My site has been behind CF since about 2012 when we started it, with no issues I recall.
I would recommend keeping the DNS control panel elsewhere and then if CF were to blow up, you can change the DNS to point back to our real server. This is what I have but never had to use it. CF is big and they have very good people running it 24/7 so issues get fixed because they make huge $$$ from big corporates. If your DNS is at CF and CF blows up, you won't be able to log in

I know some people don't like CF because it gets used to hide the true location of "criminal" websites, but they will reveal it to law enforcement agencies. CF is not in the USSR

There have been big issues here in the UK, with Mumsnet getting DDOS'd by some fathers' organisations, because it hosted the fairly predictable womens' discussions about useless fathers and how to shaft your ex husband / deny him child contact etc etc. Mumsnet went behind CF then.
It could be I got Precursor on free CF because they introduced it around July 2026 and let it be free to everyone, for a short time.
The US Govt uses CF heavily, too.
There is also Anubis. ISTM that with most virtual server outfits having a huge bw (many gbps) one could run the proof of work on the server, so long as nothing reaches the application, database, etc. It is the reaching of the application that brings down the site. Only if you run a public facing server on your 10mbps home ADSL is there a bw bottleneck

The proof of work is only time-consuming for the client browsers; it doesn't take up much CPU time on your server.
Also worth checking your DB structure. On our site we had issues (won't go into details) where a bot query locked a chunk of the DB and this brought down the site without getting all that much traffic. It turned out we were logging a lot of activity which belonged into the server log and not into the DB. Moving it out made the system withstand DDOS a lot better, without using Precursor. The cost of that change is that admins lose easy visibility of malicious activity by certain human users...
Still getting two captchas; the 2nd one saying
EEVblog Captcha
We have seen a lot of robot like traffic coming from your IP range, please confirm you're not a robotwhich cannot be true.