Baseline rules
Protection against SQL injection, cross-site scripting and known attacks on PrestaShop, WooCommerce, WordPress and Magento, using provider-managed rules that update themselves.
An online shop gets daily visits from things that are not customers: bots trying passwords on the PrestaShop admin panel, scanners hunting for a vulnerable module, competitors copying the catalogue and prices every hour and, most costly of all, networks using the checkout to test stolen cards against the Redsys payment gateway. Each failed transaction carries a fee and, if it keeps happening, the bank starts asking questions. A web application firewall sits in front of the site and filters that traffic before it reaches the server. We set it up on Cloudflare, AWS WAF, Azure Front Door or a module on your own server, depending on where the site is hosted, and tune it so it stops the bots without getting in the way of shoppers buying on their phones in the middle of the sales.
A WAF does not fix a vulnerable module, but it buys time to update it and removes most of the automated noise.
Protection against SQL injection, cross-site scripting and known attacks on PrestaShop, WooCommerce, WordPress and Magento, using provider-managed rules that update themselves.
Back office access limited by country, by address or by identity, with a cap on attempts. The admin URL stops being the busiest door on the shop.
Rate limits on the basket and checkout, challenges for suspicious sessions and alerts when gateway declines climb. For many shops this is the protection that saves the most money.
We tell legitimate search engines apart from bots that scrape prices or hammer the internal search. The first are let through; the second are slowed down or stopped.
Protection against bursts of malicious traffic at application level, which can take a small shop offline without any huge attack.
A monthly summary of what was blocked and which false positives were fixed, so you know what the filter is stopping and whether it bothers anyone.
Every WAF starts in observation mode. Switching on blocking without knowing your real traffic is the fastest way to lose sales.
Platform, hosting, DNS, payment gateway and installed modules. We decide where the filter goes with the smallest possible change.
One or two weeks logging what the WAF would block, to spot legitimate requests that look like attacks, such as a marketplace feed or calls from the ERP.
Rules are enabled family by family, starting with the safest, and checked daily in the first few days.
A monthly review or, under a support plan, continuous follow-up, with particular care before each campaign.
Stolen-card testing shows up on the payment gateway bill before it shows on the website. Hundreds of small declined payments overnight generate fees and bank warnings while the shop carries on as if nothing were wrong. A per-session attempt limit and a bot challenge cut it off before the bank gets in touch.
Usually not. Cloud WAFs such as Cloudflare work by changing DNS so traffic passes through them before reaching your current server. If the site runs on AWS or Azure, we use that provider's own service. Your hosting stays the same.
Not if it is configured properly. Legitimate search engine crawlers are recognised and allowed through. A WAF with caching also tends to speed up page loads, which does help rankings.
We identify them during observation: the Amazon.es or PcComponentes feed, calls from Channable or Lengow, ERP synchronisation and notifications from Redsys or Bizum. Each gets a documented exception so none of them breaks.
No. The WAF lowers the risk until the update arrives and holds back automated traffic, but a vulnerable module is still vulnerable. It is one more layer alongside updates, strong back office passwords and backups.
Tell us which platform your shop or site runs on, where it is hosted and which payment gateway you use. We will reply with a setup proposal.
Your request is with us
Expect an answer within one working day. A reported fault that has halted your team is handled first.
No match found. Try another spelling, or go with the closest provincial capital: every job is done remotely, so the location makes no difference to what we deliver anywhere in Spain.