Craft CMS and Core Web Vitals: What Slows Sites Down and What It Costs You in Search
Poor Core Web Vitals scores on a Craft CMS site directly affect search rankings. Here is what causes them and what is involved in fixing them.
We see the same thing on a lot of the ExpressionEngine and Craft sites we take on. Cloudflare is switched on, someone set it up a year or two ago, and it is doing almost none of what it was meant to do. Pages are not being served any faster, the security settings are on their defaults, and nobody has looked at it since.
The assumption is that an account plus a domain pointed at Cloudflare means it is working. On a content-managed site there is a configuration step after that, and it is often the step that gets skipped. When it does, you are paying the setup cost and getting none of the return.
Cloudflare sits between your visitors and your web server. Configured properly, it does four things that matter to a business-critical site.
Cloudflare lowers the volume of malicious traffic hitting the site. It does not patch the CMS for you, and an out-of-date ExpressionEngine or Craft core is still the bigger exposure, but it takes a lot of the daily noise off the table.
A plain brochure site can be handed to Cloudflare with caching turned up and left alone. A site run through ExpressionEngine or Craft is different. Most pages have logic behind them, and some of them must never be cached or shown to more than one visitor. A contact form, a logged-in account area, a basket page: these have to be built fresh every time.
So Cloudflare has to be told which pages are safe to cache and which are not. There is also a problem specific to these platforms. Out of the box, ExpressionEngine tells every browser not to cache the page, through a couple of headers it sends automatically. Cloudflare reads those headers and decides the page is not cacheable, so it stores nothing, even when the caching rules look right. Craft and Laravel applications have their own versions of the same issue.
The result is a site with Cloudflare in front of it, caching rules that appear to be set up, and every visitor still being sent all the way back to the origin server. The rules exist and nothing gets cached.
We did this work recently for a UK mental health charity with a form-heavy ExpressionEngine site. The brief was to make the site faster without putting any of its enquiry or assessment forms at risk. That meant moving the domain onto Cloudflare with no interruption to the site or email, going through years of old DNS records and clearing out the ones that no longer pointed anywhere, and setting up caching that served the content pages quickly while leaving every form and every page that collected personal information to build fresh on each visit.
It also meant catching what could go wrong. One page mixed personal information into an otherwise cacheable template. Left as it was, Cloudflare would have stored that page and could have shown one person's details to the next visitor. We found it during the review and kept it out of the cache before anything went live.
If you are having this looked at, whether that means a Cloudflare setup from scratch or a review of what a previous agency left behind, the work should cover:
One more thing worth knowing. The Cloudflare account should be in your name, with your billing, not sitting inside an agency's account. Your domain's DNS is controlled from there. If that control sits with a supplier and the relationship ends, getting it back can be slow and awkward at exactly the point you need it to be quick.
If your site runs on ExpressionEngine or Craft and you are not sure whether Cloudflare is doing anything for it, that is worth checking. We can tell you what is actually configured and what is worth changing. See Cloudflare setup and optimisation, or get in touch with Karl for a straight assessment.
Related Services
Related Case Studies
Poor Core Web Vitals scores on a Craft CMS site directly affect search rankings. Here is what causes them and what is involved in fixing them.
Most business websites work in the sense that they function. Far fewer perform in the sense that they actively contribute to the business. Here is what the difference looks like in practice.
An unpatched CMS install carries known, publicly documented vulnerabilities that no longer get fixed. What that risk actually looks like, and how to check where you stand.
Most clients come to us when their site has started to feel like a risk rather than an asset. Whether the agency relationship has ended, an upgrade has been delayed, or the site has simply grown beyond what it can handle, a conversation costs nothing.
Get in touch with KarlTrusted by established businesses and growing brands across the UK
Expression 37 works with a small number of clients at any one time. These are some of them.


