Run WordPress Behind the CDN
Every hosted site is served through the CDNShark CDN. WordPress works out of the box, and a few things are handled for you.
Already handled
- HTTPS: WordPress sees secure requests as HTTPS, so there are no redirect loops and no "mixed content" from wrong URLs. One-click installs use
https://and force HTTPS for the admin area. - Real visitor IPs: your site sees each visitor's real IP address, not the CDN's. Security plugins, comments and logs work correctly.
- Login protection:
wp-login.phpandxmlrpc.phpare rate-limited per visitor, and repeated login attempts get the IP banned for an hour. Bots hammering the login page can't slow your site down. - Uploads can't run code: PHP files inside
wp-content/uploadsare never executed, which stops the most common WordPress hack.
Tips
- Set WordPress Address and Site Address (Settings → General) to
https://your-domain. - After a theme change or a big update, if visitors still see the old version, use Clear the CDN Cache for Your Sites.
- You don't need a separate CDN plugin. If your caching plugin offers "CDN URL" rewriting, leave it empty: your normal domain already goes through the CDN.
- Uploads up to 128 MB work through the Media Library.
Moving an existing WordPress site
Coming from cPanel? Migrate from cPanel moves files and the database and updates wp-config.php for you. From anywhere else, see Move an Existing Website to CDNShark Hosting.