I’m using Cloudflare Acces with Cloudflare Teams to block acces to the /wp-admin/ directory of my website. I noticed that some features that use Ajax on my website are not working anymore.

Checking the Firewall Activity log it looks like blocking /wp-admin/admin-ajax.php is the problem. What is the best way to bypass access to /wp-admin/admin-ajax.php?

Website: https://112barneveld.nl
Load more, rating and the Poll is not working.

Why are you blocking wp-admin? That directory doesn’t do any good for someone who can’t get past wp-login. My Access App only covers wp-login.php

So you’re saying blocking /wp-login.php is secure enough?

It’s secure enough for me. I don’t see people attacking wp-admin. Just login and plugins.

Set 444 on wp login even more fun.

Set fail2ban with cloud flare ban combination 444 filter, and report them to abuseipdb auto too.

I got this and honeytraps, cleans them right up.

Thing is even if you block just that, they often mass scan. If you use Nginx I can post my nignx location block and fail2ban.

Love banning malicious bots lol.

Thanks for all the input! I appreciate that!


