How to Enable ModSecurity to Block Common Web Attacks

Turn on ModSecurity in cPanel to add a web application firewall that blocks SQL injection, XSS, and other common attacks against your website.

· Updated · 1,464 views

ModSecurity is a web application firewall (WAF) that inspects requests to your site and blocks malicious ones before they reach your application. On NairoHost shared hosting it is available directly in cPanel.

What ModSecurity Protects Against

  • SQL injection attempts against your database
  • Cross-site scripting (XSS) payloads
  • Known exploit patterns targeting WordPress, Joomla, and plugins
  • Automated bots probing for vulnerabilities

Enabling ModSecurity

  1. Log in to cPanel
  2. Go to Security → ModSecurity
  3. You will see your domains listed
  4. Toggle the switch to On for the domain you want to protect

That is all it takes; protection applies immediately.

When a Legitimate Action Is Blocked

Occasionally a strict rule blocks a normal action, such as submitting a long form or editing a post. If that happens:

  1. Note the time and what you were doing
  2. Go to ModSecurity → Hits List to find the triggered rule ID
  3. Disable that single rule, or open a ticket and we can tune it for you

Important: Disable individual rules only, never the whole firewall, so you keep protection while fixing the false positive.

ModSecurity Plus Good Habits

A WAF is one layer. Combine it with:

  • Strong passwords and two-factor authentication
  • Up-to-date WordPress core, themes, and plugins
  • Regular backups

Together these block the vast majority of attacks. For help tuning rules, contact support via the /contact page.

Was this article helpful?

Your feedback helps us improve our documentation.

Still Need Help?

Our support team is available 24/7 to assist you.