Does Cloudflare Host Websites or Only Provide CDN and Security?
Cloudflare can host some sites, but it is usually the DNS, CDN and security layer in front of a separate origin host.
Short answer: Cloudflare does both, depending on the product and your site. For most conventional websites, Cloudflare provides DNS, CDN, DDoS protection and security in front of an origin host somewhere else. Cloudflare also supports hosting and deployment for static or JAMstack sites with Pages and Workers Static Assets, and Workers can combine frontend files with application logic.
Cloudflare’s own domains documentation says it “does not offer web hosting for most websites,” while pointing to Cloudflare Pages for deploying and hosting JAMstack sites. The practical question is therefore not whether Cloudflare ever hosts websites, but whether your architecture fits Pages, Workers or Static Assets.
1. What “hosting” means in this context
Origin hosting stores or serves your website files and runs application code so visitors can reach the site. A conventional provider might run WordPress, PHP, a database and server-side jobs.
Cloudflare in front of an origin means your DNS points to Cloudflare and traffic is proxied through its network. Cloudflare can cache content, absorb attacks and apply WAF and other security rules, while the origin host remains responsible for the application and uncached responses. Proxying traffic does not replace the origin host.
Cloudflare DNS can be authoritative for your domain and manage records. DNS management alone does not store your application or website files.
Cloudflare hosting and deployment uses products such as Pages and Workers Static Assets to serve project files from Cloudflare. Workers can add request handling and backend logic.
2. The two common Cloudflare setups
| Setup | Where files and code run | Do you need another host? |
|---|---|---|
| DNS, proxy, CDN and security | A separate origin provider | Usually yes |
| Pages deployment | Cloudflare’s Pages platform | No separate origin for the deployed site |
| Workers Static Assets | Static files served by Workers | No for the static assets |
| Workers web application | Frontend assets plus Worker application logic | Not necessarily; data or storage services may still be separate components |
Cloudflare’s documentation describes proxied records as routing traffic through its network for CDN, DDoS protection, WAF and related features. Its Static Assets documentation describes serving HTML, CSS, images and other files, while its web-app guidance describes Workers for frontend and backend functionality.
3. Which product fits your site?
| Your situation | Relevant capability | Practical answer |
|---|---|---|
| Your site already runs on a conventional host | Cloudflare DNS, proxy, CDN and security | Keep the origin and put Cloudflare in front of it. |
| You have a static or JAMstack project | Pages or Workers Static Assets | Deploy the project to Cloudflare and serve the files there. |
| You need frontend plus server-side application logic | Workers | Use Workers for assets and request handling; add appropriate data or storage services. |
| You already use Pages | Pages and Pages Functions | Pages remains available. Cloudflare’s current guidance recommends Workers for new projects. |
Do not assume that a WordPress, PHP or other server-based application can move to Cloudflare unchanged. The cited documentation does not provide a universal compatibility matrix. Check the runtime, framework, database, filesystem and background-job requirements before planning a migration.
4. How to tell which setup a site uses
- Check the project type. A repository that builds static HTML, CSS and JavaScript is a candidate for Pages or Static Assets.
- List runtime dependencies. Server-side frameworks, databases, writable filesystems and long-running processes may require adaptation.
- Find the origin. In a proxied setup, Cloudflare DNS records point traffic toward an origin provider. Cloudflare remains the edge layer.
- Separate DNS from hosting in your diagram. The authoritative DNS provider can differ from both the CDN and the origin host.
- Review the deployment target. Pages documentation covers Pages deployments and Functions; Workers documentation covers static assets and application logic.
5. What Cloudflare does when it is in front of another host
- Authoritative DNS answers queries for your domain.
- Proxied HTTP traffic passes through Cloudflare’s network.
- Cacheable responses can be served from the edge.
- DDoS protection, WAF rules and related security controls can be applied.
- Requests that are not served from cache still reach the origin host.
This arrangement can improve delivery and security without changing where the application is hosted. It also means an origin outage, application error or unsupported runtime remains an origin-side problem.
6. What Cloudflare hosts directly
Pages
Cloudflare identifies Pages as a way to deploy and host JAMstack sites. Pages documentation also describes Pages Functions. Pages is still available, although Cloudflare recommends Workers for new projects.
