{"id":340850,"date":"2026-09-03T19:12:18","date_gmt":"2026-09-03T19:12:18","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/nivoli-edge\/"},"modified":"2026-09-23T14:06:04","modified_gmt":"2026-09-23T14:06:04","slug":"nivoli-edge","status":"publish","type":"plugin","link":"https:\/\/es.wordpress.org\/plugins\/nivoli-edge\/","author":23529952,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"1.79.1","stable_tag":"1.79.1","tested":"7.1.2","requires":"6.2","requires_php":"7.4","requires_plugins":null,"header_name":"Nivoli Edge","header_author":"Nivoli","header_description":"Serve your whole site from the edge: images right-sized and format-negotiated through Cloudflare Image Resizing, plus full-page HTML caching with surgical tag-based purge. Your whole site, served from the edge.","assets_banners_color":"301e66","last_updated":"2026-09-23 14:06:04","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"https:\/\/nivoli.com\/nivoli-edge","header_author_uri":"https:\/\/nivoli.com","rating":0,"author_block_rating":0,"active_installs":0,"downloads":621,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"1.48.2":{"tag":"1.48.2","author":"calimonk","date":"2026-09-03 19:12:05","revision":3680272},"1.48.3":{"tag":"1.48.3","author":"calimonk","date":"2026-09-03 19:31:40","revision":3680290},"1.49.0":{"tag":"1.49.0","author":"calimonk","date":"2026-09-04 07:51:53","revision":3680823},"1.50.0":{"tag":"1.50.0","author":"calimonk","date":"2026-09-04 07:51:53","revision":3680823},"1.50.1":{"tag":"1.50.1","author":"calimonk","date":"2026-09-04 07:51:53","revision":3680823},"1.50.2":{"tag":"1.50.2","author":"calimonk","date":"2026-09-04 07:51:53","revision":3680823},"1.51.0":{"tag":"1.51.0","author":"calimonk","date":"2026-09-04 09:51:13","revision":3680993},"1.51.1":{"tag":"1.51.1","author":"calimonk","date":"2026-09-04 09:51:13","revision":3680993},"1.52.0":{"tag":"1.52.0","author":"calimonk","date":"2026-09-04 13:33:54","revision":3681289},"1.52.1":{"tag":"1.52.1","author":"calimonk","date":"2026-09-04 13:33:54","revision":3681289},"1.52.2":{"tag":"1.52.2","author":"calimonk","date":"2026-09-04 13:33:54","revision":3681289},"1.53.0":{"tag":"1.53.0","author":"calimonk","date":"2026-09-04 13:33:54","revision":3681289},"1.53.1":{"tag":"1.53.1","author":"calimonk","date":"2026-09-04 13:33:54","revision":3681289},"1.54.0":{"tag":"1.54.0","author":"calimonk","date":"2026-09-04 13:33:54","revision":3681289},"1.54.1":{"tag":"1.54.1","author":"calimonk","date":"2026-09-04 13:33:54","revision":3681289},"1.55.0":{"tag":"1.55.0","author":"calimonk","date":"2026-09-04 18:51:09","revision":3681700},"1.56.0":{"tag":"1.56.0","author":"calimonk","date":"2026-09-04 18:51:09","revision":3681700},"1.56.1":{"tag":"1.56.1","author":"calimonk","date":"2026-09-04 19:01:51","revision":3681711},"1.57.0":{"tag":"1.57.0","author":"calimonk","date":"2026-09-04 19:09:07","revision":3681722},"1.57.1":{"tag":"1.57.1","author":"calimonk","date":"2026-09-06 07:59:36","revision":3683124},"1.57.2":{"tag":"1.57.2","author":"calimonk","date":"2026-09-06 07:59:36","revision":3683124},"1.57.3":{"tag":"1.57.3","author":"calimonk","date":"2026-09-06 07:59:36","revision":3683124},"1.57.4":{"tag":"1.57.4","author":"calimonk","date":"2026-09-07 12:54:44","revision":3684945},"1.57.5":{"tag":"1.57.5","author":"calimonk","date":"2026-09-07 12:54:44","revision":3684945},"1.57.6":{"tag":"1.57.6","author":"calimonk","date":"2026-09-07 12:54:44","revision":3684945},"1.57.7":{"tag":"1.57.7","author":"calimonk","date":"2026-09-07 13:46:51","revision":3685031},"1.57.8":{"tag":"1.57.8","author":"calimonk","date":"2026-09-07 13:46:51","revision":3685031},"1.57.9":{"tag":"1.57.9","author":"calimonk","date":"2026-09-07 13:46:51","revision":3685031},"1.58.0":{"tag":"1.58.0","author":"calimonk","date":"2026-09-07 15:09:15","revision":3685161},"1.58.1":{"tag":"1.58.1","author":"calimonk","date":"2026-09-07 15:09:15","revision":3685161},"1.58.2":{"tag":"1.58.2","author":"calimonk","date":"2026-09-07 15:09:15","revision":3685161},"1.58.3":{"tag":"1.58.3","author":"calimonk","date":"2026-09-07 15:09:15","revision":3685161},"1.58.4":{"tag":"1.58.4","author":"calimonk","date":"2026-09-07 22:16:08","revision":3685671},"1.59.0":{"tag":"1.59.0","author":"calimonk","date":"2026-09-07 22:16:08","revision":3685671},"1.60.0":{"tag":"1.60.0","author":"calimonk","date":"2026-09-07 22:16:08","revision":3685671},"1.60.1":{"tag":"1.60.1","author":"calimonk","date":"2026-09-07 22:16:08","revision":3685671},"1.61.0":{"tag":"1.61.0","author":"calimonk","date":"2026-09-07 22:16:08","revision":3685671},"1.62.0":{"tag":"1.62.0","author":"calimonk","date":"2026-09-07 22:16:08","revision":3685671},"1.63.0":{"tag":"1.63.0","author":"calimonk","date":"2026-09-07 22:16:08","revision":3685671},"1.64.0":{"tag":"1.64.0","author":"calimonk","date":"2026-09-07 