Included on every plan, even Free

A managed firewall in front of every site

Every request to your site is inspected against rules that block known attack patterns: SQL injection, cross-site scripting, exploit probes against common software. Hostile requests are rejected before your application code runs. It is a web application firewall (WAF) we run and maintain for you, on every plan.

Attack patterns rejected before a line of your code runs
WordPress-aware rules for wp-login and xmlrpc
Country rules for all 243 countries, or whole continents
Rule changes take effect in about 5 seconds
Every request, inspected
Rules maintained by us
GET /shop?id=1 UNION SELECT
SQL injection payload
Rejected
POST /search q=<script>
Cross-site scripting attempt
Rejected
POST /xmlrpc.php, repeated
Flood from one source
Rate limited
GET /wp-login.php
Known abuse-only network
Blocked
GET /products/summer-range
Ordinary visitor
Passed
Rule changes reach every site in about 5 seconds

The managed firewall

What the firewall stops

Hostile traffic is handled in front of your site, so your PHP workers and database never see it.

Known attack patterns

SQL injection payloads, cross-site scripting attempts and exploit probes against common software are matched against rules we keep current. A hostile request is rejected in front of your site; your application code never runs for it.

WordPress-aware rules

Generic rules miss the paths WordPress actually gets hit on. Here, wp-login and xmlrpc carry specific protection, because that is where the attacks land.

Rate limiting

A flood of requests from one source is slowed and then stopped. A hammering script cannot pile requests onto your site faster than it can serve real visitors.

The firewall tier of your security plugin, included

A security plugin's firewall lives inside WordPress, so it can only inspect a request after WordPress has booted: PHP starts, the database is queried, and only then is the request judged. Every attack still costs you CPU, memory and database connections. The firewall tier usually sits behind the plugin's paid upgrade, too.

Here the firewall is part of ScaleShield, the security and speed layer in front of your site, so hostile requests are rejected before they reach it. The same goes for standalone firewall services that charge per site: that job is done here, on every plan. It is one layer of WordPress security on G7Cloud.

  • Junk traffic consumes zero PHP workers and zero database connections
  • No firewall plugin to install, update or renew
  • No separate firewall subscription for each site
  • One rule set, kept current by us for every customer at once
Plugin firewall (inside your site)
RequestPHP bootsDB queriedPlugin blocks

Blocked, but the attack already cost you server resources.

ScaleShield firewall (in front of your site)
RequestFirewall rejectsPHPDB

Rejected before your code runs. The attack costs your site nothing.

Controls per site, live in about 5 seconds

We maintain the platform rule set. On top of it, each site gets its own controls, and any change is enforced across the platform in about 5 seconds.

Country rules

Allow, challenge or block traffic per country, all 243 of them, or act on a whole continent in one rule. A store that only ships to the UK can turn the rest of the map away.

Network-level blocks

Entire hosting networks known only for abuse can be blocked outright, so nothing from them ever reaches your site.

Allow and block lists

Your own lists, per site: addresses you always want through, and addresses you never want to see again.

Changes in about 5 seconds

Every rule change, ours or yours, takes effect across the platform in about 5 seconds. A block is enforced while you watch.

Attack mode: one switch for the worst day

Determined attacks happen. When one does, we flip a single switch on your site, and every visitor without a verified-human pass gets the browser check while the attack lasts: a small piece of work a real browser completes in a moment. No CAPTCHAs, nothing to click.

Real visitors barely notice. The flood stops reaching your site. When the attack ends, the switch goes off and everything returns to normal, in about 5 seconds either way.

  • One switch, flipped by us, live in about 5 seconds
  • Real visitors pass in a moment; the flood is turned away
  • No emergency plugin installs, no DNS changes mid-attack
Attack mode
On
Verified-human pass
Straight through
Everyone else
Browser check first
Fails the check
Turned away

Switched off when the attack ends. The flood never reaches your site while it lasts.

Maintained by us, watched on a live console

You maintain none of this. We keep the rules current platform-wide and watch a live console with automatic anomaly detection: a traffic spike or a surge in blocks flags itself to us. It is the same layer whether the site runs WordPress, a WooCommerce store, a Node.js app or a site from the AI Website Builder.

We maintain the rules

Updated platform-wide for every customer at once. Nothing for you to patch or tune.

We watch the console

Automatic anomaly detection flags a traffic spike or a block surge to us as it happens.

One layer for every site

WordPress, WooCommerce, Node.js apps and builder sites all sit behind the same firewall.

The firewall pairs with the rest of ScaleShield

It is one part of the layer in front of every G7Cloud site. The rest of it:

  • Bot protection: the invisible browser check, impostor-crawler detection and automatic bans that deal with automated traffic.
  • G7Cloud Cache: the same layer serves full copies of your WordPress pages in milliseconds, without starting PHP.
  • ScaleShield: the full picture of the security and speed layer, including free automatic TLS on every site.

Managed firewall FAQ

What the firewall in front of your site does, and what it means for the plugins and services you pay for today.

Do I still need a paid security plugin for its firewall?

No. The firewall tier of a typical security plugin inspects requests inside WordPress, after PHP has started. ScaleShield rejects hostile requests in front of your site instead, and we maintain the rules for you. Plugins that do other jobs, such as malware scanning inside wp-content, can still be useful.

What attack patterns does the firewall block?

Known attack patterns: SQL injection payloads, cross-site scripting attempts and exploit probes against common software. The WordPress paths that attract the most abuse, wp-login and xmlrpc, carry specific rules on top.

Can I block traffic from specific countries?

Yes. Traffic can be allowed, challenged or blocked per country, covering all 243, or by whole continent in one rule. A store that only ships to the UK can challenge or block everywhere else, and the change takes effect in about 5 seconds.

Who maintains the firewall rules?

We do, platform-wide, for every customer at once. A live console with automatic anomaly detection flags a traffic spike or a surge in blocks to us. On top of that you get per-site controls: allow and block lists, country rules and network-level blocks.

What is attack mode?

A single switch we can flip if your site comes under a determined attack. While it is on, every visitor without a verified-human pass gets a quick, invisible browser check. Real visitors barely notice, and the flood stops reaching your site.

Will the firewall block my real visitors?

The rules target known attack patterns, not people, so ordinary visitors pass straight through. If you ever need to guarantee access for a specific address, every site has its own allow list.

Is the firewall included on the Free plan?

Yes. The firewall is part of ScaleShield, the security and speed layer in front of every G7Cloud site, on every plan with no security surcharge. The same protection covers WordPress, WooCommerce, Node.js apps and sites built with the AI Website Builder.

Put a managed firewall in front of your site

It comes with every G7Cloud plan, Free included, and it is on from the moment your site goes live. Nothing to install, no rules to keep, no separate firewall bill.