Cloudflare Firewall Part 2 - Rules to filter data type

Created on: | Last updated on:

It's important to filter data types and allow only what you can actually use. Bots always search for files like .zip or .sql that could contain private or security information. For this, we identify first that it's a URI path with a dot (http.request.uri.path contains ".") and then by exclusion we define what we want to allow, by adding a negative match.

With this approach, it's very important to check often if you might use any data type that is not on the list and firewall will block false positives.

I don't include on allow list .txt and .xml, why? Because .txt is the main source of information for hackers on what version of theme/plugin you're using, therefore they can detect vulnerabilities and exploit them. Robots.txt, ads.txt and similar should be whitelisted if you don't set in Allow rulest known bot to get unrestricted access.
XML as well is very often used to identify pages that you can't crawl into and provides information for a hacker or malicious crawlers. Therefore I never allow unknown bots to access it, and I recommend making sure that for known bots you whitelist access by adding the path to Allow ruleset.

Data type .html in WordPress is not used, and accessing it will only required linke for Google or Pinterest for domain authorization purposes. ".html" should be whitelisted for known bots

(http.request.uri.path contains "." 
and not ends_with(http.request.uri.path, ".php") 
and not ends_with(http.request.uri.path, ".aac") 
and not ends_with(http.request.uri.path, ".css") 
and not ends_with(http.request.uri.path, ".eot") 
and not ends_with(http.request.uri.path, ".gif") 
and not ends_with(http.request.uri.path, ".jpeg") 
and not ends_with(http.request.uri.path, ".jpg") 
and not ends_with(http.request.uri.path, ".js") 
and not ends_with(http.request.uri.path, ".less") 
and not ends_with(http.request.uri.path, ".mp3") 
and not ends_with(http.request.uri.path, ".mp4") 
and not ends_with(http.request.uri.path, ".ogg") 
and not ends_with(http.request.uri.path, ".otf") 
and not ends_with(http.request.uri.path, ".pdf") 
and not ends_with(http.request.uri.path, ".png") 
and not ends_with(http.request.uri.path, ".svg") 
and not ends_with(http.request.uri.path, ".ico") 
and not ends_with(http.request.uri.path, ".ttf") 
and not ends_with(http.request.uri.path, ".webp") 
and not ends_with(http.request.uri.path, ".woff") 
and not ends_with(http.request.uri.path, ".woff2"))

Leave a Reply

Your email address will not be published. Required fields are marked *

WP Speed Doctor Copyright © 2026
The WordPress® trademark is the intellectual property of the WordPress Foundation, and the Woo® and WooCommerce® trademarks are the intellectual property of WooCommerce, Inc. Uses of the WordPress®, Woo®, and WooCommerce® names in this website are for identification purposes only and do not imply an endorsement by WordPress Foundation or WooCommerce, Inc. wpspeeddoctor.com is not endorsed or owned by, or affiliated with, the WordPress Foundation or WooCommerce, Inc.
Top