Solutions & guides

How ProtectMyWebsite compares, how it protects popular platforms, public-sector, and multi-site teams, and plain-English web security guides. Agency web shops can hand off the WAF and stay the web partner.

Rules start in count. After 24 hours, your dashboard shows what's safe to block — one click. Promote Copilot reads your count window and explains what's safe to promote — you still click once. $150/site/mo, 14-day trial — or Campus Estate for campus teams.

Compare

WAF by platform

WAF by vertical

Multi-site teams

Agency partners

Security guides

What is a WAF (Web Application Firewall)?
A plain-English explanation of what a web application firewall (WAF) is, what it protects against, and how a managed WAF works.
The OWASP Top 10, explained simply
A simple explanation of the OWASP Top 10 web application risks and how a web application firewall mitigates them.
HTTP security headers, explained
What the important HTTP security headers do — HSTS, Content-Security-Policy, X-Frame-Options, and more — and why they matter.
What is WAF count mode? (and why you start there)
Count mode lets campus and agency teams put a WAF in front of production without blocking real users on day one — observe ~24 hours, then promote what's safe to block.
What a WAF 403 page means (and why you start in count)
A branded 403 is what visitors see after you promote a rule to block. Count mode comes first. Promote Copilot explains what's safe — you still click once.
What's safe to block on a WAF?
Learn what's safe to block on a managed WAF. Rules start in count; Promote Copilot explains Promote, Hold, or Needs allowlist — you still click once.
WAF false positives on forms: stop blocking legitimate POSTs
Why WAFs block registration, admissions, and government forms — multipart uploads, CSRF tokens, odd field names, payment callbacks — and how count-first stopping of false positives works.
Managed WAF for WordPress without a plugin
Edge-managed WAF for WordPress — no security plugin. Cover campus departmental sites, plugin lag, and upload/form abuse with count → promote.
Managed WAF for Shopify without app spam
Edge-managed WAF for Shopify — no security app. Cover custom and headless storefronts, marketing domains you control, and cart/checkout Ajax with count → promote.
Managed WAF for Magento without an extension
Edge-managed WAF for Magento and Adobe Commerce — no security extension. Cover campus bookstores, StyleSmuggler-class zero-days, and payment paths with count → promote.
Managed WAF for Drupal without a module
Edge-managed WAF for Drupal — no security module. Cover campus multi-site estates, contrib lag, and virtual patch XSS with count → promote.
Managed WAF for government websites
City website firewall for permits, benefits, and FOIA. How a managed WAF for government websites handles public sector WAF false positives and origin IP lock-down — count first, then promote.
WAF bot management for campus and agency sites
WAF bot management for campuses and agencies — stop scrapers, admissions form spam, and credential stuffing without day-one false positives. Count → promote.
WAF for student portals without breaking SSO
WAF for student portals without breaking SSO — count-first SIS, LMS, and IdP callbacks. Stop login stuffing; keep real students. Count → promote.
Managed WAF for higher education websites
Managed WAF for higher education — university website firewall, college website WAF, campus managed WAF. Count → promote; admissions forms stay up.
Virtual patching websites with a managed WAF
Virtual patching at the edge buys time before CMS updates land. Managed WAF rules start in count; promote what's safe to block — Copilot explains, you click.
Emergency virtual patching when a CMS CVE drops
Friday CMS CVE? Put an emergency virtual patch at the edge in count first, then promote what's safe while WordPress and Drupal teams patch. Copilot explains — you click.
Hide your origin IP behind a WAF (and allowlist edge IPs only)
Origin IP bypass DDoS walks around your edge. Hide the origin IP behind a WAF and allowlist edge IPs only — the durable fix for campus and agency sites.
Campus DDoS response: keep .edu sites up under flood
Campus DDoS response for .edu and agency sites — first-hour playbook, origin IP lock-down, count→promote during recovery, and status/comms when the flood hits.
DIY WAF vs managed: console burden or operator?
DIY WAF vs managed for campus and agency teams. When console burden wins — and when managed WAF pricing is worth it vs running your own.

Blog