Title: Nivoli Edge
Author: calimonk
Published: <strong>3 سپتامبر 2026</strong>
Last modified: 26 سپتامبر 2026

---

جستجوی افزونه‌ها

![](https://ps.w.org/nivoli-edge/assets/banner-772x250.png?rev=3681289)

![](https://ps.w.org/nivoli-edge/assets/icon-256x256.png?rev=3680272)

# Nivoli Edge

 توسط [calimonk](https://profiles.wordpress.org/calimonk/)

[دانلود](https://downloads.wordpress.org/plugin/nivoli-edge.1.81.3.zip)

 * [جزئیات](https://fa.wordpress.org/plugins/nivoli-edge/#description)
 * [نقد و بررسی‌ها](https://fa.wordpress.org/plugins/nivoli-edge/#reviews)
 *  [نصب](https://fa.wordpress.org/plugins/nivoli-edge/#installation)
 * [توسعه](https://fa.wordpress.org/plugins/nivoli-edge/#developers)

 [پشتیبانی](https://wordpress.org/support/plugin/nivoli-edge/)

## توضیحات

Every WordPress security plugin runs inside the site it protects. When the site 
is taken over, so is the plugin: its settings page belongs to the intruder, its 
rules can be switched off, and every attack it inspects has already reached PHP 
on your server.

Nivoli Edge runs one layer up. Twelve shields refuse attacks, floods, scanners and
stray PHP requests at Cloudflare’s edge, before a single byte reaches your server.
Three locks keep the settings behind an email confirmation held at the edge, so 
a hacked WordPress cannot switch a shield off, install a plugin, or redirect the
confirmation address. The same edge serves whole HTML pages from the node nearest
each visitor and keeps the site up when your server goes down. Every number, what
was refused, what was served, who did what, shows inside WP admin.

**Free and managed, in one sentence:** the plugin is free and GPL, and everything
that runs on your own server works without an account; the shields, the locks, the
edge cache and the numbers run on the managed edge, which you connect with an API
key. Right-sized WebP and AVIF images from the edge are an optional add-on for the
sites that want them.

#### The Edge Security layer

Wordfence and Sucuri run inside the site they protect. This runs one layer up, at
the edge, and the site cannot reach it.

**Twelve shields, refused before PHP.** Your server never boots PHP to turn a request
away.

 * Login flood limit (10 attempts per 10 minutes per address)
 * Comment flood limit (5 posts per 5 minutes per address)
 * Search flood limit (30 searches per 5 minutes per address)
 * XML-RPC block (a cached 410)
 * Login country lock (wp-login answers only the countries you list)
 * wp-admin IP lock (your own addresses, with a self-lockout guard and an email 
   rescue)
 * AI-crawler block (GPTBot, ClaudeBot, CCBot and friends; search engines never 
   affected)
 * Stray-PHP lock (every .php request except the real WordPress entry points gets
   a 404)
 * WordPress surface lock (the REST users list, ?author=N, readme.html, license.
   txt, the installer, debug.log)
 * Security-headers pack (HSTS, nosniff, frame and referrer policies; your own values
   win)

All of them come with every managed plan. The stray-PHP and surface locks have a
monitor mode that lists what blocking would have stopped before it blocks anything.

**Three locks, nothing inside the site can turn off.** A takeover of your WordPress
admin owns every plugin’s settings page. Ours refuses to act on WordPress’s say-
so.

 * Change lock: any change that weakens protection waits for a click on a link mailed
   to the license holder; the link applies exactly that change, once.
 * Install lock: plugin and theme installs, uploads, updates, deletes and the file
   editors are refused site-wide until a 15-minute window is opened the same way.
   Automatic updates and WP-CLI run on the server and are never affected.
 * Origin lock: the edge stamps a per-site secret on every request it forwards and
   the plugin refuses code changes that arrive without it, so knowing the server’s
   address is no longer a way around the locks. A self-test reports whether the 
   server enforces it.

**Evidence: who did what, from where.**

 * Refused installs named by plugin, and every refused attempt in your inbox as 
   it happens.
 * A lock activity log with time and address for every unlock request, clicked link,
   confirmation and lock change.
 * An attack-surface strip per fortnight, a monthly report by email, and for agencies
   a posture matrix across every site.

