WordPress 6.0+ PHP 7.4+ Free · GPL v1.29.0 WordPress.org: in review

The edge layer for WordPress. Not another cache plugin.

Nivoli Edge does not touch your render path. It ships no minification, no critical CSS, no script deferral, no lazy loading, and that is deliberate: keep WP Rocket, FlyingPress or Perfmatters if you run one. Nivoli owns the four things a plugin cannot reach. Time to first byte, because whole pages come from the Cloudflare node nearest each visitor instead of your one server. Uptime, because the edge keeps serving when your origin stops. Security enforced before PHP. And numbers measured at the edge, where no plugin can see them. The first two apply to visitors who are not logged in, which is most traffic on most sites; if yours is a membership site or an LMS, read this first. One plugin, one dashboard: let us run the edge for you, or bring your own Cloudflare.

Nivoli Edge dashboard: 59% of 4.05M requests answered at the edge in 30 days
A real month on the managed edge: 2.37M of 4.05M requests answered before they reached the server, 178 GB of bandwidth the origin never carried. One dashboard for images and pages.
Fast
Time to first byte, not a score
Whole HTML pages and images answered by the Cloudflare node nearest each visitor, not a round-trip to your one server. 59% of traffic never touched the origin on the site below, last 30 days.
Stays up
Outages become non-events
Origin Shield serves the cached site for up to 7 days while your server is down, and emails you.
Defended
Attacks die before PHP runs
Login floods, XML-RPC abuse, AI crawlers and junk URLs stopped at the edge: 55k+ in a fortnight on the same site.
Measured
Analytics without cookies
Pageviews, countries, referrers and devices from the edge. No script, no consent banner.

Traffic numbers are live measurements from one real production site on the managed edge (the screenshots on this page), not averages or projections. Your numbers depend on traffic shape and cache fit.

Where we fit

We don't replace your optimizer. We sit in front of it.

What an optimizer owns

Minification, critical CSS, unused-CSS removal, script deferral, lazy loading, font handling: the render path, inside PHP and inside the browser. WP Rocket, FlyingPress, NitroPack and Perfmatters do that work well. Nivoli Edge ships none of it, on purpose. Entering that category would mean shipping a worse version of a product that has iterated for a decade.

What the edge owns

Time to first byte, from the node nearest your reader. Uptime, because cached pages keep serving for up to 7 days when your server stops. Enforcement before PHP, so login floods and scanners never reach your code. Surgical purge, so publishing does not flush your cache. Real numbers, measured on traffic you already serve. Run both. They do not overlap.

The same logic as running Wordfence alongside us: security plugins inspect requests inside PHP, the edge stops junk before PHP starts. Different layers, no conflict.

The plugin is free. The managed edge is the product.

Every feature that runs on your own server is free, forever. A Nivoli subscription runs the CDN and page cache for you (no Cloudflare account, plan, or DNS work) and lights the plugin up with live edge analytics, URL rules, and security shields. Paste a key, done in under a minute.

See managed plans

Stays up · managed

Your server can go down. Your site doesn't.

Outages become non-events

When your server errors or stops responding, the edge switches to serving the cached copy of your site, for up to 7 days, automatically. Visitors keep browsing; Google keeps crawling. You get an email the moment the shield engages and another when your server recovers. No monitoring service to configure, no status page scramble.

Honest incident history

Every outage is logged with real durations, and single-request blips are kept apart from actual incidents, so the history reads like what happened, not like noise. It's the difference between "the site was down for 40 minutes last night" and never knowing.

Included on every managed plan, on by default, nothing to configure. The shield serves pages that were cached, so it covers your public pages; a logged-in member's own page views are not cached and are not covered. More on that below.

Defended · managed

Dead URLs die at the edge. Your server never renders them.

410 blocks for dead routes

Old CMS ghosts, probe paths, scanner favorites: one regex rule answers them with a cached 410 Gone at the edge, with per-rule fired counts so you can see each rule paying its rent.

301/302 redirect manager

Map moved and legacy URLs to their new homes, served straight from the edge with hit tracking. Your origin never renders a redirect again.

