Website firewall: what a WAF blocks, and Cloudflare versus plugins
A web application firewall is the single most useful thing you can put in front of a site, and most sites have none. Here is what a WAF actually does, the real difference between an edge firewall and a plugin, and the setup we use.
Every site on the internet is being probed, constantly, by automated scripts that try known attacks against every address they can find. A firewall is what stands between those scripts and your site. Most business sites have nothing there at all, which is why so many of the cleanups we do began with an attack that a basic firewall would have refused.
What a WAF actually does
A web application firewall inspects each request before your site handles it and blocks the ones that match attack patterns: attempts to inject database commands, to upload PHP files where they do not belong, to exploit known plugin holes, to guess passwords at a hundred attempts a minute, to hammer the site from a thousand addresses at once.
It is not the same as the network firewall on your server, which controls which ports are open. A WAF understands web requests. It is also not antivirus: it does not clean an infected site. It stops the next infection.
Edge firewall versus plugin firewall
A plugin firewall runs inside WordPress. The request reaches your server, PHP starts, WordPress starts loading, the plugin inspects the request and blocks it. It works, and it sees things an edge firewall cannot, like a logged-in user doing something suspicious. But every blocked request still cost your server work, and a plugin cannot protect against attacks that hit before it loads, or that target the server itself. A flood of requests will take the site down whether the plugin blocks each one or not.
An edge firewall like Cloudflare sits between the visitor and your server. Blocked requests never reach you. It absorbs floods, hides your server’s address, caches your pages so the server does less, and applies rules maintained by people who see attacks across millions of sites. The free tier includes a managed ruleset and a handful of custom rules, which is enough for most business sites. The paid tiers add the full ruleset and more rules.
The honest answer to “is the plugin not enough” is: it is better than nothing, and it is not what we would rely on. The edge is where a firewall belongs.
The setup we use
- Cloudflare in front of the site, with the DNS moved to it so all traffic passes through. The server’s real address stays hidden, and we lock the server so it only accepts traffic from Cloudflare’s addresses.
- The managed ruleset on, which blocks the common attack patterns.
- A few custom rules: rate limits on the login page and XML-RPC, a challenge for traffic from countries the business does not serve if that makes sense, and a block on requests for files that should never be requested from outside, like the config file or PHP inside uploads.
- Bot protection for the obvious bad bots, while leaving search engines alone.
- A plugin or host firewall as the second layer, for the inside view and for the case where something bypasses the edge.
- Login hardening on the site itself: two-factor, limited attempts. The firewall is not a reason to skip these.
What a firewall will not do
It will not fix an outdated plugin. Known holes get exploited through requests that look legitimate, and while managed rules catch many, they do not catch all. Update anyway. It will not remove malware already on the site. And it will not stop someone who has a valid password. Those are the other layers.
Cost
The edge firewall for a business site is free to a few tens of dollars a month. The setup is an afternoon. Against the cost of one cleanup, it is the best-value hour in web security, and it is the first thing we put in place on every rescue job before we even start cleaning.
The scanner will show whether a site is behind a CDN or edge service. If yours is not, this is the place to start.
See where your own site stands.
The scanner checks the things this guide talks about, in about ten seconds, no signup.
More from the guides
Hacked WordPress: the cleanup order that holds
Most hacked sites get cleaned twice. The first time removes what you can see. Here is the full order we use so the second time is never needed: contain, find the door, clean, rotate, patch, watch.
Is my website hacked? Twelve signs, and a five-minute check
Most hacked sites look normal to their owners for weeks. The signs show up in Google, in your inbox and on other people's phones first. Here are the twelve we check, and a five-minute routine that catches most of them.
Deceptive site ahead: what it means and the fix order
Chrome is not warning about your design. Google Safe Browsing found phishing or malware on your domain. Here is what the red screen means, how to find the cause, and how to get the flag removed without it coming back.