Section 14
1 min read
Security
WordPress and database services carry a set of security sections on the service page.
Traffic & Threat Activity. A chart of requests and blocked threats for the last 6, 24 or 48 hours.
Protection Controls. Toggles, applied to the site as soon as you switch them:
| Control | What it does |
|---|---|
| Web Application Firewall | Blocks common exploits. WAF Mode chooses Prevention (blocks) or Detection (logs only) |
| Rate Limit Login Page | Slows brute-force attempts on the login page |
| XML-RPC Protection | Blocks the WordPress XML-RPC endpoint |
| Bot Filtering | Blocks known scanners and malicious bots. Manage bot list adds your own patterns |
| Block Headless Browsers | Blocks automated browsers. This can affect uptime monitors |
| Auto IP Blocking | Enforces your IP blocklist at the edge |
Top Targeted Endpoints, Top Client IPs and HTTP Status Breakdown show what is being requested and by whom.
IP Blocklist. Click + Block IP, enter the address and an optional label, and click Add. Unblock removes an entry.
Active Findings. Click Scan Now to probe the site for common security issues. Results list severity, type, description and the file or path involved.
Security Events. Firewall and protection events for the last hour up to seven days. Click a row for the full details.