Build1 publisher3 min readPublished
Ahrefs and three rival bot-analytics tools run a Cloudflare Worker on every file a page loads
Ahrefs, Known Agents, Profound and Scrunch run a Worker on every request, so a 20-file page spends 21 of Cloudflare's 100,000 free daily invocations. A site with 10,000 page views a day would need more than twice that.
The Engineer · Build desk
Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

What happened
- Ahrefs asks for Account Workers Scripts Edit, Zone Workers Routes Edit and Zone Read permissions, and its manual setup uses the route pattern *yourwebsite.com/*.
- Each report sends the vendor the full URL with query string, visitor IP, user agent, referer, method, status and content type, plus three Web Bot Auth signature headers.
- Cloudflare's billing docs call static-asset requests free and unlimited and charge only requests that invoke a Worker, so a route Worker in front makes every asset request count.
- On 301.sh the zone served about 19,200 requests in the seven days to 30 September, while the site's own page-only Worker ran 2,421 times.
Compiled by The EngineerSomething wrong?How this is made
Why it matters
- cost On the Free plan, a site serving twenty-file pages uses up its entire daily Worker allowance at about 4,760 page views once a vendor route is in place.
- decision Anyone installing one of these tools has to open the route and choose fail open or fail closed, because a fail-closed route turns a quota overrun into an error page for the whole site.
- exposure Human visitors' IPs and full query strings go to the vendor along with the bots'; Profound's Worker skips checkout, cart, admin and api paths, while Ahrefs' reports everything.
- constraint A site that already routes paths such as /api/* to its own Worker gets bot reports with those paths absent, and nothing in the tool flags the gap.
Ahrefs Bot Analytics, Known Agents (formerly Dark Visitors), Profound and Scrunch all install a Worker, and the author says it is short and does what it claims [2]. It hands each request on unchanged with `fetch(event.request)`. It sends its report inside `event.waitUntil` after the response has gone out, so the page is not slowed [5]. That report is a subrequest, and Cloudflare does not bill subrequests. The invocation itself counts [10]. Ahrefs' setup screen says "Your token is used once and not stored" [4]. One use is enough to create a route that runs on every request from then on [1]. According to the author, none of the four setup screens mention the cost [3].
The Workers Free plan allows 100,000 requests a day, reset at midnight UTC [8]. A route on `*example.com/*` matches the page and every image, stylesheet, script and font it loads. A visit to a page with twenty files therefore costs 21 invocations [9]. At that rate the allowance runs out at about 4,760 page views a day [2]. The author's example site, at 10,000 page views a day, would need 210,000 invocations, 2.1 times the cap [1]. That multiplier carries over to another site only if its pages load a similar number of files through the routed hostname [9].
Measured traffic on 301.sh, which runs on the Free plan, puts its multiplier at about 7.9 [4]. The author rounds it to eight [13]. The site averages roughly 2,740 zone requests a day [3], well under the limit with or without a route [13]. The author checked every limit against Cloudflare's documentation on 30 September 2026 [17].
Ordering is harder to pin down. Cloudflare's custom-domain documentation says "Any Workers running on routes before your Custom Domain can optionally call the Worker registered on your Custom Domain by issuing fetch(request)" [14]. On a site that already runs its own Worker, the vendor's code is the first to see each request [14]. Precedence adds a second wrinkle. "The most specific route pattern wins," the routes documentation says. An existing Worker on `example.com/api/*` keeps those requests, and the analytics tool never sees them [16].
What happens at the cap depends on a toggle on the route. Fail open "Bypasses the Worker. Requests behave as if no Worker is configured"; fail closed "Returns a Cloudflare 1027 error page" [15]. Neither Cloudflare's documentation nor the route request in Ahrefs' manual setup specifies which mode a new route gets [15]. The author's advice is to find the route the tool created under Workers & Pages and check it [15].
301.sh already runs the lighter design [12]. The payload fields are request headers and response metadata. The visitor IP comes from `cf-connecting-ip`. The `signature`, `signature-input` and `signature-agent` headers are the Web Bot Auth headers a signed AI agent uses to prove who it is [6]. On 301.sh's traffic, a Worker limited to page URLs sees those headers on every page request at about one-eighth the invocations [4]. The author says the full article also covers what Cloudflare provides without any tool, and how to log bots from a Worker the site already runs [19].
What to watch
- Cloudflare documenting which fail mode a new route gets, and how a route Worker plus a custom-domain Worker count against the daily quota.
- Ahrefs, Known Agents or Scrunch narrowing their routes to page URLs or adding path exclusions like Profound's.
- Vendor setup screens stating the route's invocation cost before asking for the Workers Scripts Edit token.