22:16:08","revision":3685671},"1.65.0":{"tag":"1.65.0","author":"calimonk","date":"2026-09-09 12:10:47","revision":3688263},"1.66.0":{"tag":"1.66.0","author":"calimonk","date":"2026-09-09 12:10:47","revision":3688263},"1.66.1":{"tag":"1.66.1","author":"calimonk","date":"2026-09-09 12:49:16","revision":3688314},"1.66.2":{"tag":"1.66.2","author":"calimonk","date":"2026-09-09 12:49:16","revision":3688314},"1.67.0":{"tag":"1.67.0","author":"calimonk","date":"2026-09-09 13:42:08","revision":3688392},"1.68.0":{"tag":"1.68.0","author":"calimonk","date":"2026-09-09 16:03:49","revision":3688622},"1.68.1":{"tag":"1.68.1","author":"calimonk","date":"2026-09-09 21:48:23","revision":3689041},"1.68.2":{"tag":"1.68.2","author":"calimonk","date":"2026-09-09 21:48:23","revision":3689041},"1.69.0":{"tag":"1.69.0","author":"calimonk","date":"2026-09-14 08:57:23","revision":3694828},"1.70.0":{"tag":"1.70.0","author":"calimonk","date":"2026-09-14 20:49:47","revision":3695912},"1.70.1":{"tag":"1.70.1","author":"calimonk","date":"2026-09-14 20:49:47","revision":3695912},"1.70.2":{"tag":"1.70.2","author":"calimonk","date":"2026-09-14 20:49:47","revision":3695912},"1.70.3":{"tag":"1.70.3","author":"calimonk","date":"2026-09-14 20:49:47","revision":3695912},"1.70.4":{"tag":"1.70.4","author":"calimonk","date":"2026-09-14 20:49:47","revision":3695912},"1.70.5":{"tag":"1.70.5","author":"calimonk","date":"2026-09-14 20:49:47","revision":3695912},"1.70.6":{"tag":"1.70.6","author":"calimonk","date":"2026-09-14 20:49:47","revision":3695912},"1.71.0":{"tag":"1.71.0","author":"calimonk","date":"2026-09-14 20:49:47","revision":3695912},"1.71.1":{"tag":"1.71.1","author":"calimonk","date":"2026-09-14 20:49:47","revision":3695912},"1.72.0":{"tag":"1.72.0","author":"calimonk","date":"2026-09-14 20:49:47","revision":3695912},"1.72.1":{"tag":"1.72.1","author":"calimonk","date":"2026-09-14 20:49:47","revision":3695912},"1.72.2":{"tag":"1.72.2","author":"calimonk","date":"2026-09-14 20:49:47","revision":3695912},"1.72.3":{"tag":"1.72.3","author":"calimonk","date":"2026-09-14 20:49:47","revision":3695912},"1.72.4":{"tag":"1.72.4","author":"calimonk","date":"2026-09-14 20:49:47","revision":3695912},"1.72.5":{"tag":"1.72.5","author":"calimonk","date":"2026-09-14 20:49:47","revision":3695912},"1.73.0":{"tag":"1.73.0","author":"calimonk","date":"2026-09-15 05:29:43","revision":3696239},"1.73.1":{"tag":"1.73.1","author":"calimonk","date":"2026-09-15 10:25:26","revision":3696739},"1.73.2":{"tag":"1.73.2","author":"calimonk","date":"2026-09-21 08:57:10","revision":3705207},"1.74.0":{"tag":"1.74.0","author":"calimonk","date":"2026-09-21 08:57:10","revision":3705207},"1.75.0":{"tag":"1.75.0","author":"calimonk","date":"2026-09-21 08:57:10","revision":3705207},"1.75.1":{"tag":"1.75.1","author":"calimonk","date":"2026-09-21 08:57:10","revision":3705207},"1.75.2":{"tag":"1.75.2","author":"calimonk","date":"2026-09-21 08:57:10","revision":3705207},"1.75.3":{"tag":"1.75.3","author":"calimonk","date":"2026-09-21 09:09:46","revision":3705223},"1.76.0":{"tag":"1.76.0","author":"calimonk","date":"2026-09-23 14:06:04","revision":3709476},"1.77.0":{"tag":"1.77.0","author":"calimonk","date":"2026-09-23 14:06:04","revision":3709476},"1.77.1":{"tag":"1.77.1","author":"calimonk","date":"2026-09-23 14:06:04","revision":3709476},"1.78.0":{"tag":"1.78.0","author":"calimonk","date":"2026-09-23 14:06:04","revision":3709476},"1.79.0":{"tag":"1.79.0","author":"calimonk","date":"2026-09-23 14:06:04","revision":3709476},"1.79.1":{"tag":"1.79.1","author":"calimonk","date":"2026-09-23 14:06:04","revision":3709476}},"upgrade_notice":[],"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3680272,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3680272,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3681289,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3681289,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["1.48.2","1.48.3","1.49.0","1.50.0","1.50.1","1.50.2","1.51.0","1.51.1","1.52.0","1.52.1","1.52.2","1.53.0","1.53.1","1.54.0","1.54.1","1.55.0","1.56.0","1.56.1","1.57.0","1.57.1","1.57.2","1.57.3","1.57.4","1.57.5","1.57.6","1.57.7","1.57.8","1.57.9","1.58.0","1.58.1","1.58.2","1.58.3","1.58.4","1.59.0","1.60.0","1.60.1","1.61.0","1.62.0","1.63.0","1.64.0","1.65.0","1.66.0","1.66.1","1.66.2","1.67.0","1.68.0","1.68.1","1.68.2","1.69.0","1.70.0","1.70.1","1.70.2","1.70.3","1.70.4","1.70.5","1.70.6","1.71.0","1.71.1","1.72.0","1.72.1","1.72.2","1.72.3","1.72.4","1.72.5","1.73.0","1.73.1","1.73.2","1.74.0","1.75.0","1.75.1","1.75.2","1.75.3","1.76.0","1.77.0","1.77.1","1.78.0","1.79.0","1.79.1"],"block_files":[],"assets_screenshots":{"screenshot-1.png":{"filename":"screenshot-1.png","revision":3680290,"resolution":"1","location":"assets","locale":"","width":1238,"height":1018},"screenshot-10.png":{"filename":"screenshot-10.png","revision":3688263,"resolution":"10","location