Cloudflare Audit
Cloudflare security and configuration audit workflow. Inspects zone settings, DNS records, WAF rules, Workers, and cache configuration, then generates a severity-rated report with findings and recommendations.
Quick Start
swamp extension pull @webframp/cloudflare-audit
swamp model create @webframp/cloudflare/zone cf-zone \
--global-arg apiToken=CLOUDFLARE_API_TOKEN
swamp model create @webframp/cloudflare/dns cf-dns \
--global-arg apiToken=CLOUDFLARE_API_TOKEN --global-arg zoneId=ZONE_ID
swamp model create @webframp/cloudflare/waf cf-waf \
--global-arg apiToken=CLOUDFLARE_API_TOKEN --global-arg zoneId=ZONE_ID
swamp model create @webframp/cloudflare/worker cf-worker \
--global-arg apiToken=CLOUDFLARE_API_TOKEN --global-arg accountId=ACCOUNT_ID
swamp model create @webframp/cloudflare/cache cf-cache \
--global-arg apiToken=CLOUDFLARE_API_TOKEN --global-arg zoneId=ZONE_ID
swamp workflow run @webframp/cloudflare-audit --input zoneId=ZONE_IDChecks Performed
- SSL mode (off/flexible/full/strict)
- Always Use HTTPS enabled
- Development mode disabled
- Zone paused/active status
- Firewall rules present and active
- WAF managed rulesets enabled
- DNS records proxied (origin IP exposure)
- Dangling CNAMEs (subdomain takeover risk)
- CAA records present
- Worker scripts bound to routes
- Cache level and hit rate
2026.07.24.1
Changed: Bump dependency pin:
- @webframp/cloudflare 2026.07.18.1 → 2026.07.18.2
Cloudflare security and configuration audit. Inspects zone settings, DNS records, WAF rules, Workers, and cache config, then generates a severity-rated report with findings and recommendations.
Analyzes Cloudflare zone configuration for security, DNS hygiene, WAF coverage, worker health, and cache performance
2026.07.20.1
Changed: Refreshed the dependency pin to the latest published release. No behavioral changes to the audit workflow or report.
Upgrade note: Bumps @webframp/cloudflare 2026.06.26.1 → 2026.07.18.1,
pulled automatically with this extension.
updated dependencies
2026.07.18.1
Changed: Version bump only, no code changes.
2026.06.26.1
Changed: Audit reports now include cache hit-rate and security event findings that were previously missing. The underlying cloudflare extension's GraphQL methods were silently failing — now that they work, the audit report produces complete results.
Upgrade note: Requires @webframp/cloudflare@2026.06.26.1. Pull both extensions together:
swamp extension pull @webframp/cloudflare
swamp extension pull @webframp/cloudflare-auditupdated dependencies
updated dependencies
updated platforms
- Has README or module doc2/2earned
- README has a code example1/1earned
- README is substantive1/1earned
- Most symbols documented1/1earned
- No slow types (deprecated)1/1earned
- Dependencies pass trust audit2/2earned
- Has description1/1earned
- Platform support declared (or universal)2/2earned
- License declared1/1earned
- Verified public repository2/2earned