← All guides

Website firewall: what a WAF blocks, and Cloudflare versus plugins

A web application firewall is the single most useful thing you can put in front of a site, and most sites have none. Here is what a WAF actually does, the real difference between an edge firewall and a plugin, and the setup we use.

16 September 2026, 3 min read. From the firewall setups we install on every rescue job, and the question every client asks: is the plugin not enough?

Every site on the internet is being probed, constantly, by automated scripts that try known attacks against every address they can find. A firewall is what stands between those scripts and your site. Most business sites have nothing there at all, which is why so many of the cleanups we do began with an attack that a basic firewall would have refused.

What a WAF actually does

A web application firewall inspects each request before your site handles it and blocks the ones that match attack patterns: attempts to inject database commands, to upload PHP files where they do not belong, to exploit known plugin holes, to guess passwords at a hundred attempts a minute, to hammer the site from a thousand addresses at once.

It is not the same as the network firewall on your server, which controls which ports are open. A WAF understands web requests. It is also not antivirus: it does not clean an infected site. It stops the next infection.

Edge firewall versus plugin firewall

A plugin firewall runs inside WordPress. The request reaches your server, PHP starts, WordPress starts loading, the plugin inspects the request and blocks it. It works, and it sees things an edge firewall cannot, like a logged-in user doing something suspicious. But every blocked request still cost your server work, and a plugin cannot protect against attacks that hit before it loads, or that target the server itself. A flood of requests will take the site down whether the plugin blocks each one or not.

An edge firewall like Cloudflare sits between the visitor and your server. Blocked requests never reach you. It absorbs floods, hides your server’s address, caches your pages so the server does less, and applies rules maintained by people who see attacks across millions of sites. The free tier includes a managed ruleset and a handful of custom rules, which is enough for most business sites. The paid tiers add the full ruleset and more rules.

The honest answer to “is the plugin not enough” is: it is better than nothing, and it is not what we would rely on. The edge is where a firewall belongs.

The setup we use

  1. Cloudflare in front of the site, with the DNS moved to it so all traffic passes through. The server’s real address stays hidden, and we lock the server so it only accepts traffic from Cloudflare’s addresses.
  2. The managed ruleset on, which blocks the common attack patterns.
  3. A few custom rules: rate limits on the login page and XML-RPC, a challenge for traffic from countries the business does not serve if that makes sense, and a block on requests for files that should never be requested from outside, like the config file or PHP inside uploads.
  4. Bot protection for the obvious bad bots, while leaving search engines alone.
  5. A plugin or host firewall as the second layer, for the inside view and for the case where something bypasses the edge.
  6. Login hardening on the site itself: two-factor, limited attempts. The firewall is not a reason to skip these.

What a firewall will not do

It will not fix an outdated plugin. Known holes get exploited through requests that look legitimate, and while managed rules catch many, they do not catch all. Update anyway. It will not remove malware already on the site. And it will not stop someone who has a valid password. Those are the other layers.

Cost

The edge firewall for a business site is free to a few tens of dollars a month. The setup is an afternoon. Against the cost of one cleanup, it is the best-value hour in web security, and it is the first thing we put in place on every rescue job before we even start cleaning.

The scanner will show whether a site is behind a CDN or edge service. If yours is not, this is the place to start.

See where your own site stands.

The scanner checks the things this guide talks about, in about ten seconds, no signup.

Tell us about the site.

A straight answer and a fixed quote, usually the same day.