Flash Sale:75% Off Hosting + Free DomainEnds in13h47m14sView Plans
Hostvento logoHostvento

Protect Your WooCommerce Shop with a WAF

This guide explains how a WAF protects your WooCommerce shop and what to switch on.

Firewall2 min read10 steps

What is WooCommerce and a WAF?

WooCommerce is a plugin that turns a WordPress site into an online shop. A plugin is an add-on that gives your site a new feature.

A WAF is a Web Application Firewall. It works like a guard at the shop door. It checks each request and blocks the harmful ones.

WordPress and its plugins are very popular. That makes them a common target for attackers.

Steps

  1. Ask Hostvento support whether a WAF is included in your plan. You can open a support ticket.
  2. Make a full backup of your site and database. A backup is a safe copy you can restore if something goes wrong.
  3. Open the WAF dashboard. Your welcome email or support can show you where.
  4. Turn the WAF on and pick blocking mode.
  5. Switch on the WordPress rule set if there is one.
  6. Switch on SQL injection and cross-site scripting rules. These stop attackers from sneaking in bad commands or code.
  7. Rate limit the login page, /wp-login.php. This slows down password guessing.
  8. Rate limit the /xmlrpc.php file too. Attackers often abuse it. If you do not use it, ask to block it fully.
  9. Turn on bot protection to cut fake sign-ups and scrapers.
  10. Place a test order. Check that the cart, checkout and payment all work.
Tip: Payment companies send confirmation messages to your shop. If a WAF rule blocks them, orders can get stuck. Check the WAF log and ask support to allow that request.

Extra safety for your shop

  • Update WordPress, WooCommerce and every plugin often.
  • Remove plugins and themes you do not use.
  • Do not use "admin" as a username.
  • Use long, different passwords for every user.
  • Always load your shop over HTTPS. HTTPS encrypts what visitors send.

Quick recap

  • A WAF blocks harmful requests before they reach your shop.
  • Back up first, then enable blocking mode.
  • Turn on SQL injection, XSS and bot rules.
  • Rate limit /wp-login.php and /xmlrpc.php.
  • Test an order and keep everything updated.