Limited Lifetime Deal: pay once, host for life.Secure your spot →

Web application firewall

Web application firewall: stop attacks before they reach your site

A web application firewall inspects every request to your website and blocks typical attack patterns early. With CheapTopHost it is part of our multi-layer security – no configuration required.

  • Protection against SQL injection and XSS
  • Defence against brute-force login attempts
  • Bad bots filtered out automatically

Explained simply

What is a web application firewall?

A classic network firewall decides which connections may reach a server at all. A web application firewall, or WAF for short, goes one step further: it looks at the content of each web request – the URL, form data, cookies and headers – and checks whether it contains signs of an attack.

Think of it as a security guard at the entrance of your website who reads every visitor's request before letting it in. Harmless requests pass through instantly, while suspicious ones are rejected before your WordPress installation, shop or custom application ever has to deal with them.

This is especially valuable because many attacks target weaknesses in the application itself – in a plugin, a theme or a contact form – rather than in the server.

Threats we filter

What our web application firewall protects you from

The WAF recognises the most common attack techniques used against websites today.

SQL injection

Attackers try to smuggle database commands into forms or URLs to read, change or delete data. The WAF detects these patterns and blocks the request.

Cross-site scripting (XSS)

Malicious scripts injected into your pages could steal visitor data or hijack sessions. Requests carrying such code are stopped at the door.

Brute-force attacks

Automated tools try thousands of username and password combinations on login pages. Repeated failed attempts are recognised and slowed down or blocked.

Bad bots

Bots that scan for vulnerabilities, scrape content or flood forms with spam are identified and kept away, while legitimate search engine crawlers can still visit.

Multi-layer security

One layer in a complete security concept

No single tool can stop every threat. That is why our web application firewall works together with other protective measures on our hosting platform. DDoS protection absorbs large-scale traffic floods, the WAF filters malicious requests, malware scans check your files and backups give you a way back if something does go wrong.

Each layer catches what the others might miss. For you this means strong, coordinated protection without having to install, configure and maintain several security products yourself.

  • Advanced DDoS protection at network level
  • Web application firewall at request level
  • Automatic malware scans at file level
  • Backup and restore as a safety net
All security features

Your advantages

Why a hosting-level WAF makes sense

No performance penalty

Malicious requests are discarded early, so your website spends its resources on real visitors instead of attackers.

Nothing to configure

The protection runs in the background. You do not need security plugins or technical knowledge to benefit from it.

Covers every site

Whether WordPress, Joomla!, a shop or your own PHP application – all websites in your plan benefit equally.

Behind the scenes

What happens to a request

  1. 01

    Request arrives

    A visitor or bot sends a request to your website.

  2. 02

    Inspection

    The firewall checks the request against known attack patterns and behaviour rules.

  3. 03

    Decision

    Legitimate requests are forwarded immediately; malicious ones are blocked.

  4. 04

    Delivery

    Your website responds to genuine visitors as fast as usual.

Questions about our web application firewall

Is the web application firewall included in my plan?
Yes. The WAF is part of the multi-layer security of our hosting platform and protects the websites in every WordPress and Linux hosting plan at no extra cost.
Do I still need a WordPress security plugin?
The firewall already blocks many common attacks before they reach WordPress. A security plugin can still be useful for site-specific settings such as two-factor login, but it is no longer your only line of defence.
Can the WAF block legitimate visitors?
The rules are designed to recognise clear attack patterns, so normal visitors and search engine crawlers are not affected. If you ever notice a problem, our support team will help you.
What is the difference between a WAF and DDoS protection?
DDoS protection defends against huge volumes of traffic intended to overload your website. A WAF looks at the content of individual requests and stops attacks such as SQL injection or cross-site scripting.
Does the firewall replace software updates?
No. The WAF significantly reduces risk, but keeping your CMS, plugins and themes up to date remains important. Our WordPress Manager makes updates easy.
Does the WAF slow down my website?
No noticeable slowdown is to be expected. Because malicious traffic is filtered out early, your server often has more capacity left for real visitors.

Hosting with a built-in web application firewall

Choose your plan and let our security layers keep attackers away from your website.