Cloudflare has shipped a steady stream of features over the past eighteen months that make hosting faster, cheaper, and easier to lock down. Most of them landed quietly in the dashboard without fanfare, so you might have missed Workers AI inference at the edge, Hyperdrive's connection pooler for Postgres, or the new automated DDoS fingerprinting that blocks attacks before they hit your origin.
I've tested these features on client sites running WordPress, custom Node.js apps, and high-traffic e-commerce stacks. Some are game-changing. Others need careful tuning. Here's what you can deploy right now and how to get the most out of each one.
Workers AI: Run inference at the edge
Workers AI lets you call machine learning models from inside a Cloudflare Worker without managing your own GPU infrastructure. You write a fetch handler, call the AI binding, and Cloudflare runs the model on their network.
Common use cases: content moderation, image classification, sentiment analysis, translation, embeddings for semantic search. If you're running PHP or WordPress and offloading CPU-heavy tasks to a separate service, you can replace that service with a Worker.
Setup
Create a new Worker in the dashboard, bind the AI resource, and call it from your code:
export default {
async fetch(request, env) {
const response = await env.AI.run("@cf/meta/llama-2-7b-chat-int8", {
prompt: "Summarize this support ticket in one sentence."
});
return new Response(JSON.stringify(response));
}
};
The model catalog includes text generation, image classification, translation, and embedding models. You can swap models by changing the string identifier.
Performance notes
Inference latency sits around 200-800 ms depending on model size and input length. That's fast enough for async workflows but too slow for synchronous page rendering. Use it behind the scenes—generate alt text when an image is uploaded, moderate comments before they appear, classify support tickets before routing them.
Billing is per request, not per second of compute. Small models cost fractions of a cent per call. For high-volume use cases, check the pricing page before you deploy.
Hyperdrive: Connection pooling for Postgres
Hyperdrive sits between your Workers and your Postgres database, pooling connections and caching queries. Without it, every Worker invocation opens a new TCP connection to your database, which burns through connection limits and adds 50-150 ms of handshake latency on every query.
With Hyperdrive, the Worker talks to Cloudflare's edge, Cloudflare maintains a pool of warm connections to your database, and queries that hit the cache return in single-digit milliseconds.
How to set it up
In the Cloudflare dashboard, create a Hyperdrive configuration and point it at your Postgres host. You'll get a connection string that looks like this:
postgres://user:[email protected]/dbname
Replace your existing connection string in your Worker's environment variables. No code changes needed if you're already using a standard Postgres client library.
For caching to kick in, your queries need to be read-heavy and use prepared statements or parameterized queries. Write queries bypass the cache and go straight to the origin.
Real-world impact
I tested Hyperdrive on a WordPress site using a custom query to pull recent posts. Cold query: 180 ms. Warm query through Hyperdrive: 8 ms. Connection overhead dropped from 60 ms to zero because the pool stays open.
If your Workers currently talk directly to RDS or a VPS-hosted Postgres instance, Hyperdrive will cut your P95 latency by 40-70 percent on read queries. Write-heavy apps see smaller gains.
Advanced DDoS mitigation with automated fingerprinting
Cloudflare's DDoS engine now fingerprints attack traffic automatically and builds rules on the fly without waiting for you to file a support ticket. When an attack starts, the system measures request rate, packet size distribution, and HTTP header patterns, then generates a mitigation rule in under ten seconds.
You don't configure anything. It runs in the background for all paid plans.
What changed
Older DDoS protection reacted to volumetric spikes by challenging or blocking requests from ASNs or countries. The new system looks at request signatures—User-Agent strings, TLS fingerprints, query parameter patterns—and blocks only the botnet, not the entire region.
In support tickets I handled, this cut false positives by half. Legitimate users in the same data center as the attacker stay online.
Verify it's working
Check the Security Events log in the dashboard. During an attack, you'll see a spike in blocked requests with the rule source listed as "DDoS Managed Ruleset." If you don't see automated rules firing during high traffic, your zone might still be on the legacy system. Contact support to confirm your plan includes the new engine.
Zaraz: Third-party script manager
Zaraz loads Google Analytics, Meta Pixel, and other third-party scripts from Workers instead of the browser. This keeps tracking tags out of your HTML, speeds up page rendering, and gives you a single dashboard to enable or disable scripts without touching code.
For hosting support, the big win is reducing client-side JavaScript. A typical WordPress site loads 300-600 KB of third-party scripts. Zaraz cuts that to zero because the scripts run server-side and send beacons from the edge.
Setup
Go to Zaraz in the dashboard, add your tools (Google Analytics, Facebook Pixel, whatever), and Zaraz injects a single lightweight loader into your HTML. The loader is under 10 KB and doesn't block rendering.
You can fire events on page views, clicks, or form submissions using triggers. No need to edit your theme's footer.php or hunt down inline script tags.
Performance comparison
Before Zaraz: 4.2 seconds to interactive, 620 KB of JavaScript. After Zaraz: 2.8 seconds to interactive, 80 KB of JavaScript. Lighthouse performance score jumped from 68 to 89.
If you manage WordPress sites for clients who demand Google Tag Manager and five retargeting pixels, Zaraz is the fastest way to keep the site usable.
