Cloudflare Security PostureSecurity Engineering

Overview

  • ExecutivePosture at a glance
  • EstateCross-domain comparison

Detail

  • DomainsPer-zone assessments
  • MethodologyEvidence and limits
Reports
12
Latest window
Jul 25, 2026
Cloudflare Security PostureSecurity Engineering

Overview

  • ExecutivePosture at a glance
  • EstateCross-domain comparison

Detail

  • DomainsPer-zone assessments
  • MethodologyEvidence and limits
Reports
12
Latest window
Jul 25, 2026
⌘K
v1.0 · 30-day window
Report library

Report

Estate-Wide Cloudflare Security Comparison — PeopleFinders Domain Portfolio

Jul 25, 202610 min read16.7 KB

Estate-Wide Cloudflare Security Comparison — PeopleFinders Domain Portfolio

Basis: The ten per-domain executive assessments dated 2026-07-25 (30-day evidence windows).

Method note. All figures are drawn from the individual domain reports. "Human %" / "Automated %" are shares of scored traffic (bot-score dataset, cache-excluded). "Block Rate" is edge 403 as a share of total requests. "Challenge Rate" is managed challenges issued as a share of total requests (approximate; datasets differ slightly in scope).


1. Executive Summary

  • Ten production domains, one shared security posture — and one shared blind spot. Every domain runs on Enterprise Cloudflare with the full managed ruleset stack deployed in inventory, active Bot Management, and highly effective managed challenges. Yet on 9 of 10 domains the managed WAF (signature defense) is effectively switched off — only fastbackgroundcheck.com actually enforces it.
  • The estate is bot-defended but not exploit-defended. Bot challenges achieve 83–99% abandonment everywhere, and custom rules block at scale — but signature-based protection against injection/exploit is largely absent, and so is the telemetry that would reveal such attacks.
  • Protection quality spans a 15-point band (60–75/100) on identical entitlements. The variation is configuration drift, not licensing — every gap identified is fixable within the current plan.
  • The highest-value property carries disproportionate risk. The flagship peoplefinders.com (payments, accounts, API hub) runs its WAF in log-only mode with an unproxied API surface.
  • Edge-bypass exposure is the most urgent risk class — several domains publish DNS records that route around Cloudflare entirely (unproxied API, admin panel, or origin hostnames).
  • Every domain faces the same adversary: continuous commercial-scale scraping from the same cloud/hosting networks (Google Cloud, DigitalOcean, VNPT, Linode, AWS) and ad-tech crawlers (SirdataBot, Integral Ad Science) — a shared problem with shared solutions.
  • A proven internal template already exists — fastbackgroundcheck.com demonstrates the target state (active WAF + layered defense on a clean perimeter). Estate-wide uplift is largely a replication exercise.

2. Domain Ranking

2.1 By Security Maturity (config depth, layering, WAF enforcement) — best first

#DomainWhy
1fastbackgroundcheck.comOnly domain with an active enforcing WAF; genuine layered defense (WAF + custom + challenge + rate limit + DDoS) on a clean perimeter
2cyberbackgroundchecks.comBroadest, heaviest rate limiting (31M events) + DDoS L7 + dual challenge; only missing the signature WAF
3usphonebook.comEnforcing, targeted rate limiting + heavy custom rules; WAF deployed but skipped
4peoplefinders.comFullest ruleset & only Advanced cert, but WAF in log-only mode + edge/origin exposure
5advancedbackgroundchecks.comOnly domain with an active security-level reputation layer; bot challenge strong; WAF off
6searchpeoplefree.comStrong rate limiting, but WAF off and an unproxied admin panel
7usa-people-search.comClean perimeter, but WAF near-zero and rate limiting negligible
8actualpeoplesearch.comActive, well-targeted rate limiting, but thin custom rules, no WAF, near-zero caching
9smartbackgroundchecks.comWAF completely inactive; modest rate limiting; single-tier
10fastpeoplesearch.comWAF inactive, rate limiting inert despite heavy tuning, ~100% of blocks in one rule