":"assets","locale":"","width":1235,"height":986},"screenshot-11.png":{"filename":"screenshot-11.png","revision":3684945,"resolution":"11","location":"assets","locale":"","width":1222,"height":852},"screenshot-12.png":{"filename":"screenshot-12.png","revision":3684945,"resolution":"12","location":"assets","locale":"","width":1226,"height":1098},"screenshot-2.png":{"filename":"screenshot-2.png","revision":3681289,"resolution":"2","location":"assets","locale":"","width":1228,"height":1101},"screenshot-3.png":{"filename":"screenshot-3.png","revision":3684945,"resolution":"3","location":"assets","locale":"","width":1223,"height":1162},"screenshot-4.png":{"filename":"screenshot-4.png","revision":3688263,"resolution":"4","location":"assets","locale":"","width":1070,"height":537},"screenshot-5.png":{"filename":"screenshot-5.png","revision":3684945,"resolution":"5","location":"assets","locale":"","width":1230,"height":905},"screenshot-6.png":{"filename":"screenshot-6.png","revision":3684945,"resolution":"6","location":"assets","locale":"","width":1215,"height":1001},"screenshot-7.png":{"filename":"screenshot-7.png","revision":3684945,"resolution":"7","location":"assets","locale":"","width":1229,"height":1127},"screenshot-8.png":{"filename":"screenshot-8.png","revision":3684945,"resolution":"8","location":"assets","locale":"","width":1238,"height":975},"screenshot-9.png":{"filename":"screenshot-9.png","revision":3684945,"resolution":"9","location":"assets","locale":"","width":1222,"height":1020}},"screenshots":{"1":"Dashboard: what the edge did for you in the last 30 days. Delivered, Protected and your plan at work, with 30-day trends.","2":"Edge shields: the attack surface strip (XML-RPC, logins, AI crawlers, comment and search floods) and every shield with its switch, enforced before your server.","3":"Locks: change lock and install lock, what they refused (by plugin), the wp-admin IP lock and login country lock, and the lock activity log with time and address.","4":"Lock activity: what the locks refused in the last 14 days, the exact plugin someone tried to install or update, and the log of who unlocked what, when, from which address.","5":"Probe shields: stray PHP, enumeration and traversal probes refused, with off, monitor and block for each.","6":"Stats and overview: hour-by-hour traffic, origin offload, hit rates by window, surgical purges.","7":"Heaviest images: the files costing the most bandwidth, one-click Tinify shrinking, and what the shrinking has saved so far.","8":"Redirects: legacy URLs answered at the edge, patterns and exact rules with usage, unused rules folded away.","9":"Recent 404s: paths your server keeps answering with a 404, with bot share and one-click redirect or block.","10":"Your audience: humans versus bots, served-from-cache speed, referrers, devices and countries, no tracking script.","11":"Static assets: edge hit rate for stylesheets, scripts and fonts, versioned addresses, bandwidth offloaded.","12":"Query params: which parameters split the cache, which are guarded, with one-click collapse."}},"plugin_section":[262246],"plugin_tags":[146,3882,1174,247,600],"plugin_category":[52,54],"plugin_contributors":[279069],"plugin_business_model":[],"class_list":["post-340850","plugin","type-plugin","status-publish","hentry","plugin_section-dashboard-widgets","plugin_tags-cache","plugin_tags-cloudflare","plugin_tags-firewall","plugin_tags-performance","plugin_tags-security","plugin_category-performance","plugin_category-security-and-spam-protection","plugin_contributors-calimonk","plugin_committers-calimonk"],"banners":{"banner":"https:\/\/ps.w.org\/nivoli-edge\/assets\/banner-772x250.png?rev=3681289","banner_2x":"https:\/\/ps.w.org\/nivoli-edge\/assets\/banner-1544x500.png?rev=3681289","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/nivoli-edge\/assets\/icon-128x128.png?rev=3680272","icon_2x":"https:\/\/ps.w.org\/nivoli-edge\/assets\/icon-256x256.png?rev=3680272","generated":false},"screenshots":[{"src":"https:\/\/ps.w.org\/nivoli-edge\/assets\/screenshot-1.png?rev=3680290","caption":"Dashboard: what the edge did for you in the last 30 days. Delivered, Protected and your plan at work, with 30-day trends."},{"src":"https:\/\/ps.w.org\/nivoli-edge\/assets\/screenshot-2.png?rev=3681289","caption":"Edge shields: the attack surface strip (XML-RPC, logins, AI crawlers, comment and search floods) and every shield with its switch, enforced before your server."},{"src":"https:\/\/ps.w.org\/nivoli-edge\/assets\/screenshot-3.png?rev=3684945","caption":"Locks: change lock and install lock, what they refused (by plugin), the wp-admin IP lock and login country lock, and the lock activity log with time and address."},{"src":"https:\/\/ps.w.org\/nivoli-edge\/assets\/screenshot-4.png?rev=3688263","caption":"Lock activity: what the locks refused in the last 14 days, the exact plugin someone tried to install or update, and the log of who unlocked what, when, from which address."