Estate-Wide Cloudflare Security Comparison — PeopleFinders Domain Portfolio
Basis: The ten per-domain executive assessments dated 2026-07-25 (30-day evidence windows).
Method note. All figures are drawn from the individual domain reports. "Human %" / "Automated %" are shares of scored traffic (bot-score dataset, cache-excluded). "Block Rate" is edge
403as a share of total requests. "Challenge Rate" is managed challenges issued as a share of total requests (approximate; datasets differ slightly in scope).
1. Executive Summary
- Ten production domains, one shared security posture — and one shared blind spot. Every domain runs on Enterprise Cloudflare with the full managed ruleset stack deployed in inventory, active Bot Management, and highly effective managed challenges. Yet on 9 of 10 domains the managed WAF (signature defense) is effectively switched off — only
fastbackgroundcheck.comactually enforces it. - The estate is bot-defended but not exploit-defended. Bot challenges achieve 83–99% abandonment everywhere, and custom rules block at scale — but signature-based protection against injection/exploit is largely absent, and so is the telemetry that would reveal such attacks.
- Protection quality spans a 15-point band (60–75/100) on identical entitlements. The variation is configuration drift, not licensing — every gap identified is fixable within the current plan.
- The highest-value property carries disproportionate risk. The flagship
peoplefinders.com(payments, accounts, API hub) runs its WAF in log-only mode with an unproxied API surface. - Edge-bypass exposure is the most urgent risk class — several domains publish DNS records that route around Cloudflare entirely (unproxied API, admin panel, or origin hostnames).
- Every domain faces the same adversary: continuous commercial-scale scraping from the same cloud/hosting networks (Google Cloud, DigitalOcean, VNPT, Linode, AWS) and ad-tech crawlers (SirdataBot, Integral Ad Science) — a shared problem with shared solutions.
- A proven internal template already exists —
fastbackgroundcheck.comdemonstrates the target state (active WAF + layered defense on a clean perimeter). Estate-wide uplift is largely a replication exercise.
2. Domain Ranking
2.1 By Security Maturity (config depth, layering, WAF enforcement) — best first
2.2 By Cloudflare Effectiveness (observed threat containment) — most effective first
2.3 By Operational Risk — highest risk first
2.4 By Bot Protection Readiness — most ready first
(All ten have Bot Management entitled and scoring live traffic; ranking reflects challenge effectiveness + rate-limit backstop + WAF support.)
- fastbackgroundcheck.com — BM + active WAF + rate limit + 92.8% abandon
- cyberbackgroundchecks.com — BM + 96.6% abandon + heaviest rate limit + DDoS + dual challenge
- usphonebook.com — BM + 96.5% abandon + enforcing targeted rate limit
- searchpeoplefree.com — BM + 94.5% abandon + strong rate limit
- cyber-parity: actualpeoplesearch.com — BM + rate-limit-driven challenge (~99% abandon) on its enumeration surface
- smartbackgroundchecks.com — BM + 91.5% abandon + targeted rate limit
- peoplefinders.com — BM + 94.7% abandon, but no enforcing rate-limit backstop
- advancedbackgroundchecks.com — BM + 95.5% abandon + security level, but rate limiting negligible
- fastpeoplesearch.com — BM + 93.5% abandon, but rate limiting inert (challenge is the only mechanism)
- usa-people-search.com — BM + 83.8% abandon (lowest) + rate limiting negligible
3. Comparison Table
Priority key: P1 = urgent (bypass exposure / flagship / single point of failure); P2 = high-value gap; P3 = standard uplift; P4 = maintain/replicate.
4. Strongest Protected Domains
1. fastbackgroundcheck.com — the reference standard (Score 75). The only domain where the managed WAF is actually enforcing (millions of signature blocks), giving it true defense-in-depth: signature WAF + custom rules + bot challenge + rate limiting + DDoS L7, all on a clean, fully-proxied perimeter. It contains a heavy scraping campaign (54% of traffic 403'd, 92.8% challenge abandonment) and retains attack telemetry the other nine lack. Its remaining gaps are incremental (widen rate limiting, turn on security level), not structural. This is the template for the estate.
2. cyberbackgroundchecks.com (Score 68). The estate's strongest behavioral defender: the heaviest and broadest rate limiting (31M events across record/lookup endpoints), active DDoS L7, and dual challenge layers, achieving a 96.6% abandonment rate on the most-attacked property — all on a clean perimeter. The single missing piece is the signature WAF.
3. usphonebook.com (Score 68). Highest traffic in the estate, defended with genuinely enforcing, well-targeted rate limiting (27M events) and heavy custom blocking (117.9M blocks, 96.5% abandon). Held back by a skipped managed WAF and origin-bypass DNS records.
What the leaders share: rate limiting that actually fires on the right endpoints, high challenge-abandonment, and (for fastbackgroundcheck) an active WAF. The gap between #1 and the rest is almost entirely whether the WAF is switched on.
5. Highest Risk Domains
1. peoplefinders.com (HIGH — P1). The crown jewel carries the crown-jewel risk: it is the payments, accounts, and API hub, yet its API subdomain is unproxied (bypasses every control), its DNS exposes origin and internal RFC1918 addresses, its WAF runs in log-only mode, and it has no enforcing rate limit. Highest business value + real bypass paths = top of the list.
2. searchpeoplefree.com (HIGH — P1). Publishes an unproxied admin panel that resolves straight to its Azure origin — an internet-exposed administrative surface with zero edge protection and no security telemetry — on top of an inactive WAF, while absorbing the heaviest relative attack pressure.
