Is the Cloudflare bundled with your hosting good enough?

Many hosting plans advertise that they “include Cloudflare” or even “Cloudflare Enterprise”. Is it the same thing as having your own Cloudflare account? The short answer: usually not. The difference is that you get an on/off switch or basic configuration, while the dashboard, the firewall rules and the advanced settings stay with the host. 

 

Lets have a look at the features your own Cloudflare Account brings to the table for your website and the problems it solves. I cannot decide for you but I can tell you that these are the reasons I choose to setup a dedicated Cloudflare account to protect my clients websites from hackers, spam, unwanted traffic and unnecessary hosting costs. 

What Cloudflare does?

Cloudflare sits in front of your website as a layer that all traffic passes through before it reaches your website. It is an enterprise level solution that is becoming industry standard for any website online as I described in Modern WordPress Security: The Habits Site Owners Are Adopting. It bundles a CDN that serves your pages from locations near your visitors, free SSL, a firewall that inspects every request and bot and DDoS protection that absorbs floods of unwanted traffic that could otherwise overload your website. Around a fifth of all websites run behind cloudflare and the good news is that the free tier is fully functional .

 

What “includes Cloudflare” usually means

Hosts bundle Cloudflare in three different ways, and they are not equally useful.

 

The first is a toggle in the control panel. Many shared hosts offer a Cloudflare integration, often through cPanel, that routes your traffic through Cloudflare’s network with one click. You get the basic CDN and some protection, but rarely the Cloudflare dashboard itself, and almost never the ability to write your own rules.

 

The second is an enterprise bundle. Some managed WordPress hosts build Cloudflare’s paid Enterprise tier into their platform: Kinsta includes it with every plan, WP Engine sells it as the Global Edge Security add-on, and Cloudways offers it for about $5 per month per domain. These bundles are genuinely strong, with better DDoS absorption and a fuller managed firewall than a free personal account gets. But the model is the same: the host holds the steering wheel, and anything specific goes through their support queue. 

The third is marketing. “Our infrastructure is protected by Cloudflare” describes the host’s own network, not your website. It gives you nothing to configure and often nothing at all.

 

The switch versus the control panel: what the bundle hides

The difference between the bundle and your own account is in the granular settings, that may seem overwhelming, but using them to your advantage can save you real money and unnecessary trouble. Even with your own free account you get:

 

  • Custom firewall rules. You can allow only your own IP address to reach the login page, challenge traffic from countries you never do business with, or block a URL that is being hammered. The free plan includes five active custom rules, which is enough for a typical WordPress site.

 

  • Rate limiting. If one visitor requests your login page thirty times a minute, which is rarely a human being, Cloudflare can block them automatically. The free plan includes one rate-limiting rule; the login page is the right place for it.

 

  • A lock on wp-admin. Cloudflare Zero Trust can put an identity check in front of your login page, free for up to 50 users, so brute-force bots never even see the form. 

 

  • Stop AI crawlers. Cloudflare shows you which AI bots visit your site and lets you decide, per crawler, who gets in. As I wrote in Accessibility? The shortcut to an AI-ready website, AI assistants are becoming a real source of visitors and customers, so the sensible setup is usually to welcome the assistants people actually use and block the scrapers that only take. The bundle makes that choice for you.

 

  • Turnstile for your forms. Cloudflare’s invisible CAPTCHA replacement verifies visitors in the background, so real people are not asked to click fire hydrants while your contact form stays clear of spam. Fewer hurdles at the form also means fewer abandoned enquiries. It is free, but it needs API keys from your own account.

 

  • Visibility. The dashboard shows how many requests were served from cache, how many threats were blocked and where your traffic comes from. It is the part of the iceberg under the water, the traffic Google Analytics never sees because it was filtered before it reached your pages. With a bundle, you will never see this useful dashboard.

 

Cloudflare Analytics - Web Performance and Security Insights
Cloudflare Analytics – Web Performance and Security Insights for your website

 

Portability

It sounds easier to have one less account, until you need to change your web hosting provider. Your own Cloudflare account is tied to your domain’s nameservers, not to your hosting contract. When you move to a new host, you update one DNS record in your dashboard and the switch happens in seconds: same firewall rules, same settings.

The bundled version belongs to the host. Leave, and the protection, the configuration and any tuning the host did on your behalf all stay behind. 

When the bundle is good enough

To be fair to the hosting companies that package the Cloudflare bundles, there are sites and projects where they are exactly the right fit. Your own account is still one more thing you manage, and a carelessly written rule can lock out some visitors. If you would never open the dashboard anyway, the switch buys you little.

Get your own account when you want any of the controls above, when your site takes bookings, orders or leads and downtime immediately costs you money. When you manage more than one site, or when you simply do not want your security response time to depend on someone else’s support queue.

Setting up your own account

Moving your website to your own Cloudflare account is mostly automated process with just few steps:

 

  1. Create a free account at cloudflare.com and add your domain. Cloudflare scans your existing DNS records and imports them.
  2. Before going further, compare the imported records with the DNS panel at your host or registrar, especially the MX and TXT records that carry your email. A missed record here is the reason some people’s email stops after switching; five minutes of comparing prevents it.
  3. At your domain registrar, replace the nameservers with the two Cloudflare gives you. The change usually takes minutes to a few hours.
  4. If your host has a Cloudflare toggle, switch it off, so traffic does not pass through two proxies.
  5. In the SSL/TLS settings, set the encryption mode to “Full (strict)”. It prevents the redirect loops and “too many redirects” errors that make many first Cloudflare setups frustrating.
  6. Switch on the free basics: Always Use HTTPS and Bot Fight Mode.
  7. Add your first two firewall rules: a challenge on the login page for everyone except your own IP address, and your one free rate-limiting rule on the same URL.

 

From there the layer runs on its own, and everything else in the dashboard is something you can explore when a need appears.

The takeaway

The bundled Cloudflare is a decent always-on layer but having your own account is about control and portability, and it costs nothing. The decision is simple – if you never want to touch a setting and are happy to depend on your host’s support queue when something happens, keep the bundle; if you want to be able to act with full flexibility, become a Cloudflare Owner.

by Jan Cerny
I have worked with WordPress websites for over 10 years, focusing on security, scalability, and integrations with other systems. I focus on closing the bridge between technology and real world website needs.
Share this post

Related posts

view all