Service · Cybersecurity

Web application firewall (WAF)

An online shop is reachable by anyone, day and night, and automated scanners discover a new one soon after launch. A web application firewall screens out routine attacks before they touch the code, whether the shop is built on WooCommerce, PrestaShop or bespoke software. The skill lies in doing so without turning away customers, payment gateway callbacks or the BaseLinker connection.

Learning
before blocking
OWASP
Top 10 as a baseline
Virtual patches
for known flaws
Report
summary of blocks

Included in this service

Careful coding still matters, but a WAF buys breathing space: today a rule shields the flaw, and the code is corrected in the next release.

Talk the scope through with an engineer

Attack filtering

Known techniques are stopped at the edge: SQL injection, cross-site scripting, path traversal and probing for hidden admin pages.

Login protection

Rate limiting on wp-admin, the PrestaShop back office and customer accounts, and protection of the password reset flow from abuse.

Bot management

Search engines and the price comparison services you partner with are let through. Price scrapers, card-testing bots and stock-hoarding scripts are kept out.

Virtual patching

A plugin vulnerability is neutralised by a rule before its author releases a fix, something that happens with popular WooCommerce extensions more often than anyone would like.

Integration exceptions

Callbacks from Przelewy24, PayU or Tpay, courier webhooks and marketplace connections get narrowly defined exceptions, so orders never hang on “awaiting payment”.

Reporting

A periodic overview of blocked requests, their origin and the rule responsible, written so the shop owner can follow it too.

How we work together

Most trouble with a new WAF appears right at the start, so we never begin in blocking mode.

01

Analysis

Platform, forms, customer accounts, payment methods and integrations: a complete list of everything that legitimately talks to the shop.

02

Learning

The firewall watches without blocking and builds a profile of genuine traffic, ideally spanning a weekend and one promotion.

03

Tuning

False positives are removed. A live shop always has some, usually in product search and the admin area.

04

Enforcement

Protection is switched on, alerting configured and events reviewed on a schedule, with extra attention before Black Friday and Christmas.

Never launch a WAF for the first time a week before a big sale. Traffic is unusual then, and each false positive is an abandoned basket. A firewall introduced well ahead has already learnt the shop, so at the peak it turns away bots rather than buyers.

Questions and answers

Usually not. Many cloud WAF services work alongside a CDN that serves images and scripts from servers closer to the customer, so pages may even load faster. The delay added by inspecting requests is normally imperceptible to shoppers.

On subscription platforms such as Shoper or IdoSell, the provider runs the infrastructure and its terms describe the protection included, so a separate WAF is normally unnecessary. We then concentrate on what remains yours: administrator accounts, MFA and access granted to third-party apps.

After the learning and rule tuning period, whose length depends on your traffic. Individual rules for obvious attacks, for example against a publicised plugin flaw, can be enabled immediately.

They see a page with an event reference, and we find the rule responsible in the logs and adjust it. After tuning such cases are rare, and the report shows whether they are creeping up.

Shield your shop with a WAF

Tell us which platform powers your shop or portal and what it connects to. We will recommend a WAF type and a roll-out plan.

Hours
Mon-Fri 8:00-18:00 CET, reply within one working day
Meetings
Online via Teams or Google Meet

We set strictly necessary cookies only: they keep the site running and remember the city you chose. Nothing here is used for advertising or tracking. More in our privacy policy.