Underneath all of it, Cloudflare’s managed WAF rulesets, including the WordPress
rule set, run in front of every managed site.

#### Pages served from the edge

Full-page HTML caching with surgical purge: only the pages featuring a changed post
refresh, never the whole cache.

 * Surrogate-Key / Cache-Tag headers on every cacheable page; purges go to Nivoli,
   Fastly, Cloudflare Enterprise or your own webhook.
 * Logged-in visitors, carts and checkout always bypass.
 * Stylesheets, scripts and fonts from the edge too, on versioned addresses, so 
   no browser or CDN node holds a stale file after a purge.
 * Origin shield: if your server goes down, the edge keeps serving the last good
   copy of every cached page for up to 7 days and emails you when it engages and
   when the origin recovers.

#### Images served from the edge

URLs rewrite through Cloudflare Image Resizing into right-sized WebP/AVIF variants
on the fly. No uploads, no duplicate copies, no migration, no theme changes.

 * Per-size presets, one-click Size mapping from your theme’s registered sizes, 
   a catch-all for everything else.
 * Broken, heavy and fake images found from real traffic, with where each is used
   and one-click fixes; heavy originals shrink through Tinify.

#### The numbers, inside WP admin

 * What the edge answered and what it refused, by window, with the most-requested
   and most-missed URLs.
 * Dead URLs on a Recent 404s page with one-click redirect or block; a Search Console
   404 export imported, matched to your own pages and turned into redirect and block
   rules family by family; All rules: one ordered list of every edge rule with per-
   rule counts and reordering.
 * Audience without a tracking script: humans versus bots, countries, referrers,
   devices, served-from-cache speed.
 * Static assets: edge hit rate per file type and which files still travel on plain
   addresses.
 * A monthly report by email, white-label copies for clients on Agency.

#### Free versus managed

Free, on your own infrastructure, no account: image URL rewriting through your own
Cloudflare zone (native WP filters, srcset, Gutenberg, WooCommerce, the_content 
and full-page scan), image rules and size mapping, page-cache tag headers with surgical
purge to Fastly, Cloudflare Enterprise or your webhook, prewarm on save, coverage
audit with a weekly regression email, fake-image detection and repair, purge-failure
alerts, a weekly header self-test, a printable client report, the debug overlay,
and WP-CLI.

Managed, with a Nivoli API key: everything in The Edge Security layer above, the
managed page cache (no Cloudflare account, plan or DNS work), origin shield, URL
rules and the 404 inbox, per-path cache duration, the query-param manager, cache
protection, dynamic-content safety for WooCommerce, edge insights and the monthly
report, custom image hostname and watermarking, and for agencies a fleet console
with one key across sites.

Managed Images, the optional add-on: right-sized WebP and AVIF variants created 
once at the edge and served from the node nearest each visitor, no Cloudflare account
and no plugin configuration. Without it your images serve from your own server, 
untouched; the free image tools keep working.

#### Requirements

 * **Free:** a Cloudflare zone with **Image Resizing** enabled for the image half(
   Pro+ plan or per-1000 pricing); a tag-aware edge (Fastly / CF Enterprise / your
   webhook) for the page-cache half. If Image Resizing isn’t enabled the rewritten
   URLs 404; the Tools tab has a one-click probe to verify.
 * **Managed:** none of the above for pages and security; for images, the Managed
   Images add-on. Just an API key from your Nivoli account.

### External services

The free tier’s core image rewriting sends **no data to any external service**; 
it only rewrites `<img>` URLs in your site’s HTML so browsers fetch through your
own Cloudflare zone. Beyond that, the plugin contacts external services only for
the specific, opt-in features listed below.

**Nivoli managed edge** (api at html-caching-admin.nivoli.workers.dev, dashboard
at console.nivoli.com): used **only if you enter an API key**. On activation and
on a daily background re-check it sends your API key, this site’s URL, the plugin
version, and the list of broken-image file paths you have marked handled (so the
monthly report can exclude them; these are addresses the CDN already sees in its
own traffic) to validate the key and provision your managed CDN/page-cache tenant;
it then reads back the aggregate usage statistics shown on the dashboard. If you
configure monthly reports or alerts, the recipient email address and optional report
branding (a name and logo URL) are stored with your account. No visitor data is 
ever sent. Terms: https://nivoli.com/terms · Privacy: https://nivoli.com/privacy

