Skip to content
The Orange Cloud Report

Security

Rate Limiting review

Score: 7/10

Essential and effective; the granularity you want costs more.

Reliability
8Pricing honesty
5Developer experience
6Trajectory
4

The breakdown explains the score. It is not an average. How to read these.

Last updated

Modern rate limiting rules use the WAF engine and its expression language. They are much better than the old product, which billed per request. Every plan can count by IP, while headers, cookies, JA4, and query values require higher tiers.

For basic brute-force and abuse protection it’s a ten-minute setup that just works. The mitigation timeout options and the ability to count on one expression while mitigating on another cover most real-world shapes.

It loses points because the most useful characteristics require Business or Enterprise, and because observability is weak. Checking what a rule would catch before enforcing it is clumsier than it should be.

Status page incidents

Cloudflare publishes no status page component for Rate Limiting.

All incident history →

Its incidents, if any were published, went out under a broader component. There is nothing to count per product here.