Not sure its worth the bandwidth/http request savings on a small site. If you run a big site, you'd be willing to pay for a top notch CDN.
Cloudflare sits in a weird middle ground.
On reading some of the criticisms here, I'm concerned I made the wrong recommendation - but at the same time, I'm also seeing comments like "CloudFlare is fantastic". Can anyone weigh in with what I really need to know about CloudFlare in order to ascertain if it's a good choice for my client or not?
Then I used it for my startup, which was using an SSL cert, and it had major problems on launch day because of that (ugh). It continued to have SSL compatibility issues for a week, so I've only been using it as a DNS since. As a test, I enabled it on staging and have left it off on production. To their credit, it seems like the SSL downtime issues have gone away.
It's been fine as a DNS, but I don't really have any desire to enable the CloudFlare features again. I love the idea of it keeping me safe from spambots and DDOS. At the same time, it really is a single point of failure, and it's failed more than any other technology in my stack. And the caching layer is way too brittle. I've set up rules to turn it off in staging.
Since then they've added an SSL service where you can get an SSL cert from them. It only SSL's the traffic from the client to Cloudflare, not from Cloudflare back to the server so you've still got part of your transport not secured. I wonder how many people bought into that service without realizing that. (You can have Cloudflare connect HTTPS back to your server, but they still offer that partially covered option for some reason).
Honestly, I hate them.
I usually get flagged when following popular links from Twitter. I just find it highly annoying their support doesn't care. When this happens, I just get told to wait 72 hours or whatever and go back to the site. I wonder how many users sites lose because of that.