ModSecurity is a web application firewall (WAF) that inspects requests to your site and blocks malicious ones before they reach your application. On NairoHost shared hosting it is available directly in cPanel.
What ModSecurity Protects Against
- SQL injection attempts against your database
- Cross-site scripting (XSS) payloads
- Known exploit patterns targeting WordPress, Joomla, and plugins
- Automated bots probing for vulnerabilities
Enabling ModSecurity
- Log in to cPanel
- Go to Security → ModSecurity
- You will see your domains listed
- Toggle the switch to On for the domain you want to protect
That is all it takes; protection applies immediately.
When a Legitimate Action Is Blocked
Occasionally a strict rule blocks a normal action, such as submitting a long form or editing a post. If that happens:
- Note the time and what you were doing
- Go to ModSecurity → Hits List to find the triggered rule ID
- Disable that single rule, or open a ticket and we can tune it for you
Important: Disable individual rules only, never the whole firewall, so you keep protection while fixing the false positive.
ModSecurity Plus Good Habits
A WAF is one layer. Combine it with:
- Strong passwords and two-factor authentication
- Up-to-date WordPress core, themes, and plugins
- Regular backups
Together these block the vast majority of attacks. For help tuning rules, contact support via the /contact page.