Find unused Cloudflare resources wasting your budget
CostSave runs 50+ checks across Workers, R2, KV, Pages, D1, DNS, Load Balancers, and WAF. Paste a read-only API token and see exactly what your Cloudflare account spends on idle resources.
Read-only API token·50+ checks·Under 60 seconds·Free forever
Scan my Cloudflare account free50+
Cost checks
11
Resource types covered
<60s
Scan time
$0
Cost, forever
What we scan
Every Cloudflare check CostSave runs
Covers idle resources, DNS security risks, cache misconfigurations, and unused paid features across your entire account.
Cloudflare — unused resources across your entire account
Connect with a read-only API token. CostSave scans every service — Workers, R2, KV, Pages, DNS, Tunnels, and more — and flags what's costing money without doing anything.
Workers
- Zero requests in 30 days
- Never deployed workers
- Not modified in 90+ days
- Estimated cost ($0.15/M requests)
KV Namespaces
- Zero read/write/delete ops in 30 days
- Cost estimate ($0.50/M billable ops)
R2 Buckets
- Zero requests in 30 days
- Empty buckets (0 objects)
- Storage cost ($0.015/GB-month)
Pages Projects
- Never deployed projects
- No deployment in 30+ days
- No deployment in 90+ days
D1 Databases
- Zero read/write queries in 30 days
- Databases <1 MB (likely leftover/test)
DNS & Zones
- Dangling CNAME records — subdomain takeover risk
- Stale TXT verification records
- A records pointing to private IPs
- Invalid MX records (null host)
- Duplicate DNS records
- Orphaned subdomains
- Idle subdomains — ≤500 requests in 30 days
Tunnels
- Inactive tunnels (not in healthy state)
- Tunnel health status tracking
Queues & Load Balancers
- Queues with 0 messages in 30 days
- Disabled load balancers
- Load balancers with no origin pools
Cache Settings
- Development Mode left ON (bypasses all cache)
- Cache level not set to Standard
- Browser Cache TTL below 1 day
- Tiered Cache not enabled on paid plans
- Image compression (Polish) disabled
- Auto-minification disabled for JS/CSS/HTML
- Low cache hit ratio — <70% with >1,000 requests
Security & WAF
- SSL disabled or set to Flexible (origin unencrypted)
- Minimum TLS version below 1.2
- "Always Use HTTPS" disabled
- Security level set to off
- No WAF Managed Rules on paid plan
- Allow-all firewall rules bypassing WAF
Unused Paid Features
- Email Address Obfuscation not enabled
- Hotlink Protection not enabled
- Brotli Compression not enabled
- Opportunistic Encryption not enabled
- Mirage (lazy loading for mobile) — Pro+
- HTTP/2 Early Hints — Pro+
Read-only API token — no write access
See what your Cloudflare account
is wasting — in under 60 seconds
Paste a read-only API token and get results instantly. No credit card, no agents, free forever.
Start free Cloudflare scan →