.com