Cloudflare Checkup
- Read-only assessment
Configure Checkup
Enter your Cloudflare API token and select an account to analyze.
Introducing the Vigilbase Platform
The cybersecurity operating system.
Connect the security tools you already pay for. Spin up personalised dashboards in minutes, with every log and event auditable and queryable in one place.
Acme Security OS
events | where severity >= medium | last 24h- Investigate Credential-stuffing burst against /login
- Fix Rate-limit rule deployed at the edge
- Verify Attack traffic down 98% in five minutes
About this checkup
This tool performs comprehensive security analysis of your Cloudflare account and all accessible zone configuration using the Cloudflare API. It checks governance, SSL/TLS, DNSSEC, WAF rules, legacy features, DDoS protection, and more.
Cloudflare Security DocsWhat we check
- - Account governance and MFA
- - Domain inventory and essentials
- - SSL/TLS and DNS security
- - WAF, rulesets, and managed rules
- - Legacy Firewall Rules, Page Rules, and rate limits
- - DDoS, bot, API, and page protection
- - Cloudflare One (Zero Trust): Access apps, identity providers, service tokens, Gateway policies, Gateway locations, and Cloudflare Tunnels
- - Performance and security settings
Cloudflare Checkup FAQ
What does the Cloudflare Checkup inspect?
It reviews the selected Cloudflare account and accessible zones for account governance, DNS, SSL/TLS, WAF and related configuration, plus supported Cloudflare One settings such as Access, Gateway and Tunnels.Coverage depends on the token permissions and features available in the account. A skipped check is not evidence that the setting is secure; review the reported gaps before drawing a conclusion.Managed WAF operations and change controlInternal access and Zero Trust
What access do I need to run a Cloudflare Checkup?
Use a Cloudflare API token with the requested read permissions for the accounts and zones you are authorized to review, select the account, and complete the required email verification.Limit the token to the intended resources and follow your organization’s access policy. Email verification does not grant permission to inspect someone else’s account.Tool access and verification requirementsPrivacy and data handling
Does the Cloudflare Checkup change my configuration?
No. The checkup reads configuration and produces findings; it does not apply the recommended changes to your account.Review proposed changes with the account and application owners. Agree the scope, approval, rollback and verification steps before implementing a recommendation.How we run Cloudflare after go-liveCompare Core, Priority and Critical
What is included in the free Cloudflare Checkup?
The free scan provides an initial grade and the available free findings. Additional account and domain findings, analysis and consultation options are shown in the report’s upgrade flow.Review the options shown for your report before purchasing. Neither a grade nor an upgraded report certifies the account or replaces ongoing monitoring and authorized configuration review.Compare the public security checksCompare Core, Priority and Critical