**Cloudflare** (api.cloudflare.com): used **only if you configure the Cloudflare
Enterprise page-cache backend** with your own API token, to dispatch tag-based cache
purges when your content changes. Terms: https://www.cloudflare.com/terms/ · Privacy:
https://www.cloudflare.com/privacypolicy/

**Fastly** (api.fastly.com): used **only if you configure the Fastly page-cache 
backend** with your own API token, to dispatch surrogate-key purges on content change.
Terms: https://www.fastly.com/terms/ · Privacy: https://www.fastly.com/privacy/

**TinyPNG / Tinify** (api.tinify.com): used **only if you add your own Tinify API
key and click “Shrink original”** on an image, to compress that source file. Only
the image you choose is sent. Terms & Privacy: https://tinify.com/terms

## عکس‌های صفحه

[⌊Overview: what the edge did for you in the last 30 days. Delivered, Protected 
and your plan at work, with 30-day trends, under the five tabs Overview, Security,
Pages, Images and Account.⌉⌊Overview: what the edge did for you in the last 30 days.
Delivered, Protected and your plan at work, with 30-day trends, under the five tabs
Overview, Security, Pages, Images and Account.⌉[

Overview: what the edge did for you in the last 30 days. Delivered, Protected and
your plan at work, with 30-day trends, under the five tabs Overview, Security, Pages,
Images and Account.

[⌊Edge shields: the attack surface strip (XML-RPC, logins, AI crawlers, comment 
and search floods) and every shield with its switch, enforced before your server.
Every shield on every managed plan.⌉⌊Edge shields: the attack surface strip (XML-
RPC, logins, AI crawlers, comment and search floods) and every shield with its switch,
enforced before your server. Every shield on every managed plan.⌉[

Edge shields: the attack surface strip (XML-RPC, logins, AI crawlers, comment and
search floods) and every shield with its switch, enforced before your server. Every
shield on every managed plan.

[⌊Locks: change lock, install lock and origin lock, what they refused in the last
14 days with the exact plugin named, and the lock activity log with a filter for
state changes only.⌉⌊Locks: change lock, install lock and origin lock, what they
refused in the last 14 days with the exact plugin named, and the lock activity log
with a filter for state changes only.⌉[

Locks: change lock, install lock and origin lock, what they refused in the last 
14 days with the exact plugin named, and the lock activity log with a filter for
state changes only.

[⌊Security check: what this WordPress exposes, measured from inside it and from 
one visit to its own front door, with what this plugin can switch off and what the
managed edge already refuses.⌉⌊Security check: what this WordPress exposes, measured
from inside it and from one visit to its own front door, with what this plugin can
switch off and what the managed edge already refuses.⌉[

Security check: what this WordPress exposes, measured from inside it and from one
visit to its own front door, with what this plugin can switch off and what the managed
edge already refuses.

[⌊Probe shields: stray PHP, enumeration, traversal probes and the scanner lockout,
with off, monitor and block for each and the refusal counts.⌉⌊Probe shields: stray
PHP, enumeration, traversal probes and the scanner lockout, with off, monitor and
block for each and the refusal counts.⌉[

Probe shields: stray PHP, enumeration, traversal probes and the scanner lockout,
with off, monitor and block for each and the refusal counts.

[⌊Stats and overview: hour-by-hour traffic, origin offload, hit rates by window,
surgical purges.⌉⌊Stats and overview: hour-by-hour traffic, origin offload, hit 
rates by window, surgical purges.⌉[

Stats and overview: hour-by-hour traffic, origin offload, hit rates by window, surgical
purges.

[⌊Heaviest images: the files costing the most bandwidth, one-click Tinify shrinking,
and what the shrinking has saved so far.⌉⌊Heaviest images: the files costing the
most bandwidth, one-click Tinify shrinking, and what the shrinking has saved so 
far.⌉[

Heaviest images: the files costing the most bandwidth, one-click Tinify shrinking,
and what the shrinking has saved so far.

[⌊Redirects: legacy URLs answered at the edge, patterns and exact rules with usage,
unused rules folded away.⌉⌊Redirects: legacy URLs answered at the edge, patterns
and exact rules with usage, unused rules folded away.⌉[

Redirects: legacy URLs answered at the edge, patterns and exact rules with usage,
unused rules folded away.

