A managed firewall in front of every site
Every request to your site is inspected against rules that block known attack patterns: SQL injection, cross-site scripting, exploit probes against common software. Hostile requests are rejected before your application code runs. It is a web application firewall (WAF) we run and maintain for you, on every plan.
The managed firewall
What the firewall stops
Hostile traffic is handled in front of your site, so your PHP workers and database never see it.
Known attack patterns
SQL injection payloads, cross-site scripting attempts and exploit probes against common software are matched against rules we keep current. A hostile request is rejected in front of your site; your application code never runs for it.
WordPress-aware rules
Generic rules miss the paths WordPress actually gets hit on. Here, wp-login and xmlrpc carry specific protection, because that is where the attacks land.
Rate limiting
A flood of requests from one source is slowed and then stopped. A hammering script cannot pile requests onto your site faster than it can serve real visitors.
The firewall tier of your security plugin, included
A security plugin's firewall lives inside WordPress, so it can only inspect a request after WordPress has booted: PHP starts, the database is queried, and only then is the request judged. Every attack still costs you CPU, memory and database connections. The firewall tier usually sits behind the plugin's paid upgrade, too.
Here the firewall is part of ScaleShield, the security and speed layer in front of your site, so hostile requests are rejected before they reach it. The same goes for standalone firewall services that charge per site: that job is done here, on every plan. It is one layer of WordPress security on G7Cloud.
- Junk traffic consumes zero PHP workers and zero database connections
- No firewall plugin to install, update or renew
- No separate firewall subscription for each site
- One rule set, kept current by us for every customer at once
Blocked, but the attack already cost you server resources.
Rejected before your code runs. The attack costs your site nothing.
Controls per site, live in about 5 seconds
We maintain the platform rule set. On top of it, each site gets its own controls, and any change is enforced across the platform in about 5 seconds.
Country rules
Allow, challenge or block traffic per country, all 243 of them, or act on a whole continent in one rule. A store that only ships to the UK can turn the rest of the map away.
Network-level blocks
Entire hosting networks known only for abuse can be blocked outright, so nothing from them ever reaches your site.
Allow and block lists
Your own lists, per site: addresses you always want through, and addresses you never want to see again.
Changes in about 5 seconds
Every rule change, ours or yours, takes effect across the platform in about 5 seconds. A block is enforced while you watch.
Attack mode: one switch for the worst day
Determined attacks happen. When one does, we flip a single switch on your site, and every visitor without a verified-human pass gets the browser check while the attack lasts: a small piece of work a real browser completes in a moment. No CAPTCHAs, nothing to click.
Real visitors barely notice. The flood stops reaching your site. When the attack ends, the switch goes off and everything returns to normal, in about 5 seconds either way.
- One switch, flipped by us, live in about 5 seconds
- Real visitors pass in a moment; the flood is turned away
- No emergency plugin installs, no DNS changes mid-attack
Switched off when the attack ends. The flood never reaches your site while it lasts.
Maintained by us, watched on a live console
You maintain none of this. We keep the rules current platform-wide and watch a live console with automatic anomaly detection: a traffic spike or a surge in blocks flags itself to us. It is the same layer whether the site runs WordPress, a WooCommerce store, a Node.js app or a site from the AI Website Builder.
We maintain the rules
Updated platform-wide for every customer at once. Nothing for you to patch or tune.
We watch the console
Automatic anomaly detection flags a traffic spike or a block surge to us as it happens.
One layer for every site
WordPress, WooCommerce, Node.js apps and builder sites all sit behind the same firewall.
The firewall pairs with the rest of ScaleShield
It is one part of the layer in front of every G7Cloud site. The rest of it:
- Bot protection: the invisible browser check, impostor-crawler detection and automatic bans that deal with automated traffic.
- G7Cloud Cache: the same layer serves full copies of your WordPress pages in milliseconds, without starting PHP.
- ScaleShield: the full picture of the security and speed layer, including free automatic TLS on every site.
Managed firewall FAQ
What the firewall in front of your site does, and what it means for the plugins and services you pay for today.
Do I still need a paid security plugin for its firewall?
No. The firewall tier of a typical security plugin inspects requests inside WordPress, after PHP has started. ScaleShield rejects hostile requests in front of your site instead, and we maintain the rules for you. Plugins that do other jobs, such as malware scanning inside wp-content, can still be useful.
What attack patterns does the firewall block?
Known attack patterns: SQL injection payloads, cross-site scripting attempts and exploit probes against common software. The WordPress paths that attract the most abuse, wp-login and xmlrpc, carry specific rules on top.
Can I block traffic from specific countries?
Yes. Traffic can be allowed, challenged or blocked per country, covering all 243, or by whole continent in one rule. A store that only ships to the UK can challenge or block everywhere else, and the change takes effect in about 5 seconds.
Who maintains the firewall rules?
We do, platform-wide, for every customer at once. A live console with automatic anomaly detection flags a traffic spike or a surge in blocks to us. On top of that you get per-site controls: allow and block lists, country rules and network-level blocks.
What is attack mode?
A single switch we can flip if your site comes under a determined attack. While it is on, every visitor without a verified-human pass gets a quick, invisible browser check. Real visitors barely notice, and the flood stops reaching your site.
Will the firewall block my real visitors?
The rules target known attack patterns, not people, so ordinary visitors pass straight through. If you ever need to guarantee access for a specific address, every site has its own allow list.
Is the firewall included on the Free plan?
Yes. The firewall is part of ScaleShield, the security and speed layer in front of every G7Cloud site, on every plan with no security surcharge. The same protection covers WordPress, WooCommerce, Node.js apps and sites built with the AI Website Builder.