Web Application Firewall

Attacks end before
your site begins.

Every request to your website passes a checkpoint at the network edge. SQL injection, XSS, hostile bots, brute-force floods — identified and dropped there, so your site only ever meets clean traffic.

100%
of requests inspected at the edge
OWASP
aligned rules, continuously updated
0
setup — active on every site by default
0
MAD — included on every plan

A checkpoint in front
of every request.

The WAF doesn't run on your website — it stands in front of it, at the network edge.

All traffic

Visitors, crawlers, scanners, attackers — everyone arrives together

WAF inspection

Signatures, patterns, rates and reputation checked in milliseconds

Clean traffic only

Real visitors continue to your site; attacks are dropped at the door

Blocked requests never consume your resources — they're gone before your site knows they existed.

Named threats,
standing answers.

The attacks below hit every website on the internet, every day — including yours. This is what meets them.

SQL injection

Attempts to smuggle database commands through your forms and URLs — the classic route to stolen data — are recognized by pattern and blocked before they reach a query.

Cross-site scripting (XSS)

Injected scripts that hijack your visitors' browsers — to steal sessions or deface pages — are filtered out of requests at the edge.

Malicious bots

Scrapers, credential-stuffers and vulnerability scanners are told apart from legitimate crawlers by behavior and reputation — good bots pass, bad bots don't.

Rate limiting

Brute-force login storms and request floods hit a ceiling per source. Real users never notice; scripts hammering wp-login.php very much do.

OWASP-aligned rules

Our rulesets track the OWASP Top 10 — the industry's reference list of web application risks — and are updated as new techniques appear. When a popular CMS vulnerability is disclosed, edge rules often block it before your site is even patched.

DDoS filtering

Volumetric floods meant to knock your site offline are absorbed and dispersed at the network edge — paired with autoscaling, the two layers hold the door together.

Protection you
don't operate.

A firewall that needs a specialist isn't protection — it's a job opening. Ours ships running.

  • On by default — every site, every plan, from the first request. Nothing to enable.
  • Maintained for you — rules are updated as threats evolve; you never patch a signature file.
  • Tuned against false positives — and if a legitimate feature of your app ever trips a rule, support adjusts it for your site specifically.
  • Part of a stack — the WAF is layer one of secure hosting: malware scanning, isolation and backups stand behind it.

Why "at the edge" matters

Security plugins inspect attacks after they've already reached your site — consuming your CPU, touching your PHP, sometimes exploiting the very plugin meant to stop them. An edge WAF drops hostile requests before they cross your threshold. Your site stays fast because it stays out of the fight.

The firewall, answered.

What is a web application firewall, exactly?

A WAF inspects every HTTP request before it reaches your website and blocks the ones that look like attacks — SQL injection, cross-site scripting, malicious bots, brute-force attempts. Think of it as a security checkpoint standing in front of your site, not software running on it.

Do I need to configure it?

No. It's active on every VACLIC site, with rules kept current as new threats appear. There's nothing to install, license or tune.

Will it block my real visitors?

Rules are tuned infrastructure-wide against false positives, and legitimate traffic — including good bots like search engine crawlers — passes freely. If a specific feature of your application ever trips a rule, support adjusts it for your site.

Does the WAF replace keeping my site updated?

No — it blocks the bulk of automated attacks and buys you time when vulnerabilities are disclosed, but patched software remains essential. That's why the infrastructure pairs it with automatic updates, daily malware scanning and backups. The full security stack →

Your site, behind
the checkpoint.

The firewall is already part of every VACLIC plan — along with scanning, isolation and backups. Protection starts with the first request.

View Hosting Plans