Choosing the best image CDN for your web projects
If your images already live in a bucket or CMS, compare products that can transform them without moving the originals. If you need hosted uploads too, compare that storage path separately. The best image CDN for your project is the product and plan that fit both your image workflow and its delivery requirements.
This comparison covers Cloudflare Images, Cloudinary’s Image & Video API, ImageKit, and imgix. Features and public prices were checked on October 2, 2026. Prices are in USD before tax; this is a documentation-based shortlist, with no measured provider latency ranking.
Define your image workload
You can use this comparison without opening accounts or changing DNS. First write down:
- Originals: Will they stay in your CMS or object storage, or move into a managed media library?
- Outputs: Which widths, crops, and formats do you need? Is automatic AVIF a requirement, or would WebP with JPEG/PNG fallback suffice?
- Access: Are originals and every thumbnail public, or must delivery require authorization?
- Usage: How much storage, delivered bandwidth, and new transformation work do you expect?
- Integration: Must you retain image paths, use your own hostname, or support a WordPress theme?
Count distinct requested outputs as well as original images. A catalog with several widths and crops can create substantially more transformation work than its upload count suggests.
Separate storage, transformations, and delivery
An image service can fetch or store an original, resize or convert it, and deliver the result through a CDN. These are separate responsibilities with separate limits. Object storage holds your files; a general CDN caches responses. Neither alone establishes that an image will be resized or that its format will be negotiated for the requesting browser.
If you already generate all required versions, you may need only storage and delivery. For that general website workload, see our CDN cost comparison. Its estimates exclude image transformations, so they cannot price the complete image services below.
Compare the image workflows
The table describes ordinary image processing. AI operations, video, and negotiated enterprise features need their own feature and price checks.
| Product | Where originals live and what integration changes | Transformations and format negotiation |
|---|---|---|
| Cloudflare Images | Keep your origin for remote transformations, or upload into Images storage. The zone-based remote path requires enabling transformations and allowing the source origin; Workers offer another integration path. | Resize and crop remote images or use hosted variants. format=auto selects a supported format; hosted delivery uses it by default. A custom transformation Worker must handle the Accept header. AVIF encoding can fall back to WebP or JPEG. |
| Cloudinary Image & Video API | Upload into its managed library, or keep your origin and use remote fetch. Fetch caches copies and derivatives; auto-upload is a separate path that imports assets for management. | URL-based resizing, cropping, and effects. f_auto negotiates formats, but automatic AVIF availability depends on the account’s billing metric and configuration. Image-bandwidth accounts do not enable it by default. |
| ImageKit | Use its integrated media library or attach external storage, including S3 and a web server, to a URL endpoint. Originals can stay in the existing storage. | URL-based resizing and cropping with automatic format conversion. Automatic AVIF is listed as available on demand on Pro and Enterprise, rather than included in Free or Lite. |
| imgix | Connect a Source to your existing bucket or Web Folder and serve images through imgix URLs. The Source guide lists arbitrary-URL Web Proxy for Enterprise plans, distinct from a fixed Web Folder origin. Confirm that eligibility in your offer. | URL-based transformations. auto=format negotiates AVIF, WebP, or a JPEG/PNG fallback according to client support. |
Supporting an output format and automatically selecting it are different capabilities. If AVIF is mandatory, confirm automatic delivery on the actual account before choosing a plan. For Cloudinary, the documentation distinguishes image-impressions accounts from image-bandwidth accounts; the latter need an Enterprise discussion for automatic AVIF support. Cloudinary’s format rules also explain why opening a URL in a browser tab can give a different format from embedding it in a page.
Security considerations
A signed URL restricts which URL a caller can use. Your application still decides who receives it, and someone with a valid URL may share it. Keep signing keys on the server and check access to the original as well as the CDN copy.
- Cloudflare hosted Images supports expiring signed delivery URLs. A variant configured for public access bypasses that requirement. Private images do not support custom paths, and flexible variants cannot be used with images requiring signed delivery URLs. These hosted-image rules do not establish access control for your separate remote origin.
- Cloudinary distinguishes
privateandauthenticateddelivery. Private originals are protected, but derivatives are public by default. Authenticated assets protect both; their derivatives must be generated eagerly rather than on demand. Check token-based access separately if expiry is required; a delivery signature alone is not an expiry policy. - ImageKit offers signed URLs with optional expiry on all plans, but signature enforcement is off by default. Enable enforcement for all image requests when that is your requirement. Marking an asset private is a different control: its documented access paths include valid named transformations as well as signed URLs.
- imgix can require signed URLs
at the Source. Sign the
expiresparameter too if you need time-limited delivery; an unsigned expiry value can be changed. A public origin can still expose the original outside imgix.
HTTPS and CORS do not replace authorization. CORS controls which browser scripts can read a response; it does not prevent ordinary image embedding or direct downloads.