},{"src":"https:\/\/ps.w.org\/nivoli-edge\/assets\/screenshot-5.png?rev=3684945","caption":"Probe shields: stray PHP, enumeration and traversal probes refused, with off, monitor and block for each."},{"src":"https:\/\/ps.w.org\/nivoli-edge\/assets\/screenshot-6.png?rev=3684945","caption":"Stats and overview: hour-by-hour traffic, origin offload, hit rates by window, surgical purges."},{"src":"https:\/\/ps.w.org\/nivoli-edge\/assets\/screenshot-7.png?rev=3684945","caption":"Heaviest images: the files costing the most bandwidth, one-click Tinify shrinking, and what the shrinking has saved so far."},{"src":"https:\/\/ps.w.org\/nivoli-edge\/assets\/screenshot-8.png?rev=3684945","caption":"Redirects: legacy URLs answered at the edge, patterns and exact rules with usage, unused rules folded away."},{"src":"https:\/\/ps.w.org\/nivoli-edge\/assets\/screenshot-9.png?rev=3684945","caption":"Recent 404s: paths your server keeps answering with a 404, with bot share and one-click redirect or block."},{"src":"https:\/\/ps.w.org\/nivoli-edge\/assets\/screenshot-10.png?rev=3688263","caption":"Your audience: humans versus bots, served-from-cache speed, referrers, devices and countries, no tracking script."},{"src":"https:\/\/ps.w.org\/nivoli-edge\/assets\/screenshot-11.png?rev=3684945","caption":"Static assets: edge hit rate for stylesheets, scripts and fonts, versioned addresses, bandwidth offloaded."},{"src":"https:\/\/ps.w.org\/nivoli-edge\/assets\/screenshot-12.png?rev=3684945","caption":"Query params: which parameters split the cache, which are guarded, with one-click collapse."}],"raw_content":"<!--section=description-->\n<p>Every WordPress security plugin runs inside the site it protects. When the site is taken over, so is the plugin: its settings page belongs to the intruder, its rules can be switched off, and every attack it inspects has already reached PHP on your server.<\/p>\n\n<p>Nivoli Edge runs one layer up. Twelve shields refuse attacks, floods, scanners and stray PHP requests at Cloudflare's edge, before a single byte reaches your server. Three locks keep the settings behind an email confirmation held at the edge, so a hacked WordPress cannot switch a shield off, install a plugin, or redirect the confirmation address. The same edge serves whole HTML pages from the node nearest each visitor and keeps the site up when your server goes down. Every number, what was refused, what was served, who did what, shows inside WP admin.<\/p>\n\n<p><strong>Free and managed, in one sentence:<\/strong> the plugin is free and GPL, and everything that runs on your own server works without an account; the shields, the locks, the edge cache and the numbers run on the managed edge, which you connect with an API key. Right-sized WebP and AVIF images from the edge are an optional add-on for the sites that want them.<\/p>\n\n<h4>The Edge Security layer<\/h4>\n\n<p>Wordfence and Sucuri run inside the site they protect. This runs one layer up, at the edge, and the site cannot reach it.<\/p>\n\n<p><strong>Twelve shields, refused before PHP.<\/strong> Your server never boots PHP to turn a request away.<\/p>\n\n<ul>\n<li>Login flood limit (10 attempts per 10 minutes per address)<\/li>\n<li>Comment flood limit (5 posts per 5 minutes per address)<\/li>\n<li>Search flood limit (30 searches per 5 minutes per address)<\/li>\n<li>XML-RPC block (a cached 410)<\/li>\n<li>Login country lock (wp-login answers only the countries you list)<\/li>\n<li>wp-admin IP lock (your own addresses, with a self-lockout guard and an email rescue)<\/li>\n<li>AI-crawler block (GPTBot, ClaudeBot, CCBot and friends; search engines never affected)<\/li>\n<li>Stray-PHP lock (every .php request except the real WordPress entry points gets a 404)<\/li>\n<li>WordPress surface lock (the REST users list, ?author=N, readme.html, license.txt, the installer, debug.log)<\/li>\n<li>Security-headers pack (HSTS, nosniff, frame and referrer policies; your own values win)<\/li>\n<\/ul>\n\n<p>Eight of them come with every managed plan; the AI-crawler block and the wp-admin IP lock from Shield Plus up. The stray-PHP and surface locks have a monitor mode that lists what blocking would have stopped before it blocks anything.<\/p>\n\n<p><strong>Three locks, nothing inside the site can turn off.<\/strong> A takeover of your WordPress admin owns every plugin's settings page. Ours refuses to act on WordPress's say-so.<\/p>\n\n<ul>\n<li>Change lock: any change that weakens protection waits for a click on a link mailed to the license holder; the link applies exactly that change, once.<\/li>\n<li>Install lock: plugin and theme installs, uploads, updates, deletes and the file editors are refused site-wide until a 15-minute window is opened the same way. Automatic updates and WP-CLI run on the server and are never affected.