Website Firewall (WAF)

Complete Website Security Achieved With

Website AntiVirus Plans SEE FEATURES

Protect your Website from Hackers, Malware and Blacklists!

The perimeter defense your website deserves, bringing you peace of mind

Some Platforms We Support Wordpress Joomla Drupal Magento Microsoft Dot Net OSCommerce vBulletin PhpBB
Features Website AntiVirus Website Firewall
Stop Hackers Yes Yes
DDOS Mitigation Yes Yes
Performance Optimization Yes Yes
Web Application Firewall Yes Yes
Malware Detection Yes No
Malware Cleanup Yes No
Blacklist Removal Yes No
Find Out More LEARN MORE
Distributed Denial of Service - DDOS Mitigation

Distributed Denial of Service

(DDoS) Mitigation

DoS / DDoS attacks have increased in popularity. They are easy to employ and highly effective. Often, the attacker has to do little to cause your website harm. The goal is to disrupt your business by taking your website off-line. Stay ahead of these attacks.

Layer 7 HTTP Flood Attacks

DNS Amplification Attacks

SSDP Attacks

Distributed Denial of Service - DDOS Mitigation

Brute Force

Protection and Prevention

Regardless of platforms, attackers are looking to hack your website via any means possible. One very popular technique employs a concept known as Brute Force attacks. This technique is antiquated, yet highly effective. It's a means of trying every possible combination of username and password against your log in panel, in the attempt at guessing the right combination, in turn gaining access to your website..

Throttling of Access Attempts to Entry Points

Brute Force Attacks Against WordPress, Joomla and Others

Introduction of IP Whitelisting Access Features

Vulnerability Exploitation Prevention

Stop Website

Attacks and Hacks

The biggest contributor to website hacks today come from insecure code being exploited. With enough time, as new techniques are found, attackers find ways to exploit weaknesses in code. The Website Firewall helps stop those vulnerabilities from being exploited.

SQL Injection Attacks

Cross Site Scripting (XSS)

Stop Hackers Exploiting Software Vulnerabilities

Malware Prevention



No one wants to know that their website is being used to infect online visitors. Whether it's to install a Trojan or something similar on their computer, or to steal credentials to their social platforms (i.e., Facebook, Twitter, etc..).

Stop Your Website From getting Infected

Prevent Google Blacklists

Protect your Brands Reputation

Zero Day Immediate Response

Zero Day

Immediate Response

Zero Day attacks have been around since the beginning of the security industry. They signify the moment where vulnerabilities are disclosed and a patch is not available. It's the moment where you and your website are at the greatest risk. Our Website Firewall allows us to virtually patch your environment within minutes of a Zero Day event being disclosed.

Virtual Hardening

Virtual patching

Protection in the Cloud

Performance Optimization



The biggest concern with security implementations is always the impacts to the websites performance. Rest assured that with our Website Firewall, you experience dramatic increases in performance, not just in how your website loads for your clients, but in the load placed on your web server.

Restore your brands reputation

Reduced load on infrastructure

Improved Website Performance

Platform Agnostic / Simple Configuration

Platform Agnostic

Simple Configuration

The beauty of the Sucuri Website Firewall is it works across all platforms, including today's most popular brands - WordPress, Joomla!, Drupal, vBulletin and many more. It supports Apache, NGINX, and Windows web servers as well. It was built with the end-user in mind, allowing for quick and easy deployments.

No product installation required

Supports all Content Management Systems (CMS) — WordPress, Joomla, etc...

Support all Web Servers — Apache, IIS, NGINX

Complete Website Security Achieved With

Website AntiVirus Bundles



  • Do you offer refunds?

    Yes we do in the following conditions:

    1. It's within 30 days of purchase.

  • How do you define a website?

    The definition of a website varies by organization, here at Sucuri it is non different and we define a website very clearly. To us, a website in most instances is a unique Fully Qualified Domain Name (FQDN).

    There are however several situations in which more clarity is required. This is especially true for those that make use of a Content Management System (CMS) like WordPress, Joomla!, Drupal and so many others. In these instances, we extend the definition of a website to include unique CMS installations.

    To clarify further, the following configuration require a unique license: directs traffic to

    In situations like the one described above, the FQDN requires unique attention, which is why it requires its own coverage. This is especially true when dealing with FQDNs that have been blacklisted.

    The following configuration does not require a license: or

    In this configuration, we will treat the blog / forum or other extension of the main website as part of the main website, as long as a FQDNS is not associated with the directory. If a FQDN is associated with the directory, again, it will require its own license. This means if your domain configuration is or then you would require a unique license for all three, the main domain and the subdomains.

  • What do I have to do to cancel?

    For your security, all cancellation requests must be initiated via the ticketing system. You open a general support request. Once that request has been assigned, the team will ask you to fill out a survey and we'll initiate the refund.

  • How do you handle WordPress Multisite installs?

    We understand and appreciate the complexities of Multisite instances. For the Website AntiVirus, you must sign up for a plan that covers all Fully Qualify Domain Names (FQDN). Yes, we understand they share the same core, but they don't always share the same theme. Depending on your configuration, you could have multiple unique domains pointing to one install. Those distinct domains could be affected or blacklisted, and without directed knowledge of the domains we'd be none the wiser. To address this, a license is required for every domain to ensure we go through each one individually. Due to the nature of Multisite configurations, you cannot effectively sign up to cover just one domain without touching all of the others.

    Examples of this configuration that does require a license include:



    Examples of this configuration that does not require a license includes:


  • Does this plan include malware cleanup?

    The Website Firewall is a standalone product, if you believe you are infected you require the Website AntiVirus product. The Website AntiVirus product includes the Website Firewall.

  • Can I upgrade ?

