Likelihood to Recommend Based on my experience, Cloudflare is well-suited for high-traffic websites and probably e-commerce platforms. Cloudflare can mitigate the risk of attacks on these websites using WAF and DNS protection mechanisms and provide cached content to the end-users quickly. The websites where it is not suitable are those that need high security and compliance requirements as Cloudflare might not meet all those criteria.
Read full review Burp Suite is a good general tool to test websites as long as your website is not too large or you have the time for it to complete. We have some websites that only about five to ten minutes for Burp Suite to complete an attack and a spider only takes about two minutes. Other websites have taken a few hours to complete. I have seen a tester actually run Burp Suite against one of our websites and it took all day to complete.
Read full review Pros Registrar and DNS services are impeccable, with registrations done at cost and without ADs. DNS services setting standards for speed of resolution. DDOS protection. With their content distribution network to back them they have the bandwidth and tools to be both proactive and reactive to bad actors. WAF - Their Web Application Firewall helps mitigate common site vulnerabilities and has active zero-day protection running for breaking exploits Read full review The passive scan feature is really awesome, it kind of covers areas that you might miss. The CSRF POC is really helpful to my team. It helps development team see the issue and understand it. Burp intruder and repeater are the features I myself and my team uses the most as it helps us use our payloads in a variety of different ways. Active scan helps the team to ensure coverage for the whole application. Read full review Cons In some cases, using Cloudflare can actually lead to slower website speeds if the network is congested or if the website's traffic is particularly heavy. Some website owners may find that the level of customization offered by Cloudflare is limited, especially in comparison to other solutions. While Cloudflare is easy to set up and manage, it may be too complex for users who are not familiar with web technologies. Read full review More features to be available for the free/community version to allow more learning Manual updating of plugin without network connectivity More controls with the manual testing with scenario inputs Read full review Likelihood to Renew lower cost
Read full review Usability Everything is extremely concise and all settings apply immediately and take effect globally. There is no reason to explicitly plan/think in terms of individual regions as one would have to traditional cloud offerings (AWS, OCI, Azure). All Cloudflare products integrate seamless as part of a single pipeline that executes from request to response.
Read full review Given this tool's wide area of testing functionality for mobile and web applications, it's a great tool to invest in for security testing. Though it lacks documentation to carry out particular vulnerability findings which are very challenging for a new user of this tool
Read full review Reliability and Availability In 6+ years of relying on Cloudflare, I think we experienced one or two brief outages that were Cloudflare's fault.
Read full review Performance Their Argo for the global network is the core feature we love.
Read full review Support Rating I have only used their support a few times, and most times, they are responsive and able to resolve my issue with a minimal amount of time and effort. However, there was one instance where I simply asked about how to purchase some more resources (redirect rules), and I received some type of automated/AI response that was very unhelpful and gave me no opportunity to escalate to a person.
Read full review BurpSuite does not have an amazing customer support. All the major help that you will find is from public forums and Google. Although you will find all the required information on Google, still at time professional support helps you solve the problem in much less time and make your operations go smoothly.
Read full review Implementation Rating Very well executed implementation where our team was able to handle the implementation with guidance.
Read full review Alternatives Considered Firebase can be a good starter for basic projects but as I scaled up, I found it lacking the maturity Cloudflare has. Naturaly, I opted for Cloudflare for bigger projects. I still use
Firebase , but for small scale hobby projects only.
Read full review The only other tool I use that works like Burp Suite is the OWASP ZAP. It works a lot like Burp but just has a different layout. I prefer how Burp has the tabs for Repeater, Intruder, Decoder, ect.
Read full review Scalability They are built for scale and have the capacity to handle all the traffic we could ever expect to get.
Read full review Return on Investment A lot of requests are cached and so egress costs from downstream providers are mitigated. DDoS protection has also managed to keep our site up and our cloud computing bill down. Setting up a proxy with a worker made putting various Google Cloud Functions running behind a single URL very easy and performant. Plus they offer API Shield on top of this. Read full review Positive impact, time to complete security development stage is decreased. Very positive impact on budgeting for external penetration testing. We can do the bulk of the common testing ourselves now. Read full review ScreenShots