One-click block from the error log

The Recent Errors panel shows exactly which junk URLs hammer your origin. Blocking one is a single click; it becomes an edge rule on the spot.

What-was-blocked visibility

A live log of everything the rules caught, by path and rule, windowed from 6 hours to 7 days. You see the junk you no longer pay to serve. Cache-purge triggers can be locked to your own IPs, too.

Defended · managed

Seven shields, all enforced before PHP starts.

Wordfence and Sucuri inspect requests inside PHP, which means your server has already booted WordPress to decide it did not want the request. These run at Cloudflare, before that. Nobody else in the cache category owns pre-PHP enforcement.

Block stray PHP

Every direct .php request except your real entry points gets a 404 at the edge, so scanners probing wp-config.php, wp-load.php and plugin files never reach your server. It can also watch before it blocks: monitor mode runs the identical check and lists the real paths it would have stopped, measured on your own traffic, without changing a single response. Evidence first, enforcement when you are ready. Growth and up.

wp-admin IP lock

/wp-admin restricted to your own IPs and CIDR ranges, enforced before PHP. A self-lockout guard refuses a list your current address is not on, and the 403 page carries an email self-rescue flow for the day you travel. admin-ajax.php stays open so the front end keeps working. Growth and up.

Login rate limiting

10 attempts per 10 minutes per IP. A brute-force run gets a cached 429 from the edge instead of your login form, so the flood costs you nothing. Self-healing: you cannot lock yourself out. Growth and up.

AI-crawler blocking

One switch. GPTBot, ClaudeBot, CCBot, Bytespider, Google-Extended and PerplexityBot get a 403 before they consume your bandwidth or train on your writing. Verified search engines are never affected, so this costs you no traffic. Growth and up.

Login country lock

wp-login.php answers only the countries you list; everyone else gets a 403 at the edge. Continent quick-add buttons included, and the form keeps you from removing the country you are sitting in. 55.6K login attempts stopped in 14 days on the site below. Every plan.

XML-RPC off, headers on

/xmlrpc.php answered with a cached 410, killing the classic amplification and password-spray target. One more switch adds the security headers pack: HSTS, X-Content-Type-Options, X-Frame-Options, Referrer-Policy and a conservative Permissions-Policy. Your own header values always win. Every plan.

Edge security pane: attack-surface tiles, XML-RPC blocked, login country lock with 55.6K logins stopped in 14 days
Edge shields on a live site: 55.6K login attempts and 1.8K XML-RPC hits stopped in 14 days, AI-crawler blocking, wp-admin IP lock, login rate-limiting, and a one-switch security headers pack. All enforced before PHP ever runs.

Edge controls · managed

The knobs that decide what the edge keeps.

Cache duration, per path

One lifetime never fits a whole site. Give /news/ minutes and /about a week, per path, and let stale-while-revalidate serve the old copy instantly while the edge fetches the new one behind it. Visitors never wait on your server.

Query params

?utm_*, ?fbclid and unknown junk collapse into the cached page instead of splitting your cache into thousands of near-identical copies, while real functional params keep working. A campaign link and a bare link become one cache entry.

Cache protection

Purge triggers locked to your own IPs, so nobody else can make your site rebuild itself. If your origin runs its own micro-cache (nginx fastcgi, Varnish) the pane hands you the exact snippet to keep the two layers from fighting.

Speculative loading

When a visitor hovers a link, Chrome renders that page in the background, so the click lands on a page that is already there. The rules ride a response header pointing at a file we serve, so your theme's HTML is never modified. Prerendering runs the target page's JavaScript, so action links are excluded: cart, checkout and admin paths, anything carrying add-to-cart or a nonce, and WooCommerce's own button classes. Those are query params and CSS classes rather than page names, so they hold in any language. Logged-in visitors are never sent the rules, since their pages bypass the cache anyway. Off by default, with measured reach and origin cost beside the switch. Every managed plan.

