Layer-7 protection against OWASP Top 10 attacks. Free on every hosting and cloud plan.
Enable
- Portal → Security → WAF.
- Toggle Enable for this site.
- Choose a sensitivity preset:
Low(few false positives, catches obvious attacks),Medium(recommended),High(paranoid — expect some false positives on admin panels).
Tune rules
Logs tab → filter “blocked” → find rules that block legitimate traffic → click Allow this pattern. Each exception is scoped to the specific URL + rule, not globally.
Custom rules
Add IP allow/deny, country blocks, rate limits, and custom header-match rules. Rules take effect in 10 seconds.