Cost considerations and free options
Use the specific image offer’s limits, not the provider’s general CDN free tier. These allowances are not interchangeable:
| Offer | Free allowance | Boundary to plan around |
|---|---|---|
| Cloudflare Images Free | 5,000 unique remote transformations per calendar month; no Images-hosted storage. | Above the allowance, new transformations return error 9422; existing cached transformations continue. Images Paid charges $0.50 per 1,000 unique transformations above the included 5,000. |
| Cloudinary Free | 25 shared credits: one credit covers 1,000 standard image transformations, 1 GB storage, or 1 GB image bandwidth. Add consumption across those resources. | Transformations and bandwidth use a rolling 30-day window; storage is the current total, including derived assets. Excess base-credit usage leads to warnings and eventual account disabling if unresolved. |
| ImageKit Forever Free | 20 GB monthly bandwidth and 3 GB fixed media-library storage. | Exceeding a free inclusion stops the corresponding functionality. Custom domains and on-demand automatic AVIF start at Pro; the listed Pro base fee is $89/month plus usage beyond its inclusions. |
| imgix trial | 100 credits for 30 days. This is a trial, not an ongoing free plan. | Starter is $25/month for 100 credits with monthly billing. Credits cover management, delivery, and transformations; a delivery allowance is not an additional independent storage allowance. |
For Cloudflare-hosted images, the separate rates are $5 per 100,000 images stored per month, purchased in storage increments, and $1 per 100,000 image deliveries. Delivery through the hosted image URL counts as Images Delivered; processing through the Images binding counts as Images Transformed. The pricing documentation distinguishes those paths. Add your external storage and origin costs when you keep your own origin.
For imgix, management consumes two credits per GB/month and delivery one credit per GB. Management covers image cache storage and metadata, even when originals remain in your bucket; transformation consumption varies by feature. Do not budget all 100 Starter credits for delivery while also treating management and transformations as free.
Match a requirement to a shortlist
These are decisions from the documented limits, not provider performance results:
- Existing public catalog on a Cloudflare zone: Requesting 500 originals in four distinct sizes produces 2,000 unique remote transformations if those are the only requested combinations. Cloudflare Images Free is a candidate for that transformation workload. It does not host those originals for free or cover your origin’s bill. Compare ImageKit and imgix if their external storage integration better fits your application.
- Small app with hosted uploads: Suppose all stored originals and derivatives total 1 GB,
image delivery is 10 GB in both the calendar month and the rolling 30-day window, and 3,000
standard derivatives are newly generated in that rolling window. Cloudinary’s base-resource
estimate is
1 + 10 + 3 = 14credits, below 25. ImageKit’s 3 GB storage and 20 GB bandwidth allowances also fit those two resources. This shortlists both; it does not include AI add-ons or establish automatic AVIF eligibility. - Automatic AVIF on a continuing free plan: ImageKit Forever Free fails this requirement. Cloudinary Free’s credit allowance alone does not establish it either. Check Cloudflare’s remote path and its transformation allowance; imgix’s trial does not meet a continuing-free requirement. Allow documented format fallbacks rather than assuming every response will be AVIF.
- Members-only originals and thumbnails: Reject an integration that protects only originals. For Cloudinary, evaluate authenticated delivery and eager derivatives. For ImageKit, evaluate enforcement for all requests. For Cloudflare-hosted images, evaluate predefined signed variants and exclude public variants. In each case, verify denial at the CDN and the origin before launch.
Choose an image CDN for WordPress
A WordPress site can keep uploads on its existing server and use a fetching service, or move media into hosted storage. Choose which model you want before choosing a plugin. Rewriting a hostname alone does not prove that an image is smaller or converted to a different format.
If you already use W3 Total Cache or WP Fastest Cache, assess its CDN integration against the chosen
image product’s URL and storage model. In staging, check the rendered src, every srcset
candidate, and CSS background URLs. WordPress generates responsive image candidates,
so changing only src can leave browsers fetching other sizes from the old origin. Check new
uploads, existing posts, and rollback while keeping an independent copy of your originals.
Performance testing and validation
Pilot a representative image set after the feature and plan checks: a photograph, a transparent
graphic, a crop with an important subject, and any private image type you will serve. Check actual
dimensions, crop content, transparency, response Content-Type, and delivered bytes. Compare
formats at acceptable visual quality; matching a numeric quality setting across encoders is not
enough to establish equivalent output.
Measure page-load behavior, p95 image request latency, and errors from the regions your users occupy. Separate first-request transformation work from warmed-cache delivery, and record cache headers as well as timing. Smaller payloads and cache hits can help, but this comparison cannot tell you which provider will be fastest for your users.
Troubleshooting common issues
If a transformed URL fails, check the original’s accessibility, allowed source hosts, signature enforcement, and plan limits before changing the image parameters. If an updated image stays stale, use the product’s documented replacement or invalidation workflow. For example, Cloudinary fetch refresh rules differ from uploading a replacement; changing the origin file does not immediately update every cached derivative.
Keep the product, plan, required features, usage estimate, and pilot results together in your decision record. That gives you a concrete reason to choose a service, and a useful trigger to revisit it when your catalog or delivery requirements change.
