What is a WAF?
WAF means Web Application Firewall. Picture a guard at a school gate. The guard checks everyone who comes in. Strangers with bad plans are stopped. A WAF checks every visit to your website. It blocks hackers, fake bots and attacks.
WordPress is used by millions of sites. That makes it a popular target. Attackers try to guess passwords. They also look for old plugins with weak spots. A WAF stops many of these tries before they reach your site.
Two kinds of WAF
- Cloud WAF. It sits in front of your site. Cloudflare and Sucuri are examples.
- Plugin WAF. It runs inside WordPress. Wordfence is an example.
Ask Hostvento support what is available on your plan.
Steps for a plugin WAF
- Log in to your WordPress dashboard. The address is usually your site name followed by
/wp-admin. - Take a backup of your site first.
- Click Plugins, then Add New.
- Search for a security plugin with a firewall, such as Wordfence.
- Click Install Now, then Activate.
- Open the plugin's firewall page.
- Follow the setup guide. Turn the firewall on.
- Run a first scan to look for bad files.
Steps for a cloud WAF
- Create an account with the provider.
- Add your domain.
- Change your name servers to the ones the provider gives you. You can do this in your client area under Domains.
- Turn on the firewall and managed rules.
- Turn on login protection or rate limits for
/wp-login.php.
Warning: Name server changes can affect email. Save all your DNS records before changing them.
Other good habits
- Update WordPress, themes and plugins often.
- Delete plugins you do not use.
- Use long, unique passwords.
- Turn on two-step login.
Quick recap
- A WAF is a guard for your website.
- Choose a plugin WAF or a cloud WAF.
- Back up before you install or change anything.
- Protect the login page.
- Keep everything updated.