A web application firewall (WAF) sits between visitors and your site, filtering out malicious requests such as SQL injection, cross-site scripting, and bad bots. It is one of the most effective ways to reduce attacks reaching your application.
Choose a Firewall Type
| Type | How It Works | | --- | --- | | Server WAF | Runs on the hosting server, like ModSecurity | | Cloud WAF | Filters traffic before it reaches your host | | Plugin WAF | Runs inside your application, such as WordPress |
Each layer adds protection, and they can work together.
Use Server-Level ModSecurity
Many cPanel servers include ModSecurity:
- Log in to cPanel.
- Look for ModSecurity under the Security section.
- Confirm it is enabled for your domain.
- If a rule blocks legitimate traffic, note the rule ID for support.
If you do not see the tool, ModSecurity may be managed server-wide by your host.
Add a Cloud Firewall
A cloud WAF, such as Cloudflare, filters traffic before it reaches your server:
- Sign up and add your domain.
- Update your domain's nameservers as instructed.
- Enable the firewall and security rules in the dashboard.
- Set the security level to suit your traffic.
Add a Plugin Firewall
For WordPress, a security plugin provides an application-level firewall:
- Block known malicious IPs and bots.
- Limit login attempts.
- Patch common vulnerabilities virtually.
Combining a server or cloud WAF with a plugin firewall gives layered defense. If a firewall rule blocks a real visitor or breaks a feature, contact support via the /contact page with the request details so the rule can be tuned.