Support
Log in Sign up

Web application firewall (Pro)

What it does: Inspects each request against ten rules — SQL injection (UNION, tautology, time-based), encoded PHP payloads, command execution, config-file traversal, /etc/passwd reads, script-tag and event-handler XSS, remote file inclusion — and blocks it before WordPress does any further work. How to access: GuardForge > Settings > WAF. Free/PRO: Pro (waf). Notes:
  • Administrators are exempt, and same-site URLs in redirect_to are not treated as remote file inclusion — the two false positives that make firewalls unusable.
  • Every block is logged with the rule that fired, so a false positive is something you can read and fix rather than guess at.
Forge AI Assistant Online

Hi! I'm the Guard Forge AI assistant. Ask me anything about the plugin — setup, features, troubleshooting, or development.

Just now
Powered by Forge AI · Browse docs