<\/li>\n<li>Origin lock: the edge stamps a per-site secret on every request it forwards and the plugin refuses code changes that arrive without it, so knowing the server's address is no longer a way around the locks. A self-test reports whether the server enforces it.<\/li>\n<\/ul>\n\n<p><strong>Evidence: who did what, from where.<\/strong><\/p>\n\n<ul>\n<li>Refused installs named by plugin, and every refused attempt in your inbox as it happens.<\/li>\n<li>A lock activity log with time and address for every unlock request, clicked link, confirmation and lock change.<\/li>\n<li>An attack-surface strip per fortnight, a monthly report by email, and for agencies a posture matrix across every site.<\/li>\n<\/ul>\n\n<p>Underneath all of it, Cloudflare's managed WAF rulesets, including the WordPress rule set, run in front of every managed site.<\/p>\n\n<h4>Pages served from the edge<\/h4>\n\n<p>Full-page HTML caching with surgical purge: only the pages featuring a changed post refresh, never the whole cache.<\/p>\n\n<ul>\n<li>Surrogate-Key \/ Cache-Tag headers on every cacheable page; purges go to Nivoli, Fastly, Cloudflare Enterprise or your own webhook.<\/li>\n<li>Logged-in visitors, carts and checkout always bypass.<\/li>\n<li>Stylesheets, scripts and fonts from the edge too, on versioned addresses, so no browser or CDN node holds a stale file after a purge.<\/li>\n<li>Origin shield: if your server goes down, the edge keeps serving the last good copy of every cached page for up to 7 days and emails you when it engages and when the origin recovers.<\/li>\n<\/ul>\n\n<h4>Images served from the edge<\/h4>\n\n<p>URLs rewrite through Cloudflare Image Resizing into right-sized WebP\/AVIF variants on the fly. No uploads, no duplicate copies, no migration, no theme changes.<\/p>\n\n<ul>\n<li>Per-size presets, one-click Size mapping from your theme's registered sizes, a catch-all for everything else.<\/li>\n<li>Broken, heavy and fake images found from real traffic, with where each is used and one-click fixes; heavy originals shrink through Tinify.<\/li>\n<\/ul>\n\n<h4>The numbers, inside WP admin<\/h4>\n\n<ul>\n<li>What the edge answered and what it refused, by window, with the most-requested and most-missed URLs.<\/li>\n<li>Dead URLs on a Recent 404s page with one-click redirect or block; a Search Console 404 export imported, matched to your own pages and turned into redirect and block rules family by family; All rules: one ordered list of every edge rule with per-rule counts and reordering.<\/li>\n<li>Audience without a tracking script: humans versus bots, countries, referrers, devices, served-from-cache speed.<\/li>\n<li>Static assets: edge hit rate per file type and which files still travel on plain addresses.<\/li>\n<li>A monthly report by email, white-label copies for clients on Agency.<\/li>\n<\/ul>\n\n<h4>Free versus managed<\/h4>\n\n<p>Free, on your own infrastructure, no account: image URL rewriting through your own Cloudflare zone (native WP filters, srcset, Gutenberg, WooCommerce, the_content and full-page scan), image rules and size mapping, page-cache tag headers with surgical purge to Fastly, Cloudflare Enterprise or your webhook, prewarm on save, coverage audit with a weekly regression email, fake-image detection and repair, purge-failure alerts, a weekly header self-test, a printable client report, the debug overlay, and WP-CLI.<\/p>\n\n<p>Managed, with a Nivoli API key: everything in The Edge Security layer above, the managed page cache (no Cloudflare account, plan or DNS work), origin shield, URL rules and the 404 inbox, per-path cache duration, the query-param manager, cache protection, dynamic-content safety for WooCommerce, edge insights and the monthly report, custom image hostname and watermarking, and for agencies a fleet console with one key across sites.<\/p>\n\n<p>Managed Images, the optional add-on: right-sized WebP and AVIF variants created once at the edge and served from the node nearest each visitor, no Cloudflare account and no plugin configuration. Without it your images serve from your own server, untouched; the free image tools keep working.<\/p>\n\n<h4>Requirements<\/h4>\n\n<ul>\n<li><strong>Free:<\/strong> a Cloudflare zone with <strong>Image Resizing<\/strong> enabled for the image half (Pro+ plan or per-1000 pricing); a tag-aware edge (Fastly \/ CF Enterprise \/ your webhook) for the page-cache half. If Image Resizing isn't enabled the rewritten URLs 404; the Tools tab has a one-click probe to verify.<\/li>\n<li><strong>Managed:<\/strong> none of the above for pages and security; for images, the Managed Images add-on. Just an API key from your Nivoli account.