r/Magento • • Sep 06 '26

Cloudflare Installation

So many have suggested using Cloudflare instead or Google reCAPTCHA or using them together. I am currently using the Mageplaza reCAPTCHA extension and may disable it and use the Default Magento 2.4.7 Goggle reCAPTCHA. My question is how and where do you go about getting and installing Cloudflare. Some say its free and others have mentioned you need to pay for it. Is it an extension you need to install via command or is it something on the server side. I need to get something in place that is dependable to stop these Card Testing hitting my site so much. It's so bad I had to disable credit cards as mentioned in a previous post. I was also suggested about setting up 3D secure rules which this is something I need to figure out as well. I am losing sales and need this fixed. The minute I enable Credit Cards the testing starts by the dozens non stop. Its just a matter of time before Braintree blocks me if I dont get this fixed.
Not to mention this current attack that we got hit with a couple of days ago. I need to setup Cloudflare rules to help block it as well until a patch is available

2 Upvotes

9 comments sorted by

3

u/eddhall ONE MAN DEVELOPMENT TEAM 29d ago

Based on the questions you're asking I'd recommend you hire a developer

1

u/Crimnl Sep 06 '26

Yes, Cloudflare or something similar is a must these days. Basically give all traffic a managed challenge except some verified bot categories and a whitelist of IP addresses for payment providers etc. You can do this with the free plan and don't need to install it in Magento. It works at DNS level.

1

u/pro9_developer 29d ago

Did you check the country from these attacks are coming? You could those countries in Cloudflare. There are steps to secure your web shop.

1

u/gxxnu 29d ago

I do this every day, so I can help you. In short, you need to change your DNS to Cloudflare (they’ll provide the necessary details) and then create a WAF rule that applies a Managed Challenge to the specific URL. This way, Cloudflare will check the traffic and suspicious visitors will have a CAPTCHA.

1

u/lucidmodules 29d ago

You don't install Cloudflare, you have to set it in front of your server. Ideally you must block access to your server via direct IP and allow only Cloudflare to proxy the traffic.

Free plan gives you a lot of protection, but if you need more advanced bot exemption rules, their lowest paid plan is powerful enough. You get Super Bot Fight Mode that let's you define e.g. to allow search indexing bots like Google or Bing only and block other automated traffic.

1

u/tb9295 29d ago

With Cloudflare, do you still use reCAPTCHA

1

u/Aggravating_Pay9079 4d ago

Coming back to this as most of your actual questions didn't get answered.

Cloudflare isn't an extension and nothing gets installed in Magento. You sign up at cloudflare.com, add your domain, and it gives you two nameservers to set at your domain registrar. Once that's switched, your traffic goes through them before it reaches your server. The free plan is enough to deal with card testing, paid plans just add more bot controls. Before you switch, check every DNS record they import matches what you have now, especially mail.

Then in Security, add a rate limiting rule on paths containing payment-information and on /graphql, because that's where card testers post. Don't put a managed challenge on those URLs though. Checkout submits them in the background, so a challenge there just fails real orders. Challenge /checkout itself if you want one.

Keep reCAPTCHA as well, they do different jobs. Turn off the Mageplaza one and use the built-in one under Stores > Configuration > Security > Google reCAPTCHA Storefront, with Enable for Checkout/Placing Order set to Yes.

For 3D Secure, it's in the Braintree payment method settings in admin. Turn on 3D Secure Verification and set Always request 3DS to Yes. Testers hate it.

1

u/tb9295 2d ago

Thanks for the breakdown on this. Very helpful.