Dynamic content stays dynamic

A cart is not a cacheable page. Cart, checkout and account pages bypass the cache, along with any visitor carrying a WooCommerce cart or session cookie, so one shopper is never served another shopper's cached cart. That part is a floor, not a setting: it holds even with no plugin installed, and the paths are anchored so a page like /carts-and-crates stays cached. The edge also obeys your own origin: anything you mark no-store is never kept. no-cache and private are softer, so they are counted first and enforced only when you ask, with the measured cost shown next to the switch.

If your members log in

Membership, LMS and forum sites: read this before you buy.

A logged-in visitor's pages are never cached, by design: caching a page built for one member and serving it to another is the one mistake a cache must not make. So on a site where the audience is signed in, the two claims at the top of this page land differently. We would rather you read that here than discover it after paying.

Works no matter who is logged in

Security before PHP, because the shields run before WordPress boots and never consult a cookie: login floods, XML-RPC, AI crawlers and stray-PHP probes die at the edge whoever the visitor is. Image delivery and every transform. Edge analytics, including what your members request most. Surgical purge, so publishing still does not flush your cache.

Works for everything public

Your sales page, course catalog, pricing, blog and forum pages a guest can read are cached and shielded normally. On most member sites this is the majority of traffic, and it is the traffic that decides whether somebody signs up in the first place.

Does not apply to signed-in page views

A member's own page views go to your server. That means no edge time to first byte on those pages, and no outage coverage for them either, since Origin Shield can only serve a page that was cached. Your public pages stay up during an outage; the members' area does not.

What we are not doing

We have not built per-user cache buckets or edge-side includes, and we are not going to imply we have. If your members' page views are the traffic that needs to be faster, an origin-side cache or better hosting will move that number and we will not. Said plainly so you can decide.

Measured · managed

Know your traffic. Without the tracking script.

Human pageviews, countries, referrers and devices, measured at the edge from requests you're already serving. No JavaScript snippet, no cookies, no consent banner needed, and bots are counted separately instead of inflating your numbers. A monthly digest lands in your inbox; the full panel lives in WP admin.

Countries come from Cloudflare's own geolocation, aggregated per country: no visitor-level data is ever stored.

Stats and audience pane: hour-by-hour traffic, human pageviews vs bots, top referrers and visitor countries
A live fortnight: 829k pageviews split into 383k humans and 446k bots, hour-by-hour cache traffic, top referrers, and where visitors actually are.

See what the edge does for your site.

Fourteen days, full features, a card at checkout but nothing billed until the trial ends. The dashboard shows your own offload, shield and security numbers within the first hour of traffic.

Start the 14-day trial

Fast · images

Every image fully optimized. Never a byte bigger than needed.

Right-sized, every time

Each image is served at the exact dimensions its slot needs, per device and pixel density, generated on the fly from your one original. No 2000-pixel photo squeezed into a 300-pixel column ever again.

The lightest format the browser supports

WebP or AVIF automatically per visitor, falling back gracefully for old browsers. Typically 60–90% smaller than the original file, with no visible quality loss.

Nothing escapes

Thumbnails, srcset, Gutenberg blocks, WooCommerce, inline content, CSS backgrounds, lazy-load attributes: rewritten at the WordPress filter boundary, so theme quirks are covered too.

No migration, no storage bill

Your originals stay exactly where they are. Variants render at the edge and are cached on the Cloudflare node nearest each visitor, so images arrive fast worldwide; nothing is duplicated, re-uploaded, or held hostage.

Safe by default

If a transform ever fails, or you hit your plan's cap, the original image serves straight from your site. Visitors never see a broken image; worst case is an unoptimized one.

The library itself gets healthier

Tinify compression shrinks oversized originals in place (backup kept), and the fake-image scanner finds and repairs corrupt files pretending to be images.

Fast · pages

The whole page, from the node nearest your visitor.

Not just less server load, faster pages

Most caching plugins still render on, or fetch from, your one server in one location. Nivoli caches the full HTML across Cloudflare's global network, so a reader in Sydney gets the page from Sydney and a reader in Berlin from Berlin, no round-trip to your origin. Lower time-to-first-byte for every visitor, not just a lighter load on you.

