Attack filtering
Known techniques are stopped at the edge: SQL injection, cross-site scripting, path traversal and probing for hidden admin pages.
Careful coding still matters, but a WAF buys breathing space: today a rule shields the flaw, and the code is corrected in the next release.
Known techniques are stopped at the edge: SQL injection, cross-site scripting, path traversal and probing for hidden admin pages.
Rate limiting on wp-admin, the PrestaShop back office and customer accounts, and protection of the password reset flow from abuse.
Search engines and the price comparison services you partner with are let through. Price scrapers, card-testing bots and stock-hoarding scripts are kept out.
A plugin vulnerability is neutralised by a rule before its author releases a fix, something that happens with popular WooCommerce extensions more often than anyone would like.
Callbacks from Przelewy24, PayU or Tpay, courier webhooks and marketplace connections get narrowly defined exceptions, so orders never hang on “awaiting payment”.
A periodic overview of blocked requests, their origin and the rule responsible, written so the shop owner can follow it too.
Most trouble with a new WAF appears right at the start, so we never begin in blocking mode.
Platform, forms, customer accounts, payment methods and integrations: a complete list of everything that legitimately talks to the shop.
The firewall watches without blocking and builds a profile of genuine traffic, ideally spanning a weekend and one promotion.
False positives are removed. A live shop always has some, usually in product search and the admin area.
Protection is switched on, alerting configured and events reviewed on a schedule, with extra attention before Black Friday and Christmas.
Never launch a WAF for the first time a week before a big sale. Traffic is unusual then, and each false positive is an abandoned basket. A firewall introduced well ahead has already learnt the shop, so at the peak it turns away bots rather than buyers.
Usually not. Many cloud WAF services work alongside a CDN that serves images and scripts from servers closer to the customer, so pages may even load faster. The delay added by inspecting requests is normally imperceptible to shoppers.
On subscription platforms such as Shoper or IdoSell, the provider runs the infrastructure and its terms describe the protection included, so a separate WAF is normally unnecessary. We then concentrate on what remains yours: administrator accounts, MFA and access granted to third-party apps.
After the learning and rule tuning period, whose length depends on your traffic. Individual rules for obvious attacks, for example against a publicised plugin flaw, can be enabled immediately.
They see a page with an event reference, and we find the rule responsible in the logs and adjust it. After tuning such cases are rare, and the report shows whether they are creeping up.
Tell us which platform powers your shop or portal and what it connects to. We will recommend a WAF type and a roll-out plan.
Your enquiry has reached us
You will hear back within one working day, and if you have reported an outage that is holding up work, it goes to the front of the queue.
No match for that name. Try a different spelling or pick a bigger town nearby - all our support is delivered online, so your choice has no effect on the service.