[⌊Recent 404s: paths your server keeps answering with a 404, with bot share and 
one-click redirect or block.⌉⌊Recent 404s: paths your server keeps answering with
a 404, with bot share and one-click redirect or block.⌉[

Recent 404s: paths your server keeps answering with a 404, with bot share and one-
click redirect or block.

[⌊Your audience: humans versus bots, served-from-cache speed, referrers, devices
and countries, no tracking script.⌉⌊Your audience: humans versus bots, served-from-
cache speed, referrers, devices and countries, no tracking script.⌉[

Your audience: humans versus bots, served-from-cache speed, referrers, devices and
countries, no tracking script.

[⌊Static assets: edge hit rate for stylesheets, scripts and fonts, versioned addresses,
bandwidth offloaded.⌉⌊Static assets: edge hit rate for stylesheets, scripts and 
fonts, versioned addresses, bandwidth offloaded.⌉[

Static assets: edge hit rate for stylesheets, scripts and fonts, versioned addresses,
bandwidth offloaded.

[⌊Query params: which parameters split the cache, which are guarded, with one-click
collapse.⌉⌊Query params: which parameters split the cache, which are guarded, with
one-click collapse.⌉[

Query params: which parameters split the cache, which are guarded, with one-click
collapse.

[⌊Hardening: eight things WordPress exposes by default, one click each, with the
ones the edge already refuses grouped and saying so.⌉⌊Hardening: eight things WordPress
exposes by default, one click each, with the ones the edge already refuses grouped
and saying so.⌉[

Hardening: eight things WordPress exposes by default, one click each, with the ones
the edge already refuses grouped and saying so.

[⌊Broken images: failed image requests from the last 7 days, files gone from disk
with a placeholder ready, and the momentary failures that handled themselves.⌉⌊Broken
images: failed image requests from the last 7 days, files gone from disk with a 
placeholder ready, and the momentary failures that handled themselves.⌉[

Broken images: failed image requests from the last 7 days, files gone from disk 
with a placeholder ready, and the momentary failures that handled themselves.

## نصب

 1. Upload the plugin and activate it (or paste your API key on the **Account** tab;
    the managed edge provisions itself and fills the settings in for you).
 2. Free / bring-your-own-zone: open **Nivoli Edge  Settings**, confirm the auto-detected
    image host + path prefix, toggle Enabled.
 3. Add rules under **Image rules** if specific sizes need specific treatment, or let**
    Size mapping** create them from your theme’s registered sizes in one click. Catch-
    all handles the rest with zero config.
 4. For HTML caching, open **Settings  Page cache** and pick a backend (managed Nivoli
    with your API key, or your own Fastly / CF Enterprise / webhook).
 5. The **Dashboard** shows whether everything’s working and what the edge is doing
    for you.

## سوالات متداول

### Does this replace Wordfence or Sucuri?

It sits above them. Those plugins inspect requests inside WordPress, after PHP has
started; Nivoli Edge refuses hostile traffic at Cloudflare’s edge before your server
sees it, and its settings cannot be switched off from inside a compromised WordPress.
Run both if you like; they do not overlap.

### What do the twelve shields stop?

Login, comment and search floods, XML-RPC abuse, logins from countries you do not
serve, wp-admin from addresses that are not yours, AI crawlers, direct requests 
to PHP files that are not WordPress entry points, the probes that map a site (user
lists, readme, license file, installer, debug.log), path traversal attempts in any
encoding, addresses that keep probing after five refusals, and missing security 
headers. All twelve come with every managed plan.

### Does this require Cloudflare Pro?

Only for the free image rewriting on your own zone: Cloudflare Image Resizing is
bundled with Pro plans or available pay-as-you-go. The managed edge needs no Cloudflare
account at all.

### Will this break my theme?

No. The plugin only modifies URLs at the filter boundary; the HTML structure your
theme outputs is unchanged. Use the `no-cf` CSS class on any element to opt out.

### How is this different from Smush / ShortPixel / Optimole?

Those plugins compress and re-host images on their own CDN. Nivoli Edge transforms
on the fly from your origin: no asset duplication, no migration step, no storage
bill.