    Yes, we offer various upgrade options once you've subscribed. If you do not find the upgrade you're looking for, please submit a General Request and our administrative team will give you a hand.

  • Do you offer volume pricing?

    Yes, we definitely do but you'll need to engage our team via email at

  • Do you offer any partnerships with hosts or development shops?

    It depends on the circumstances, it's best to engage us directly via email at

  • Is this a subscription service?

    Yes, all plans are subscriptions, if you wish to stop the subscription you will need to submit a general request form via your dashboard. Requests to stop subscriptions will not be accepted over the phone, chat or email.

  • Can I cover my subdomains and test sites?

    A license is required for every subdomain ( and unique website structure.

  • Are there any additional taxes or fees?

    There are no extra fees, no additional taxes, and no hidden costs. The price you see is the price that you pay. All of our prices are listed in USD, and the conversion will be automatically handled by our third-party transaction processors.

  • If I have the Website Firewall, can I upgrade to AntiVirus Plan? What is the difference between the products?

    Yes, you can upgrade by submitting a general ticket request, or going to your account settings.

    The AntiVirus plan includes the three key pieces of security - Protection | Detection | Response. The Firewall is included with the AntiVirus product, it’s supplemented with a monitoring engine that is continuously scanning for security issues and globally distributed incident response team in the event of a security incident.

  • Are you going to host my website if I sign up to your Website Firewall?

    No, we do not host your website. We will function as an intermediary for all your incoming traffic; this means that all your traffic will funnel through our secure network but will be sent directly to your host / web server.

  • Will the Website Firewall work with my CDN or my Hosting company?

    Yes, we play very nicely with a number of the largest CDN providers - including CloudFlare, MaxCDN, Amazon CloudFront, and others.

    Our team can help navigate the configuration of any CDN via the ticketing system in your account.

  • Will the Website Firewall affect my SEO?

    No, the Firewall does not affect your SEO.

  • Will the Firewall work with my plugin / theme / service?

    The Website Firewall is a Software as a Service (SaaS) solution. This means it doesn’t require a local configuration at the application layer (this is where the plugins / themes live). With that in mind, if there is an issue it’d be in how the communication occurs between the user's browser and the web server. In those cases, our team is available to troubleshoot to get you back up and running.

  • Do you guarantee my site won’t get compromised?

    We guarantee we’ll do everything within our power to keep the website safe. In security though there is no 100% solution, while we’re highly effective there are various variables we cannot account for (i.e., the website owner, the web server environment).

    Example: if an attacker discovers your admin passwords, or if your website is infected from the back-end (server cross-contamination or compromise). You should also ensure that you have set a rule to prevent Firewall bypass in your .htaccess in case someone knows your website’s IP address.

  • Which plan do I need for my HTTPS (i.e., using SSL) website?

    You require the Professional plan.

How Does the Website Firewall Work

  • How does the protection work?

    The protection feature is a custom Website Firewall solution that functions as a perimeter defense for your website. In technical terms, it's recognized as an Intrusion Detection System and an Intrusion Prevention System (IPS) designed specifically for websites. It filters all incoming traffic to your website through our network, allowing us to detect and stop all malicious traffic.

  • Will there be any downtime associated with the activation process?

    The migration is seamless and you should not experience any down time.

  • Will this protection stop hackers from exploiting vulnerabilities?


  • What is a DDoS attack?

    A distributed denial-of-service (DDoS) attack happens when multiple IP addresses (sources) are trying to DoS (denial-of-service) a chosen target. This means that the targeted site or server gets so many requests that it cannot respond to legitimate traffic, or responds so slowly that it is rendered as unavailable. If these attacks are successful, there will be a server overload and the site will go down.

    There are many types of DDOS attacks that can affect and bring down a website, and they vary in complexity and size. The most well known attacks are the syn-flood, Layer 3/4 UDP and DNS amplification attacks, and Layer 7 HTTP Flood Attacks.

  • Where are your servers located?

    High availability infrastructure is one of our Firewall’s features. To best assist our clients, our servers are distributed around the world. For more information please see our knowledge base article.

  • Does the Firewall offer load balancing?

    The Business plan offers load balancing. This distributes traffic across a number of servers to increase capacity and reliability.

  • What security options are available?

    The Firewall offers a number of configuration options including Protected Page, blocking XMLRPC, IP WhiteListing, Virtual Patching and Hardening, and many more settings you can review in our knowledge base.

  • Why do I need your AntiVirus if I have the Firewall?

    It’s a concept known as Layered Defenses. We can not promise 100% Detection or 100% Protection, but with both we can assure you of a much lowered threat risk to your website. What one fails to stop, the other will catch.

  • Does the Website Firewall protect my email?

    No, the Firewall is for your website only.

  • What if someone tries to bypass your Firewall?

    We recommend only allowing HTTP access from our firewall. To do this, you have to add restrictions to your .htaccess file so that only your Firewall IP will be able to access your web server. More about how to do this in our knowledge base.

Customer Support

  • Can I talk directly to the Support team?

    All support is handled via our ticketing system. We do not currently offer chat or phone support to clients.

  • Do you work every day?

    Yes, we provide support year round, 7 days a week, 24 hours a day.

  • Do you offer a Service Level Agreement?

    Yes, the Firewall plans offer different SLA's depending on your plan. They range from 8 support hours per day to full 24-hour support.

  • Will you configure the Website Firewall for me?

    Yes, if you require assistance we'll be happy to help you get configured. We only need access to your DNS manager, but be sure to submit the request via the ticketing system.

Contact Us For Any Answer

Get in touch with us and we will help you right away!

Contact Us
Sucuri KnowledgeBase

Learn everything about our products and how they work

Learn More