<\/li>\n<\/ul>\n\n<h3>External services<\/h3>\n\n<p>The free tier's core image rewriting sends <strong>no data to any external service<\/strong>; it only rewrites <code>&lt;img&gt;<\/code> URLs in your site's HTML so browsers fetch through your own Cloudflare zone. Beyond that, the plugin contacts external services only for the specific, opt-in features listed below.<\/p>\n\n<p><strong>Nivoli managed edge<\/strong> (api at html-caching-admin.nivoli.workers.dev, dashboard at console.nivoli.com): used <strong>only if you enter an API key<\/strong>. On activation and on a daily background re-check it sends your API key, this site's URL, the plugin version, and the list of broken-image file paths you have marked handled (so the monthly report can exclude them; these are addresses the CDN already sees in its own traffic) to validate the key and provision your managed CDN\/page-cache tenant; it then reads back the aggregate usage statistics shown on the dashboard. If you configure monthly reports or alerts, the recipient email address and optional report branding (a name and logo URL) are stored with your account. No visitor data is ever sent. Terms: https:\/\/nivoli.com\/terms \u00b7 Privacy: https:\/\/nivoli.com\/privacy<\/p>\n\n<p><strong>Cloudflare<\/strong> (api.cloudflare.com): used <strong>only if you configure the Cloudflare Enterprise page-cache backend<\/strong> with your own API token, to dispatch tag-based cache purges when your content changes. Terms: https:\/\/www.cloudflare.com\/terms\/ \u00b7 Privacy: https:\/\/www.cloudflare.com\/privacypolicy\/<\/p>\n\n<p><strong>Fastly<\/strong> (api.fastly.com): used <strong>only if you configure the Fastly page-cache backend<\/strong> with your own API token, to dispatch surrogate-key purges on content change. Terms: https:\/\/www.fastly.com\/terms\/ \u00b7 Privacy: https:\/\/www.fastly.com\/privacy\/<\/p>\n\n<p><strong>TinyPNG \/ Tinify<\/strong> (api.tinify.com): used <strong>only if you add your own Tinify API key and click \"Shrink original\"<\/strong> on an image, to compress that source file. Only the image you choose is sent. Terms &amp; Privacy: https:\/\/tinify.com\/terms<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Upload the plugin and activate it (or paste your API key on the <strong>Account<\/strong> tab; the managed edge provisions itself and fills the settings in for you).<\/li>\n<li>Free \/ bring-your-own-zone: open <strong>Nivoli Edge \u2192 Settings<\/strong>, confirm the auto-detected image host + path prefix, toggle Enabled.<\/li>\n<li>Add rules under <strong>Image rules<\/strong> if specific sizes need specific treatment, or let <strong>Size mapping<\/strong> create them from your theme's registered sizes in one click. Catch-all handles the rest with zero config.<\/li>\n<li>For HTML caching, open <strong>Settings \u2192 Page cache<\/strong> and pick a backend (managed Nivoli with your API key, or your own Fastly \/ CF Enterprise \/ webhook).<\/li>\n<li>The <strong>Dashboard<\/strong> shows whether everything's working and what the edge is doing for you.<\/li>\n<\/ol>\n\n<!--section=faq-->\n<dl>\n<dt id=\"does%20this%20replace%20wordfence%20or%20sucuri%3F\"><h3>Does this replace Wordfence or Sucuri?<\/h3><\/dt>\n<dd><p>It sits above them. Those plugins inspect requests inside WordPress, after PHP has started; Nivoli Edge refuses hostile traffic at Cloudflare's edge before your server sees it, and its settings cannot be switched off from inside a compromised WordPress. Run both if you like; they do not overlap.<\/p><\/dd>\n<dt id=\"what%20do%20the%20twelve%20shields%20stop%3F\"><h3>What do the twelve shields stop?<\/h3><\/dt>\n<dd><p>Login, comment and search floods, XML-RPC abuse, logins from countries you do not serve, wp-admin from addresses that are not yours, AI crawlers, direct requests to PHP files that are not WordPress entry points, the probes that map a site (user lists, readme, license file, installer, debug.log), path traversal attempts in any encoding, addresses that keep probing after five refusals, and missing security headers. Ten come with every managed plan; the AI-crawler block and the wp-admin IP lock from the second plan up.<\/p><\/dd>\n<dt id=\"does%20this%20require%20cloudflare%20pro%3F\"><h3>Does this require Cloudflare Pro?<\/h3><\/dt>\n<dd><p>Only for the free image rewriting on your own zone: Cloudflare Image Resizing is bundled with Pro plans or available pay-as-you-go. The managed edge needs no Cloudflare account at all.<\/p><\/dd>\n<dt id=\"will%20this%20break%20my%20theme%3F\"><h3>Will this break my theme?<\/h3><\/dt>\n<dd><p>No. The plugin only modifies URLs at the filter boundary; the HTML structure your theme outputs is unchanged. Use the <code>no-cf<\/code> CSS class on any element to opt out.<\/p><\/dd>\n<dt id=\"how%20is%20this%20different%20from%20smush%20%2F%20shortpixel%20%2F%20optimole%3F\"><h3>How is this different from Smush \/ ShortPixel \/ Optimole?