### What’s the difference between Free and Managed?

Everything the plugin does on your own server is free and fully functional: image
rewriting, page-cache purging, audits, prewarming, alerts, reports. Nothing phones
home. An API key connects the plugin to the Nivoli managed edge: we run the Cloudflare
zone and page cache for you (no Cloudflare setup at all) and the service adds what
a plugin alone can’t, such as edge-side usage statistics, per-URL traffic insights,
edge URL rules and security shields, custom hostnames, watermarking, and multi-site
fleet management.

### What if I lose access to my license email?

Confirmation and unlock links go to the email address on your Nivoli license and
nowhere else; that is what makes the locks hold against a takeover. Support can 
move the license to a new address after verifying you own it. Until then the locks
stay as they are and the site keeps running; only changes that weaken protection
wait.

### Does the install lock break automatic updates?

No. Automatic background updates run from wp-cron on your server and WP-CLI runs
on the box; neither passes through the edge, so neither is affected. Only installs,
uploads, updates and deletes started from wp-admin are refused, and you open a 15-
minute window by email when you want to do one yourself.

### What if my site gets hacked anyway?

The locks stop the intruder from switching the shields off, installing anything 
through WordPress, or redirecting the confirmation address, and every attempt lands
in your inbox and on the Locks page with its time and address. What no edge control
can do is undo code already running on your server: cleaning the box is still yours(
scan, restore, rotate). The locks make sure the compromise stays where it landed.

### Does the page caching conflict with my security plugin (Wordfence, Sucuri)?

No. Different layers: security plugins inspect requests inside WordPress/PHP; Nivoli
Edge’s twelve shields run at Cloudflare’s edge, before the request reaches your 
server. It sheds junk traffic so your origin and your security plugin only see real
visitors. They complement each other.

### Do I need to change my nginx / web-server config?

Only if your origin runs its own micro-cache (nginx fastcgi/proxy cache, Varnish)
and you use the manual purge trigger; the Cache protection pane shows the exact 
one-line snippet. A standard PHP-FPM origin needs no server changes at all.

## نقد و بررسی‌ها

نقد و بررسی‌ای برای این افزونه یافت نشد.

## توسعه دهندگان و همکاران

“Nivoli Edge” نرم افزار متن باز است. افراد زیر در این افزونه مشارکت کرده‌اند.

مشارکت کنندگان

 *   [ calimonk ](https://profiles.wordpress.org/calimonk/)

[ترجمه “Nivoli Edge” به زبان شما.](https://translate.wordpress.org/projects/wp-plugins/nivoli-edge)

### علاقه‌ مند به توسعه هستید؟

[کد را مرور کنید](https://plugins.trac.wordpress.org/browser/nivoli-edge/)، [مخزن SVN](https://plugins.svn.wordpress.org/nivoli-edge/)
را بررسی کنید، یا از طریق [RSS](https://plugins.trac.wordpress.org/log/nivoli-edge/?limit=100&mode=stop_on_copy&format=rss)
در [گزارش توسعه](https://plugins.trac.wordpress.org/log/nivoli-edge/) مشترک شوید.

## گزارش تغییرات

Recent releases are listed below. The full history for every version is in CHANGELOG.
md, which ships with the plugin, and on the GitHub releases page.

#### 1.81.3

Screenshots redone for the five-tab admin: Overview, Edge shields, Locks, Security
check, Probe shields, Stats, Heaviest images and Static assets reshot, Hardening
and Broken images added.

#### 1.81.2

Lock activity shows its first 25 entries with a Show older button for the rest, 
a checkbox to hide unlock and confirmation requests so lock changes stay in view,
and the exact time on hover. The edge now keeps up to 200 state changes for good
and 200 requests for 90 days.

#### 1.81.1

The side rail says which panes are free, managed or the add-on again, as a word 
on the group heading, or on the odd item in a mixed group. Tinify moved under Account,
Connection.

#### 1.81.0

A dot on a rail item, and on its tab, means something is waiting there: findings
exposed at the last check, a change waiting for your emailed click, shields still
monitoring, broken, heavy or fake images, a license that needs attention. Only while
true, never a nag.

#### 1.80.6

The floods finding tells the three limiters apart: partly on when one or two are
on, with each one named. A finding the edge could refuse but has off, or partly 
off, on this site gets a Switch on at the edge button that lands on the pane with
the switch.

#### 1.80.5

The side rail loses its tier dots; they read as unread markers on every item.

