Section 14 1 min read

Security

WordPress and database services carry a set of security sections on the service page.

Traffic & Threat Activity. A chart of requests and blocked threats for the last 6, 24 or 48 hours.

Protection Controls. Toggles, applied to the site as soon as you switch them:

Control What it does
Web Application Firewall Blocks common exploits. WAF Mode chooses Prevention (blocks) or Detection (logs only)
Rate Limit Login Page Slows brute-force attempts on the login page
XML-RPC Protection Blocks the WordPress XML-RPC endpoint
Bot Filtering Blocks known scanners and malicious bots. Manage bot list adds your own patterns
Block Headless Browsers Blocks automated browsers. This can affect uptime monitors
Auto IP Blocking Enforces your IP blocklist at the edge

Top Targeted Endpoints, Top Client IPs and HTTP Status Breakdown show what is being requested and by whom.

IP Blocklist. Click + Block IP, enter the address and an optional label, and click Add. Unblock removes an entry.

Active Findings. Click Scan Now to probe the site for common security issues. Results list severity, type, description and the file or path involved.

Security Events. Firewall and protection events for the last hour up to seven days. Click a row for the full details.