<\/h3><\/dt>\n<dd><p>Those plugins compress and re-host images on their own CDN. Nivoli Edge transforms on the fly from your origin: no asset duplication, no migration step, no storage bill.<\/p><\/dd>\n<dt id=\"what%27s%20the%20difference%20between%20free%20and%20managed%3F\"><h3>What's the difference between Free and Managed?<\/h3><\/dt>\n<dd><p>Everything the plugin does on your own server is free and fully functional: image rewriting, page-cache purging, audits, prewarming, alerts, reports. Nothing phones home. An API key connects the plugin to the Nivoli managed edge: we run the Cloudflare zone and page cache for you (no Cloudflare setup at all) and the service adds what a plugin alone can't, such as edge-side usage statistics, per-URL traffic insights, edge URL rules and security shields, custom hostnames, watermarking, and multi-site fleet management.<\/p><\/dd>\n<dt id=\"what%20if%20i%20lose%20access%20to%20my%20license%20email%3F\"><h3>What if I lose access to my license email?<\/h3><\/dt>\n<dd><p>Confirmation and unlock links go to the email address on your Nivoli license and nowhere else; that is what makes the locks hold against a takeover. Support can move the license to a new address after verifying you own it. Until then the locks stay as they are and the site keeps running; only changes that weaken protection wait.<\/p><\/dd>\n<dt id=\"does%20the%20install%20lock%20break%20automatic%20updates%3F\"><h3>Does the install lock break automatic updates?<\/h3><\/dt>\n<dd><p>No. Automatic background updates run from wp-cron on your server and WP-CLI runs on the box; neither passes through the edge, so neither is affected. Only installs, uploads, updates and deletes started from wp-admin are refused, and you open a 15-minute window by email when you want to do one yourself.<\/p><\/dd>\n<dt id=\"what%20if%20my%20site%20gets%20hacked%20anyway%3F\"><h3>What if my site gets hacked anyway?<\/h3><\/dt>\n<dd><p>The locks stop the intruder from switching the shields off, installing anything through WordPress, or redirecting the confirmation address, and every attempt lands in your inbox and on the Locks page with its time and address. What no edge control can do is undo code already running on your server: cleaning the box is still yours (scan, restore, rotate). The locks make sure the compromise stays where it landed.<\/p><\/dd>\n<dt id=\"does%20the%20page%20caching%20conflict%20with%20my%20security%20plugin%20%28wordfence%2C%20sucuri%29%3F\"><h3>Does the page caching conflict with my security plugin (Wordfence, Sucuri)?<\/h3><\/dt>\n<dd><p>No. Different layers: security plugins inspect requests inside WordPress\/PHP; Nivoli Edge's twelve shields run at Cloudflare's edge, before the request reaches your server. It sheds junk traffic so your origin and your security plugin only see real visitors. They complement each other.<\/p><\/dd>\n<dt id=\"do%20i%20need%20to%20change%20my%20nginx%20%2F%20web-server%20config%3F\"><h3>Do I need to change my nginx \/ web-server config?<\/h3><\/dt>\n<dd><p>Only if your origin runs its own micro-cache (nginx fastcgi\/proxy cache, Varnish) and you use the manual purge trigger; the Cache protection pane shows the exact one-line snippet. A standard PHP-FPM origin needs no server changes at all.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<p>Recent releases are listed below. The full history for every version is in CHANGELOG.md, which ships with the plugin, and on the GitHub releases page.<\/p>\n\n<h4>1.79.1<\/h4>\n\n<p>Security, tidied after a first look: the scanner lockout sits with the other probe shields; the login rate limit, the login country lock and the wp-admin IP lock share one Login &amp; admin pane; the security check groups its findings (exposed, worth fixing, what only the edge refuses, and the fine ones folded away with a count), shows nothing to press on a finding that is already fine, and reads \"refused at the edge\" in green on a managed site. Images opens on Coverage, with Health above Optimization.<\/p>\n\n<h4>1.79.0<\/h4>\n\n<p>The admin is regrouped by what you are doing: Overview, Security, Pages, Images and Account replace the Managed Edge, Tools and Settings tabs. Every pane kept its place in old links and mails. Free and managed panes sit together under their subject, marked by a dot; a free install sees the managed panes folded into one \"Switch on the edge\" line per tab. New under Security: a Hardening pane with eight switches (the five the check offered, plus the version in asset URLs and headers, head clutter and minor core updates) and a generated must-use plugin that keeps them on when this plugin is off.<\/p>\n\n<h4>1.78.0<\/h4>\n\n<p>Shield 12, the scanner lockout: an address that collects five refusals from the shields within ten minutes gets a 403 on every further request for ten minutes, at the edge. Logged-in sessions and verified search engines are never locked out. On by default for every site; its card on the Edge shields page shows off, monitor or block and lists what locked-out addresses kept asking for. Turning it down waits for the change lock.