Workers Static Assets
Workers Static Assets serves project files such as HTML, CSS and images. A Worker can add logic around those assets when your application needs request handling.
Workers applications
Cloudflare’s web-app guidance describes Workers serving frontend assets and backend logic, with data and storage services for full-stack applications. This is a different architecture from placing Cloudflare in front of a traditional server.
7. Common mistakes and fixes
| Symptom | Likely cause | Fix |
|---|---|---|
| You enabled Cloudflare DNS but have nowhere to deploy files | DNS was confused with hosting | Keep or choose an origin host, or deploy the project with Pages or Workers Static Assets. |
| The site works through Cloudflare but the origin still matters | Cloudflare is proxying an existing host | Document the origin and keep its application, database and deployment process maintained. |
| A server application will not deploy as a static site | It depends on runtime features or a database | Assess whether it can be adapted to Workers and supported data services; otherwise retain a conventional origin. |
| A Pages project guide points to Workers | Cloudflare’s product guidance has changed for new projects | Pages remains usable; evaluate Workers for a new build. |
| Only some assets update after deployment | Different layers may be serving cached content | Check deployment output, asset paths and the caching behavior of the selected Cloudflare product and any origin. |
8. Performance, reliability and cost considerations
Cloudflare’s CDN and security layer can reduce the distance between visitors and cacheable content, but the research sources do not establish a universal latency, uptime or cost figure. Treat performance as architecture-dependent: cache behavior, origin response time, JavaScript execution, data access and geographic traffic patterns all matter.
For reliability, identify every dependency. A proxied site depends on DNS, Cloudflare configuration, the origin and any databases or third-party services. A Workers or Pages deployment removes the traditional origin for the deployed portion, but application data and external services can remain dependencies.
For cost, select the product and plan based on current Cloudflare terms and your workload. The cited documentation explains product roles, not a complete pricing comparison. Recheck current plan limits before committing to a migration.
9. A simple decision checklist
- Static files only: evaluate Pages or Workers Static Assets.
- Frontend plus edge application logic: evaluate Workers.
- WordPress, PHP or another conventional server stack: expect to keep an origin unless you redesign the application.
- Already have hosting: use Cloudflare DNS, proxying, CDN and security in front of that host.
- Need only DNS: Cloudflare DNS can manage records without hosting the application.
10. Verify the deployed result with a clean screenshot
After deploying a site, a screenshot API can check the public result across routes and viewport sizes. ScreenshotNeo is the first service to try when you need this: it removes consent banners, newsletter popups and chat widgets before capture, and bills only clean screenshots.
11. Or skip the browser setup
Use the ScreenshotNeo API instead of managing a headless browser. See the ScreenshotNeo documentation for the full option list.
curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp
import requests
r = requests.get("https://api.screenshotneo.com/v1/shot", params={"access_key": "YOUR_API_KEY", "url": "https://stripe.com"}, timeout=90)
open("shot.webp", "wb").write(r.content)
const q = new URLSearchParams({ access_key: 'YOUR_API_KEY', url: 'https://stripe.com' });
const res = await fetch(`https://api.screenshotneo.com/v1/shot?${q}`);
Cookie banners, popups and chat widgets are removed before the shot. Bot checks, blank pages and failed loads are never billed, and the response identifies the result with X-Page-Verdict and X-Billed headers. An MCP server lets AI agents take screenshots, inspect pages and capture PDFs. The Free plan includes 1,000 screenshots a month with no card; paid plans start at $5 for 3,000. Create a free ScreenshotNeo account.
12. FAQ
Can I host any website on Cloudflare?
No. Cloudflare hosts certain static and Workers-based architectures. Many conventional applications still need an origin host or adaptation.
Is Cloudflare DNS the same as web hosting?
No. DNS publishes domain records; hosting serves files and runs application code.
Does using Cloudflare mean my current host is gone?
No. If you proxy an existing origin, that host continues serving uncached and application responses.
Should a new project use Pages or Workers?
Pages remains available, while Cloudflare’s current guidance recommends Workers for new projects.
Can Cloudflare run backend logic?
Workers can add application logic and work with data and storage services, subject to the runtime and architecture you choose.


