Sucuri’s Web Application Firewall (WAF), also referred to as the Website Firewall, is a cloud-based protection service that blocks hacks, DDoS attacks, and zero-day exploits before traffic reaches your server. The WAF inspects all HTTP/HTTPS requests with signature and heuristic detection, applies virtual patching and hardening rules, and includes an intrusion prevention system (IPS) to stop automated attacks and bad bots. Activation requires changing DNS records and Sucuri automatically provisions SSL for encrypted traffic; Pro and Business plans support uploading custom SSL certificates. The solution offers Protected Pages, IP allowlisting for admin areas, and multi-factor options (CAPTCHA and 2FA) to secure sensitive endpoints. Backed by a 24/7 security team, guaranteed malware removal, unlimited manual cleanups on covered plans, and a 30-day guarantee, the service also includes blocklist monitoring & removal and frequent advanced scanning. Performance features include Anycast CDN speed enhancement and caching options to reduce server load. The WAF supports mitigation of Layer 3, 4, and 7 DDoS attacks, virtual patching for unpatched software, and platform-agnostic compatibility with major CMSs and hosting environments.
The WAF is platform-agnostic and integrates with major CMSs and hosting providers, including WordPress, Magento, Shopify, Drupal, Wix, and Joomla. It operates as a DNS-based cloud proxy with Anycast CDN integration, automatic SSL provisioning and optional custom SSL uploads on Pro/Business plans, and adapts via custom firewall rules for different hosting environments.
Sucuri is a renowned cybersecurity company specializing in website security, offering services such as malware detection, protection, and performance optimization to safeguard websites from online threats.