<\/p>\n\n<h4>1.77.1<\/h4>\n\n<p>The traversal guard's description on the PHP &amp; surface shields page says what the shield does and nothing else.<\/p>\n\n<h4>1.77.0<\/h4>\n\n<p>Shield 11, the traversal guard: any request whose path or query string carries ..\/ in any encoding, after up to three rounds of decoding, gets a 404 at the edge. On by default for every site. Its card on the PHP &amp; surface shields page shows off, monitor or block and lists what monitoring saw; turning it down waits for the change lock. The onboarding shields step and the Protected pillar count it.<\/p>\n\n<h4>1.76.0<\/h4>\n\n<p>Page caching has a switch: on, or pass-through with every shield and lock still on and every page from your own server, for sites that want the protection without the cache. The Stats &amp; overview pane carries it. When the plan policy sets pass-through (a site far above its pageviews for two monthly checks) the pane says so and points at the plan change.<\/p>\n\n<h4>1.75.3<\/h4>\n\n<p>The WordPress.org listing tells the security story first: what runs one layer above WordPress, what the shields stop, what the locks hold, and where the free plugin ends and the managed edge begins. No prices on the listing; plans live on the pricing page.<\/p>\n\n<h4>1.75.2<\/h4>\n\n<p>The \"traffic is not reaching the managed CDN\" warning no longer fires on the edge's own pass-through redirects (an allowance used up, the add-on not on), Refresh data re-runs its probe, and on a nivoli.com hostname it names the symptom instead of a Cloudflare CNAME you do not have.<\/p>\n\n<h4>1.75.1<\/h4>\n\n<p>The account card says whether Managed Images is on, with the allowance and the variants created in the last 30 days. A change made on the edge (a block added, a plan change) shows up on the next page view: the hub re-checks the key by itself when its status is older than ten minutes.<\/p>\n\n<h4>1.75.0<\/h4>\n\n<p>Your account: the Account tab opens console.nivoli.com\/account, where the email on the license signs you in to your plan, sites, Managed Images and invoices; Change plan and Managed Images go straight to the billing portal. When the image allowance fills, the one path is another block; the one-time pack is gone.<\/p>\n\n<h4>1.74.0<\/h4>\n\n<p>Plans are Shield, Shield Plus and Agency, and image transformation at the edge is the Managed Images add-on. On a managed plan without it the plugin leaves image URLs alone (images serve from your server, untouched) and the Usage, Custom hostname, Watermark, Broken images and Heaviest images panes show one card that explains and sells the add-on. The setup overview runs key, pages, shields, locks, images (optional), report. Plan names everywhere come from one label map.<\/p>\n\n<h4>1.73.2<\/h4>\n\n<p>The Cloudflare DNS callout on the site-CNAME step now actually appears when the zone runs on Cloudflare nameservers; the check behind it could never match before.<\/p>\n\n<h4>1.73.1<\/h4>\n\n<p>Fake images: a pending row whose file is a real image again is settled when the pane opens. If the plugin's backup store holds the original, the row becomes replaced (the record had been lost); if not, the file was fixed outside and the row goes. Replace on such a row does the same instead of refusing with \"That file is a real image\".<\/p>","raw_excerpt":"Security one layer above WordPress: attacks refused before they reach PHP, locks a hacked site cannot switch off, and whole pages served from Cloudfla &hellip;","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/es.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/340850","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/es.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/es.wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/es.wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=340850"}],"author":[{"embeddable":true,"href":"https:\/\/es.wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/calimonk"}],"wp:attachment":[{"href":"https:\/\/es.wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=340850"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/es.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=340850"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/es.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=340850"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/es.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=340850"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/es.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=340850"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/es.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=340850"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}