3. fastpeoplesearch.com (HIGH — P1). The most fragile posture: 99.99% of all blocking comes from a single custom rule, with no WAF backstop and a rate limiter that is heavily configured but fires almost never. Extremely effective today, but one misconfiguration from collapse.
4–6. smartbackgroundchecks.com, usphonebook.com, cyberbackgroundchecks.com (HIGH). All defend well behaviorally but run the managed WAF inactive on dynamic/API surfaces (/search.php, /api/*), and two of them (usphonebook) publish origin-bypass DNS records.
What the high-risk domains share: an inactive signature WAF combined with either an edge-bypass path or a single point of failure. The behavioral controls are often strong; the structural gaps are what elevate the risk.
6. Common Estate Weaknesses (recurring)
- Managed WAF not enforcing — the dominant estate-wide gap. 9 of 10 domains run the managed WAF / OWASP ruleset inactive, skipped, or log-only. Only
fastbackgroundcheck.comenforces it. The estate has broad bot defense but almost no signature/exploit defense — and no WAF-layer attack telemetry on nine domains. - Edge/origin bypass paths in DNS. Roughly half the estate publishes unproxied records that route around Cloudflare: unproxied API (
peoplefinders), admin panel (searchpeoplefree),fastly-origin/origin hostnames (usphonebook,advancedbackgroundchecks), and an origin IP (fastpeoplesearch). - Rate limiting is wildly inconsistent. From excellent and broad (cyber 31M, usphonebook 27M, searchpeoplefree 17.8M) to negligible or inert (fastpeoplesearch 9.8K despite heaviest tuning, usa-people-search 15K, advanced 42K, peoplefinders log-only). No estate standard.
- Security level (reputation challenge) off almost everywhere. Only
advancedbackgroundchecks.comshows it active. A cheap reputation layer is unused across the estate. - Single-rule concentration. Most domains route 90–99.99% of blocks through one custom rule — a resilience risk with no signature backstop behind it.
- Country filtering not applied as a standard. Foreign traffic runs at 95–99%+ threat rates across the estate, yet handling is per-domain and inconsistent rather than a shared baseline.
- Universal-only certificates. Only the flagship uses an Advanced certificate; the rest rely on Universal certs (one had an expired backup pack).
- Unverifiable hardening + likely Page Shield gaps. SSL mode, HSTS, min-TLS, and Page Shield status were not confirmable under the audit token on any zone — a governance/visibility gap in itself, and Page Shield is likely off estate-wide on data-collection properties.
7. Common Estate Strengths
- Bot Management is entitled and active on all 10 domains — live bot scoring everywhere, including the smallest zone.
- Managed Challenge is the estate's most reliable control — 83–99% challenge-abandonment on every domain; the workhorse against scraping.
- Custom firewall rules do real, heavy enforcement everywhere — tens to hundreds of millions of blocks/challenges per domain.
- The full managed ruleset stack is already deployed in inventory on every zone (OWASP, Cloudflare Managed, Exposed Credentials, DDoS L7, Normalization) — activating the WAF is a switch-on, not a purchase.
- Enterprise plan, valid TLS, near-universal HTTPS (96–99%+ encrypted) across the estate.
- Several domains have genuinely clean DNS (fastbackgroundcheck, cyberbackgroundchecks, usa-people-search, smartbackgroundchecks, actualpeoplesearch) — no origin exposure.
- A proven internal reference implementation exists (
fastbackgroundcheck.com) — the target state is already running in production. - Consistent, well-attributed adversary — the same scrapers recur estate-wide (Google Cloud, DigitalOcean, VNPT, Linode, AWS; SirdataBot / Integral Ad Science; the GoDaddy IP
92.204.248.55), making a shared blocklist immediately effective.
8. Executive Observations (CTO lens)
- One systemic fix outranks all others: turn the managed WAF on. It is inactive on 9 of 10 domains despite being paid for and deployed — the estate is paying for signature defense it isn't using.
- We are defending against bots, not against attacks. Scraping is well-contained; injection/exploit defense and its telemetry are largely absent. We would not currently see a successful exploit attempt on most domains.
- The gap is configuration, not budget. A 15-point spread on identical Enterprise entitlements means the uplift is operational discipline — no new licensing required.
- The flagship is the least-proportionately-protected asset. peoplefinders.com holds payments, accounts, and the API, yet runs WAF in log-only mode with an unproxied API. Risk and business value are inverted here.
- Bypass paths are the fastest way an attacker skips everything we built. Unproxied API, admin, and origin records on several domains make the rest of the security stack irrelevant for those paths — fix these first.
- We already own the blueprint. fastbackgroundcheck.com proves the target posture works in production; the program is "make the other nine look like this one."
- Resilience is quietly fragile. Most domains hang their entire blocking function on a single custom rule; a routine change could silently drop protection with no backstop.
- Rate limiting has no standard. The same control ranges from best-in-class to non-functional across domains — a shared baseline (which endpoints, what thresholds) would close most of the variance.
- One adversary, ten front doors. The identical scraper set hitting every domain means estate-level controls (shared blocklist, standard country/ASN handling) pay off ten times per change.
- Governance, not heroics, closes this. A short standard — WAF enforcing, rate-limit baseline, security level on, DNS hygiene (no unproxied origins), Page Shield on payment/data sites — applied uniformly would raise the entire estate and eliminate the drift that produced this spread.