2.2 By Cloudflare Effectiveness (observed threat containment) — most effective first

#DomainSignal
1fastbackgroundcheck.com54% block rate, active WAF, 92.8% challenge abandon, layered
2cyberbackgroundchecks.com40% block rate, 25.7M rate-limited, 96.6% abandon, DDoS active
3fastpeoplesearch.com48% block rate, 93.5% abandon — extremely effective today (but fragile, one rule)
4searchpeoplefree.com34.6% block rate, 17.8M rate-limited, 94.5% abandon
5usphonebook.com22.9% block rate, 27M rate-limited, 96.5% abandon
6smartbackgroundchecks.com21.2% block rate, 91.5% abandon, targeted rate limits
7usa-people-search.com27% block rate, 83.8% abandon (rate limiting weak)
8actualpeoplesearch.comLow 403 (2.3%) but 11.4% rate-limited; primary threat actively contained
9peoplefinders.com94.7% abandon, but WAF log-only and API bypasses the edge — effectiveness holes
10advancedbackgroundchecks.com95.5% abandon but lowest attack pressure (least "tested"), WAF off, origin bypass

2.3 By Operational Risk — highest risk first

#DomainRiskPrimary driver
1peoplefinders.comHIGHPayments/accounts/API flagship; unproxied API, origin+RFC1918 in DNS, WAF log-only, no enforcing rate limit
2searchpeoplefree.comHIGHUnproxied admin panel bypasses all protection; WAF off; heaviest-attacked
3fastpeoplesearch.comHIGHSingle-rule single point of failure; WAF off; rate limiting inert
4smartbackgroundchecks.comHIGHWAF 0 events on a dynamic /search.php surface
5usphonebook.comHIGHWAF skipped; origin-bypass DNS records; highest traffic
6cyberbackgroundchecks.comHIGH (low end)Most-attacked; WAF off — but strongest behavioral defense
7advancedbackgroundchecks.comMEDIUMWAF off + fastly-origin bypass; but lowest attack pressure
8usa-people-search.comMEDIUMWAF off + rate limiting weak; but clean perimeter
9actualpeoplesearch.comMEDIUMThin depth, no WAF; but active rate limiting + clean DNS + small
10fastbackgroundcheck.comMEDIUM (lowest)Active WAF, layered, clean DNS — only incremental gaps

2.4 By Bot Protection Readiness — most ready first

(All ten have Bot Management entitled and scoring live traffic; ranking reflects challenge effectiveness + rate-limit backstop + WAF support.)

  1. fastbackgroundcheck.com — BM + active WAF + rate limit + 92.8% abandon
  2. cyberbackgroundchecks.com — BM + 96.6% abandon + heaviest rate limit + DDoS + dual challenge
  3. usphonebook.com — BM + 96.5% abandon + enforcing targeted rate limit
  4. searchpeoplefree.com — BM + 94.5% abandon + strong rate limit
  5. cyber-parity: actualpeoplesearch.com — BM + rate-limit-driven challenge (~99% abandon) on its enumeration surface
  6. smartbackgroundchecks.com — BM + 91.5% abandon + targeted rate limit
  7. peoplefinders.com — BM + 94.7% abandon, but no enforcing rate-limit backstop
  8. advancedbackgroundchecks.com — BM + 95.5% abandon + security level, but rate limiting negligible
  9. fastpeoplesearch.com — BM + 93.5% abandon, but rate limiting inert (challenge is the only mechanism)
  10. usa-people-search.com — BM + 83.8% abandon (lowest) + rate limiting negligible

3. Comparison Table

DomainScoreRiskHuman % (scored)Automated % (scored)Block Rate (403)Challenge Rate (issued)Protection MaturityPriority
fastbackgroundcheck.com75MEDIUM30%64%54.0%~37%Layered — active WAFP4 (template)
usphonebook.com68HIGH46%33%22.9%~18%Strong behavioral; WAF skippedP2
cyberbackgroundchecks.com68HIGH (low)40%43%40.0%~33%Strongest rate limit + DDoS; WAF offP2
peoplefinders.com65HIGH29%55%11.7%~5%Full stack; WAF log-only; API bypassP1
actualpeoplesearch.com64MEDIUM50%38%2.3% (+11.4% RL)~13%Rate-limit-led; thin custom; no WAFP3
usa-people-search.com63MEDIUM41%37%27.0%~13%Single-tier; WAF off; RL weakP3
advancedbackgroundchecks.com63MEDIUM59%27%11.7%~6%Behavioral + reputation; WAF off; origin bypassP3
searchpeoplefree.com62HIGH28%45%34.6%~20%Strong RL; WAF off; admin bypassP1
smartbackgroundchecks.com61HIGH43%30%21.2%~13%Single-tier; WAF 0; dynamic searchP2
fastpeoplesearch.com60HIGH43%51%48.4%~29%Single-rule; WAF 0; RL inertP1