#### 1.80.4

The edge pill on a finding tells the truth for that finding: on this site, on but
not seen yet (the edge reports it on, the probe still saw it), off on this site,
or with the managed edge. A Hardening switch the check still sees exposed is no 
longer grouped as covered. Also fixes a stray closing tag on the Hardening pane 
that let the page footer float up.

#### 1.80.3

Hardening: the switches are grouped, off, on, and already refused by the edge; the
off pill is readable.

#### 1.80.2

Security check and Hardening, clearer: the edge note on each finding is a block 
of its own with a pill saying whether this site has it; every fixable finding links
to the switch behind it; on a managed site the Hardening switches the edge already
covers say so and read Turn on as well; the copy says plainly that Turn on applies
at once and the must-use file is the copy that keeps enforcing when the plugin is
off.

#### 1.80.1

The setup checklist knows when it is done: the key in, the site behind the edge,
one shield and one lock on. After that it shrinks to a small Recommended card with
only what is still worth doing, dismissable on the Overview; the Account tab keeps
the list.

#### 1.80.0

The security check now reads past what WordPress shows about itself: must-use files
and drop-ins on disk that WordPress does not list, administrators in the database
that the Users screen does not show, hooks on the login and user filters from must-
use, drop-in or theme files, and the hash of your own must-use hardening file, with
one click to accept a file you regenerated. Integrity checks, not a malware scanner:
a plugin one layer above the site can make them when the site itself has started
lying.

#### 1.79.2

Every shield on every plan: the AI-crawler block, the wp-admin IP lock and enforcing
origin cache directives no longer need Shield Plus. Plans differ in sites, pageviews,
history and reports, never in how safe the site is. Needs edge admin-v2.43.2.

#### 1.79.1

Security, tidied after a first look: the scanner lockout sits with the other probe
shields; the login rate limit, the login country lock and the wp-admin IP lock share
one Login & admin pane; the security check groups its findings (exposed, worth fixing,
what only the edge refuses, and the fine ones folded away with a count), shows nothing
to press on a finding that is already fine, and reads “refused at the edge” in green
on a managed site. Images opens on Coverage, with Health above Optimization.

#### 1.79.0

The admin is regrouped by what you are doing: Overview, Security, Pages, Images 
and Account replace the Managed Edge, Tools and Settings tabs. Every pane kept its
place in old links and mails. Free and managed panes sit together under their subject,
marked by a dot; a free install sees the managed panes folded into one “Switch on
the edge” line per tab. New under Security: a Hardening pane with eight switches(
the five the check offered, plus the version in asset URLs and headers, head clutter
and minor core updates) and a generated must-use plugin that keeps them on when 
this plugin is off.

## اطلاعات

 *  نگارش **1.81.3**
 *  آخرین به‌روزرسانی **3 روز پیش**
 *  نصب‌های فعال **کمتر از 10**
 *  نگارش وردپرس ** 6.2 یا بالاتر **
 *  آزمایش‌شده تا **7.1.2**
 *  نگارش PHP ** 7.4 یا بالاتر **
 *  زبان
 * [English (US)](https://wordpress.org/plugins/nivoli-edge/)
 * برچسب
 * [cache](https://fa.wordpress.org/plugins/tags/cache/)[cloudflare](https://fa.wordpress.org/plugins/tags/cloudflare/)
   [firewall](https://fa.wordpress.org/plugins/tags/firewall/)[performance](https://fa.wordpress.org/plugins/tags/performance/)
   [security](https://fa.wordpress.org/plugins/tags/security/)
 *  [نمایش پیشرفته](https://fa.wordpress.org/plugins/nivoli-edge/advanced/)

## امتیازها

هنوز هیچ نقدی ارسال نشده است.

[بررسی شما](https://wordpress.org/support/plugin/nivoli-edge/reviews/#new-post)

[مشاهدهٔ همهٔ بررسی‌ها](https://wordpress.org/support/plugin/nivoli-edge/reviews/)

## مشارکت کنندگان

 *   [ calimonk ](https://profiles.wordpress.org/calimonk/)

## پشتیبانی

چیزی برای گفتن دارید؟ نیاز به کمک دارید؟

 [مشاهده انجمن پشتیبانی](https://wordpress.org/support/plugin/nivoli-edge/)