We are currently reviewing our WAF rules in Cloudflare and based on the documentation here (Fields reference · Cloudflare Ruleset Engine docs),
the field cf.threat_score will be deprecated on 2024-09-30.
What can we use instead of this field, so that our rules will not be impacted?
Hi @gabriela.corsatea and thanks for flagging this! Since February of 2024, we have silently released a new security system that automatically combines the IP threat score with a traffic threshold and a botnet tracking system. This new system supersedes and replaces the existing Security Level logic (including the cf.threat_score) and is available to all customers on all plans, and also eliminates the need for customers to set a sensitivity level.
You may choose to review and edit or delete these existing rules. Rest assured, the automatic protections we have implemented will ensure your security remains uncompromised.