Priority key: P1 = urgent (bypass exposure / flagship / single point of failure); P2 = high-value gap; P3 = standard uplift; P4 = maintain/replicate.


4. Strongest Protected Domains

1. fastbackgroundcheck.com — the reference standard (Score 75). The only domain where the managed WAF is actually enforcing (millions of signature blocks), giving it true defense-in-depth: signature WAF + custom rules + bot challenge + rate limiting + DDoS L7, all on a clean, fully-proxied perimeter. It contains a heavy scraping campaign (54% of traffic 403'd, 92.8% challenge abandonment) and retains attack telemetry the other nine lack. Its remaining gaps are incremental (widen rate limiting, turn on security level), not structural. This is the template for the estate.

2. cyberbackgroundchecks.com (Score 68). The estate's strongest behavioral defender: the heaviest and broadest rate limiting (31M events across record/lookup endpoints), active DDoS L7, and dual challenge layers, achieving a 96.6% abandonment rate on the most-attacked property — all on a clean perimeter. The single missing piece is the signature WAF.

3. usphonebook.com (Score 68). Highest traffic in the estate, defended with genuinely enforcing, well-targeted rate limiting (27M events) and heavy custom blocking (117.9M blocks, 96.5% abandon). Held back by a skipped managed WAF and origin-bypass DNS records.

What the leaders share: rate limiting that actually fires on the right endpoints, high challenge-abandonment, and (for fastbackgroundcheck) an active WAF. The gap between #1 and the rest is almost entirely whether the WAF is switched on.


5. Highest Risk Domains

1. peoplefinders.com (HIGH — P1). The crown jewel carries the crown-jewel risk: it is the payments, accounts, and API hub, yet its API subdomain is unproxied (bypasses every control), its DNS exposes origin and internal RFC1918 addresses, its WAF runs in log-only mode, and it has no enforcing rate limit. Highest business value + real bypass paths = top of the list.

2. searchpeoplefree.com (HIGH — P1). Publishes an unproxied admin panel that resolves straight to its Azure origin — an internet-exposed administrative surface with zero edge protection and no security telemetry — on top of an inactive WAF, while absorbing the heaviest relative attack pressure.

3. fastpeoplesearch.com (HIGH — P1). The most fragile posture: 99.99% of all blocking comes from a single custom rule, with no WAF backstop and a rate limiter that is heavily configured but fires almost never. Extremely effective today, but one misconfiguration from collapse.

4–6. smartbackgroundchecks.com, usphonebook.com, cyberbackgroundchecks.com (HIGH). All defend well behaviorally but run the managed WAF inactive on dynamic/API surfaces (/search.php, /api/*), and two of them (usphonebook) publish origin-bypass DNS records.

What the high-risk domains share: an inactive signature WAF combined with either an edge-bypass path or a single point of failure. The behavioral controls are often strong; the structural gaps are what elevate the risk.


