Security
SSL/TLS review
Score: 9/10Free universal certs changed the whole industry.
The breakdown explains the score. It is not an average. How to read these.
Last updated
Universal SSL made HTTPS free and automatic for millions of sites. It is still excellent, with automatic issuance and renewal, Total TLS for every subdomain, and Advanced Certificate Manager when you need control over CAs, validity, or hostnames.
Origin CA certificates (free 15-year certs for the Cloudflare-to-origin hop) plus Full (strict) mode is a setup I’d consider mandatory, and it takes about ten minutes.
It loses a point for occasional sharp edges. Certificate validation can get stuck with vague dashboard messages, some renewals need a manual nudge, and useful controls such as custom cipher suites require higher tiers.
Status page incidents
Published under SSL Certificate Provisioning, SSL for SaaS Provisioning, plus incidents whose title names it.
- Last 3 years
- 43
- 9 from the title
- Major or critical
- 1
- Median time open
- 1.4 h
- Since March 2016
- 160
Counts what Cloudflare published, not what broke: time open is how long the status entry stayed open, and nothing before March 2016 is tracked at all. Incidents Cloudflare tagged against nothing but named in the title are counted too. The caveats in full.