Surgical, not scorched-earth

Every cacheable page carries Surrogate-Key tags describing what it's built from. A save purges only the pages featuring that post; the rest of the cache stays hot, and stale-while-revalidate means visitors never wait on your server for a cached page. Works with Fastly, Cloudflare Enterprise, a custom webhook, or the managed Nivoli edge.

The files the page loads, too

Stylesheets, scripts and fonts are answered by the Cloudflare node nearest your reader rather than your one server, so a visitor on the other side of the world stops paying a round trip for every file the page pulls in, and your server keeps its PHP workers for rendering pages instead of handing out static files. How long browsers hold those files stays exactly what your server already sets: we do not shorten it and we do not stretch it. Every managed plan.

What it actually does

Plain HTTP, nothing magic.

# Images: rewritten at render time, transformed at the edge
<img src="/wp-content/uploads/2026/hero.jpg">
  → <img src="https://img.yoursite.com/cdn-cgi/image/w=800,f=auto/wp-content/uploads/2026/hero.jpg">

# Pages: every response carries the tags it was built from
Surrogate-Key: post-42 category-7 author-3 home

# One post save → one surgical purge of just those tags
POST /purge  { "keys": ["post-42", "category-7", "home"] }

Setup

Running in three steps.

1 · INSTALL

Install the plugin

From WordPress.org (listing in review) or the managed welcome email. Activate; image host and path prefix auto-detect.

2 · CONNECT

Pick your edge

Managed: paste the license key and the CDN provisions itself. Self-hosted: point at your own Cloudflare zone + your Fastly/CF-Enterprise/webhook purger.

3 · VERIFY

Probe it

One click on the Dashboard fetches a real image through the pipeline and confirms end-to-end delivery. The dashboard then shows exactly what the edge carries for you.

Built for production sites

Operational from day one. All free.

Coverage audit

Weekly re-run, email when optimization regresses.

Fake-image scan & repair

Finds error pages saved as .jpg, fixes them in place.

Runtime misses log

Unoptimized stragglers grouped into one-click rules.

Prewarming, alerts & self-test

Re-warms after saves; failures email you; weekly self-check.

Rules, presets & size mapping

One-click mapping from your theme's sizes, catch-all included.

Client report, WP-CLI & debug overlay

Printable white-label report, full CLI, on-page debug badges.

The managed edge adds

What a plugin alone can't do.

Managed image CDN + page cache

Zero Cloudflare setup: we run the zone and the full-page cache, so there is no account, plan or DNS work on your side. Custom hostname (img.yoursite.com) and CDN-level watermarking on higher plans.

Origin Shield + audience analytics

Stale-serving through outages with an email when the shield engages and when it recovers, plus cookieless visitor analytics. Both measured from real edge traffic no plugin can see.

Insight a plugin cannot reach

Most-missed URLs, broken images found from real 404s, heaviest images, per-URL cache stats, and a 404 inbox that turns dead traffic into rules in one click. Your server never saw these requests, so no plugin could have told you.

Agency console, outside WordPress

A console at console.nivoli.com, signed in by magic link, no password to share with a team. A needs-attention list that ranks real failures above cosmetic ones, a security posture matrix covering all seven shields across every site, fleet-wide purge, a one-click security baseline, and a Manage link into any single site. Business and Agency plans.

All of it connects with one license key. Plans from €15/mo, 14-day trial.

Get it

Two ways to start. Both take minutes.

Self-hosted: free forever

GPL-2.0-or-later, any number of sites, no account, nothing phones home. Every locally-running feature included: audits, prewarming, alerts, repair tools, reports, Tinify with your own key. Bring your own Cloudflare zone for images and your own Fastly / CF Enterprise / webhook for pages.

Read the setup docs →

WordPress.org listing in review; until it's live, any trial or plan email delivers the plugin zip.

Managed: the edge, run for you

The same plugin plus everything on this page: Origin Shield, edge security, audience analytics, the CDN and page cache, zero Cloudflare setup. Paste the license key from the welcome email; provisioning is automatic. From €15/mo, 14-day free trial, cancel anytime.

Start the 14-day trial Compare plans

Questions? support@nivoli.com