6. Common Estate Weaknesses (recurring)

  1. Managed WAF not enforcing — the dominant estate-wide gap. 9 of 10 domains run the managed WAF / OWASP ruleset inactive, skipped, or log-only. Only fastbackgroundcheck.com enforces it. The estate has broad bot defense but almost no signature/exploit defense — and no WAF-layer attack telemetry on nine domains.
  2. Edge/origin bypass paths in DNS. Roughly half the estate publishes unproxied records that route around Cloudflare: unproxied API (peoplefinders), admin panel (searchpeoplefree), fastly-origin/origin hostnames (usphonebook, advancedbackgroundchecks), and an origin IP (fastpeoplesearch).
  3. Rate limiting is wildly inconsistent. From excellent and broad (cyber 31M, usphonebook 27M, searchpeoplefree 17.8M) to negligible or inert (fastpeoplesearch 9.8K despite heaviest tuning, usa-people-search 15K, advanced 42K, peoplefinders log-only). No estate standard.
  4. Security level (reputation challenge) off almost everywhere. Only advancedbackgroundchecks.com shows it active. A cheap reputation layer is unused across the estate.
  5. Single-rule concentration. Most domains route 90–99.99% of blocks through one custom rule — a resilience risk with no signature backstop behind it.
  6. Country filtering not applied as a standard. Foreign traffic runs at 95–99%+ threat rates across the estate, yet handling is per-domain and inconsistent rather than a shared baseline.
  7. Universal-only certificates. Only the flagship uses an Advanced certificate; the rest rely on Universal certs (one had an expired backup pack).
  8. Unverifiable hardening + likely Page Shield gaps. SSL mode, HSTS, min-TLS, and Page Shield status were not confirmable under the audit token on any zone — a governance/visibility gap in itself, and Page Shield is likely off estate-wide on data-collection properties.

7. Common Estate Strengths

  1. Bot Management is entitled and active on all 10 domains — live bot scoring everywhere, including the smallest zone.
  2. Managed Challenge is the estate's most reliable control — 83–99% challenge-abandonment on every domain; the workhorse against scraping.
  3. Custom firewall rules do real, heavy enforcement everywhere — tens to hundreds of millions of blocks/challenges per domain.
  4. The full managed ruleset stack is already deployed in inventory on every zone (OWASP, Cloudflare Managed, Exposed Credentials, DDoS L7, Normalization) — activating the WAF is a switch-on, not a purchase.
  5. Enterprise plan, valid TLS, near-universal HTTPS (96–99%+ encrypted) across the estate.
  6. Several domains have genuinely clean DNS (fastbackgroundcheck, cyberbackgroundchecks, usa-people-search, smartbackgroundchecks, actualpeoplesearch) — no origin exposure.
  7. A proven internal reference implementation exists (fastbackgroundcheck.com) — the target state is already running in production.
  8. Consistent, well-attributed adversary — the same scrapers recur estate-wide (Google Cloud, DigitalOcean, VNPT, Linode, AWS; SirdataBot / Integral Ad Science; the GoDaddy IP 92.204.248.55), making a shared blocklist immediately effective.

8. Executive Observations (CTO lens)

  1. One systemic fix outranks all others: turn the managed WAF on. It is inactive on 9 of 10 domains despite being paid for and deployed — the estate is paying for signature defense it isn't using.
  2. We are defending against bots, not against attacks. Scraping is well-contained; injection/exploit defense and its telemetry are largely absent. We would not currently see a successful exploit attempt on most domains.
  3. The gap is configuration, not budget. A 15-point spread on identical Enterprise entitlements means the uplift is operational discipline — no new licensing required.
  4. The flagship is the least-proportionately-protected asset. peoplefinders.com holds payments, accounts, and the API, yet runs WAF in log-only mode with an unproxied API. Risk and business value are inverted here.
  5. Bypass paths are the fastest way an attacker skips everything we built. Unproxied API, admin, and origin records on several domains make the rest of the security stack irrelevant for those paths — fix these first.
  6. We already own the blueprint. fastbackgroundcheck.com proves the target posture works in production; the program is "make the other nine look like this one."
  7. Resilience is quietly fragile. Most domains hang their entire blocking function on a single custom rule; a routine change could silently drop protection with no backstop.
  8. Rate limiting has no standard. The same control ranges from best-in-class to non-functional across domains — a shared baseline (which endpoints, what thresholds) would close most of the variance.
  9. One adversary, ten front doors. The identical scraper set hitting every domain means estate-level controls (shared blocklist, standard country/ASN handling) pay off ten times per change.
  10. Governance, not heroics, closes this. A short standard — WAF enforcing, rate-limit baseline, security level on, DNS hygiene (no unproxied origins), Page Shield on payment/data sites — applied uniformly would raise the entire estate and eliminate the drift that produced this spread.

Rendered verbatim from reports/ESTATE-WIDE-cloudflare-security-comparison-2026-07-25.md. This view is presentation only — the source document is authoritative and is never modified, summarised, or reformatted by this application.