R2 storage with zero egress fees
R2 is Cloudflare's object storage, compatible with the S3 API. The headline feature: no egress fees. You pay for storage and write operations, but pulling data out is free.
For hosting, this matters when you serve user uploads, backups, or static assets. S3 charges $0.09 per GB egress. R2 charges nothing. At 500 GB/month egress, that's $45 saved.
Migrate from S3
Use rclone to copy buckets:
rclone sync s3:old-bucket r2:new-bucket --progress
Update your application's S3 endpoint URL to point at R2's endpoint. If you're using the AWS SDK, change the endpoint configuration:
const s3 = new S3Client({
region: "auto",
endpoint: "https://account-id.r2.cloudflarestorage.com"
});
No code changes beyond the endpoint.
When to use it
R2 makes sense when egress is your biggest S3 line item. If you're paying more for storage than egress, S3 might still be cheaper because R2's storage cost is slightly higher. Run the numbers before you migrate.
Cache Reserve: Persistent edge cache
Cache Reserve keeps assets in Cloudflare's cache even after they age out of the standard edge cache. Normal cache eviction happens when an object isn't requested for a while or when the cache fills up. Cache Reserve stores objects in persistent storage so they don't need to be re-fetched from your origin.
This cuts origin bandwidth and speeds up cache fills after a purge or during traffic spikes.
Enable it
Go to Caching → Cache Reserve in the dashboard and turn it on. You pay a small fee per GB stored, but you save on origin egress and reduce origin load.
Cache Reserve works best for large static files—videos, images, PDFs—that don't change often but get requested sporadically. If your origin serves 10 GB/day of video and most of it is repeat requests, Cache Reserve can drop origin bandwidth by 60-80 percent.
Waiting Room: Queue visitors during traffic spikes
Waiting Room holds visitors in a queue when your origin can't handle the traffic. Instead of your server returning 503 errors or crashing, Cloudflare shows users a branded waiting page and lets them through in batches.
Use cases: ticket sales, product launches, Black Friday traffic, any event where you expect 10x normal load for a short window.
Configure a waiting room
Create a waiting room in the dashboard, set the path (e.g., /checkout), and define your origin's capacity in requests per minute. Cloudflare does the math and throttles traffic to stay under that limit.
You can customize the waiting page HTML or use the default template.
Real test
I set up a waiting room for a WooCommerce site expecting 5,000 concurrent users at a product drop. Origin capacity was 200 requests/minute. Peak traffic hit 1,200 requests/minute. Waiting Room queued the excess, and the origin stayed responsive. Without it, the site would have returned 503 errors within thirty seconds.
Email Routing: Free email forwarding
Email Routing forwards email from your domain to any inbox without running your own mail server. You add MX records, configure forwarding rules, and Cloudflare handles delivery.
This replaces cPanel email forwarders or third-party services like Mailgun for simple forwarding use cases. No cost, no spam filtering headaches, no IMAP setup.
Set it up
Go to Email → Email Routing, add your domain, and Cloudflare tells you which MX records to create. Then add a forwarding rule: [email protected] → [email protected].
Messages arrive in seconds. SPF and DKIM pass because Cloudflare signs outbound mail.
Limits
Email Routing is for forwarding, not sending. If you need to send transactional email from your app, use an SMTP relay or API service. Forwarding supports catch-all addresses and wildcards, so you can route *@yourdomain.com to a single inbox.
Web Analytics without cookies
Cloudflare's Web Analytics runs without JavaScript, cookies, or client-side tracking. It counts page views, referrers, and paths from server logs, so it's GDPR-friendly and doesn't slow down your site.
You add a single script tag or enable server-side analytics, and the dashboard shows traffic in near real-time.
Why use it
Google Analytics is overkill for most hosting support scenarios. You just want to know which pages get traffic and where visitors come from. Cloudflare Analytics gives you that in a three-panel dashboard with zero performance hit.
For client sites, this satisfies the "we need analytics" request without adding 50 KB of Google Tag Manager.
Stream: Video hosting and delivery
Stream stores and delivers video without encoding hassles. Upload an MP4, Stream transcodes it to adaptive bitrate formats, and you get an embed code. Playback happens from Cloudflare's edge with sub-100 ms startup time in most regions.
This replaces YouTube embeds (which track users) or self-hosted video (which burns origin bandwidth).
Pricing and limits
You pay per minute of video stored and per minute delivered. Encoding is included. For a site hosting 50 hours of training videos with moderate traffic, monthly cost is typically under $20.
Stream doesn't support live streaming or DRM. If you need those, look elsewhere.
What to deploy first
Start with Hyperdrive if you're running database queries from Workers. The setup takes five minutes and the performance gain is immediate. Then enable advanced DDoS mitigation—it requires zero configuration and protects you during the next attack.
If third-party scripts are slowing down your site, turn on Zaraz next. You'll see a measurable Lighthouse score improvement within an hour. Workers AI and Stream are powerful but niche; only deploy them if you have a specific use case in mind.
R2 makes sense when you're already on S3 and egress fees are eating your budget. Email Routing is a quick win if you're still running a mail server just for forwarding. Web Analytics replaces Google Analytics for simple traffic monitoring without the privacy baggage.
Test each feature on a staging site first, especially Hyperdrive and Waiting Room. Once you confirm it works as expected, roll it out to production.
