When scanners miss the attack: how Cloudflare Client-Side Security protects storefronts

Cloudflare added a Client-Side Security ML model that detects malicious JavaScript on storefronts, uncovering eight payloads missed by VirusTotal and URLScan. The blog details four attack operations and notes that the model flagged all incidents in live traffic, offering developers real‑time protection.

Cover image for When scanners miss the attack: how Cloudflare Client-Side Security protects storefronts