/etc/passwd reads, script-tag and event-handler XSS, remote file inclusion — and blocks it before WordPress does any further work.
How to access: GuardForge > Settings > WAF.
Free/PRO: Pro (waf).
Notes:
- Administrators are exempt, and same-site URLs in
redirect_toare not treated as remote file inclusion — the two false positives that make firewalls unusable. - Every block is logged with the rule that fired, so a false positive is something you can read and fix rather than guess at.