Decloak is an AI-powered web security intelligence platform that scans a site's HTTP/TLS posture, JavaScript, and third-party scripts to produce a report anyone can read. This guide is part of Decloak's library of practical, source-backed security guidance.
In this guide
- Key takeaways
- Does Cloudflare Pages encrypt traffic for GitHub - driven sites?
- What security headers can I enforce from my GitHub repo?
- How do redirects work and what limits apply?
- Are there any build or file - size constraints I should watch?
- Can I run server - side code securely?
- How do I protect my GitHub token used for deployment?
- What additional security does Cloudflare provide?
- How can I verify the security posture of my deployed site?
- What steps should I take after a scan flags issues?
- Where can I find more detailed guidance?
Key takeaways
- Cloudflare Pages automatically provides HTTPS and built - in DDoS mitigation for any site linked to a GitHub repository.
- The free tier limits you to 20 000 files, 25 MiB per asset and a single concurrent build; larger projects need a paid plan.
- Secrets such as GitHub tokens must never be baked into the static output because Page Functions run on the Workers runtime and do not protect hard - coded credentials.
- Use
_headersand_redirectsfiles within the repository to enforce security headers and safe redirect rules, staying under the 100 - rule and 2 100 - rule limits. - Monitor build quotas and file counts via the Cloudflare dashboard to avoid silent failures that could expose incomplete deployments.
Does Cloudflare Pages encrypt traffic for GitHub - driven sites?
Yes, every site deployed through Cloudflare Pages receives a TLS certificate automatically, so visitors always connect over HTTPS. This protects data in transit even though the source code lives on GitHub. The TLS certificate is managed by Cloudflare and renewed without manual steps.
What security headers can I enforce from my GitHub repo?
You can add a _headers file at the project root. Each rule may be up to 2 000 characters and you can define up to 100 rules. Typical headers include Content - Security - Policy, Strict - Transport - Security, X - Content - Type - Options and Referrer - Policy. Example snippet:
/*
Strict-Transport-Security: max-age=31536000; includeSubDomains
X-Content-Type-Options: nosniff
Referrer-Policy: same-origin
These directives are applied by Cloudflare’s edge cache before the response reaches the client.
How do redirects work and what limits apply?
Create a _redirects file in your repository. You may list up to 2 000 static redirects and 100 dynamic redirects, for a total of 2 100 entries. A simple permanent redirect looks like:
/old - path /new - path 301
Dynamic redirects can use query parameters and capture groups, but each line still counts toward the limit. Exceeding the limit will cause the build to fail.
Are there any build or file - size constraints I should watch?
Yes. On the free plan you can store up to 20 000 files and each asset must be 25 MiB or smaller. If you need larger files, upload them to Cloudflare R2 and reference them from your static pages. Paid plans raise the file count ceiling to 100 000 and increase concurrent builds (5 for Pro, 20 for Business). Builds time out after 20 minutes, so long - running compile steps must be optimized or moved to a separate CI system.
Can I run server - side code securely?
Pages Functions let you add Workers - style JavaScript that runs at the edge. These functions count against your Workers quota and follow the standard Workers security model. However, they do not hide secrets; any token embedded in the function code can be extracted from the deployed script. Store secrets in Cloudflare Workers KV or environment variables and reference them at runtime, never commit them to the GitHub repo.
How do I protect my GitHub token used for deployment?
When you connect a GitHub repository, Cloudflare creates an OAuth token with read - only access to the repo. Keep this token out of any public logs or CI output. If you use a CI pipeline, store the token in a secret store (GitHub Actions secrets, for example) and reference it only during the wrangler pages deploy step. Revoking the token immediately stops further deployments.
What additional security does Cloudflare provide?
Beyond TLS, Cloudflare automatically mitigates DDoS attacks by filtering traffic at the edge. You can also integrate Cloudflare Access or Zero - Trust to require authentication for admin - only paths, but this requires a custom Worker that checks the request before serving the page.
How can I verify the security posture of my deployed site?
Run a free Decloak scan on the live URL. The scan checks HTTPS configuration, static HTML for unsafe headers, network behavior, and looks for dangerous JavaScript patterns such as eval() or wildcard postMessage. It does not scan for hard - coded API keys, so you must verify those manually.
What steps should I take after a scan flags issues?
- Fix any missing security headers in the
_headersfile. - Reduce the number of redirects if you exceed the 2 100 limit.
- Move oversized assets to R2.
- Replace any hard - coded secrets with environment variables or KV lookups.
- Re - run the Decloak scan to confirm the remediation.
Where can I find more detailed guidance?
The Decloak journal post "Your API Keys Are Probably in Your JavaScript Bundle Right Now" explains how to audit client - side code for leaked credentials. The "Your SSL Certificate Being Valid Isn't the Same Thing as Your TLS Being Secure" article covers TLS best practices that still apply even with Cloudflare’s automatic certificates.
Related guides
What is Cloudflare Pages and How Does It Work?
Deploying with Cloudflare Pages gives you edge performance and built - in TLS, but you still need to scan for misconfigurations. Decloak’s free scan can verify your site’s security posture in seconds.
Is GitHub Pages Secure Enough for My Site?
Learn GitHub Pages size, bandwidth, and security limits, then see how Decloak’s free scan can quickly spot misconfigurations on a static site.
Is Cloudflare Pages better than GitHub Pages for security and performance?
Cloudflare Pages offers a global edge network, unlimited bandwidth and serverless functions, making it technically stronger than GitHub Pages for secure, high - performance static sites.