Skip to main content

Glossary Entry

What is WAF?

What WAF actually means, buzzwords removed — with the example that makes it land.

The short answer

A WAF inspects incoming web requests for attack patterns such as SQL injection, injected scripts and probes for known exploits, and stops them before your application runs.

The rest of the page opens it up — the mechanics, why a site owner should care, and one concrete example of it at work.

By the Hosting & Domains team · Reviewed 18 August 2026

0

Jargon left undefined

100+

Entries, all cross-linked

Real

Working examples

Free

To read, always

It matches every request against maintained rule sets updated as new vulnerabilities become public. How fast those rules arrive is the real product. A WAF at server level, such as the Imunify360 on our protected plans, stops requests underneath the application, before it is ever involved.

False positives are the tax you pay. Now and then a genuine submission looks like an attack, and the remedy is a narrow exception for that rule on that path, never switching the shield off.

The everyday parallel

A scanner on the inbound conveyor, checking parcels against a list of dangerous contents refreshed daily. Once in a while something harmless looks wrong on the screen and gets detained.

Carry that picture with you and most documentation on the topic loses its mystery on a first read.

Why it matters to a site owner

A WAF buys time and coverage. Holes you have yet to patch stay unexploited, and a great many attempts are stopped without you ever hearing of them. Paired with an updating habit, it covers both halves of the problem.

That, incidentally, is the bar for any technical term — not 'could I lecture on it' but 'would I recognise it as the answer to my problem'. For this one, you now would.

How it turns up day to day

Monday brings a public plugin vulnerability, and by Tuesday the WAF rule sets already know what its exploit looks like. Anything sitting behind it is covered across that gap, before the owner has read the news.

Entirely unremarkable once you have seen it — which is the point: most hosting ideas are plain machinery behind an intimidating label.

Where it sits inside your own account

You will meet it in the control panel and now and then in a support thread, usually already set correctly. If this one landed, the natural follow-ups are Firewall, Malware, SQL Injection and Cross-Site Scripting.

Mailboxes at your own name are part of the plan — mail is included, not sold back to you at the checkout.

The filtering that absorbs an attack well before it reaches the site

Unexplained jargon slows everybody down

An unexplained piece of jargon is, to us, a service defect. This is the support team's collected translations, published where a search engine can hand them over on our behalf.

The rate you register at is the rate you renew at, so year two costs precisely what year one did — nothing lying in wait on the invoice.

  • 100+ entries, plain English all the way
  • Ordinary analogies, working examples
  • Neighbouring ideas linked together
  • Written by our own support engineers

Why Hosting & Domains

Standard on every plan

Tied to real hosting

Examples name platforms you would genuinely use, never an abstract diagram on a whiteboard.

The next step, drawn out

Carry on into Firewall and Malware — ideas rarely travel alone, so the neighbours are linked in.

Jargon-free by design

Definitions written for people who run sites, not for other sysadmins — translation rather than restatement.

Stakes made explicit

More than what a thing is: the moments it turns out to be the answer to a problem you have.

This term, properly landed

WAF defined, pictured by analogy and located in your own panel — recognise-level after a single read.

Clear about how deep to go

Most of these are recognise-level rather than operate-level, and every entry says which it is.

Quick Start

Order placed to site online

  1. 1

    Find it in your own account

    Open the control panel and find where this idea sits — a definition turns into understanding the moment it attaches to your own site.

  2. 2

    Check the defaults as they stand

    The platform ships sensible defaults for this — check rather than assume, and your setup becomes something you know instead of hope.

  3. 3

    Chase the neighbouring terms

    Hosting terms travel in groups — Firewall, Malware and SQL Injection finish this one's picture, each a two-minute read away.

Built In

Fitted to every plan

  • cPanel, which is what most of the industry already runs
  • People on the support desk every hour of every day
  • DDoS filtering absorbed at the network edge
  • A renewal figure identical to the one you registered at
  • A daily copy, with restores you run yourself from the panel
  • No set-up charge at any point, and no joining fee
  • Softaculous included for one-click application installs
  • Money back within 30 days on hosting plans, 7 on reseller
  • Your existing site brought across by our engineers, at no charge
  • NVMe SSD storage on every tier, not only the dear ones

Frequently Asked

The questions that come up most

With a WAF in place, can I stop updating?

No. It spans the gap rather than closing it. Rules match attack patterns somebody has already catalogued, whereas a patch deletes the underlying flaw. One covers the other's blind spot, and running just one leaves a failure mode you could write down beforehand.

The WAF is blocking my contact form. Now what?

Write a targeted exception for that rule on that path and the form works again while the shield stays up everywhere else. That adjustment takes our support desk a few minutes. Switching the WAF off to rescue one form is a bargain nobody should take.

What is the refund position if I change my mind?

Shared, business, WordPress and WooCommerce hosting get thirty days, and reseller gets seven. VPS and dedicated servers are built to order the moment payment lands, so they sit outside the guarantee — as do domain registrations, where the registry charges the instant the name is secured. Inside the window one request returns the hosting fee, with no retention script to sit through.

Does hosting include mail?

Yes — every hosting plan includes mailboxes at your own name, with webmail, IMAP, POP and SMTP plus spam filtering on from the start. There is standalone email hosting too, for a name whose website lives somewhere else.

Keep reading

Changing hosts? Run through our checklist first.

A plain order of work for a move nobody visiting will notice: which files go over first, how to carry the mail across without losing a message, when exactly to repoint DNS, and the two mistakes behind nearly every outage we are asked to rescue.

What arrives is the checklist, and then the occasional note on keeping a site quick. Leave whenever you like; the privacy policy covers the rest.

Your site has earned better hosting.

Every plan carries the essentials other hosts bill as extras — and support that answers.

View Plesk Reseller Hosting plans