SecuritySW Edge · SW App

Stop abuse at Sitewrap Edge — before it reaches your origin.

Sitewrap Edge firewall, origin hardening, form protection, admin gating, bot controls, and a firewall dashboard — so scanners and spam hit Sitewrap first, not your hosting.

Sitewrap EdgeFirewall · cache · tracking
Bot blockedAdmin gatedOrigin protected

Absorb scanners before they become origin load

Blocklists, allowlists, rate limits, and 404 bans run in Sitewrap so abusive traffic never needs to wake your CMS, app server, or host.

  • IP blocklist with immediate deny
  • Allowlist bypass for trusted operators
  • 404 ban windows for probe-heavy bots

Harden the noisy surfaces without origin rewrites

Block suspicious probes, private path patterns, and common attack files at Sitewrap Edge — then tune rules in the dashboard without SSH.

  • Suspicious probe handling (.env, .git, random PHP)
  • Route blacklist for private paths
  • Rules sync to Sitewrap Edge where possible

Security visibility without careless exposure

The Firewall dashboard shows blocked IPs, reasons, top paths, and bots vs humans. Everyday analytics stay masked; security views keep full IPs for ban workflows.

  • 24h blocked counts and action breakdown
  • One-click block / unblock with reasons
  • Audit trail for who changed what
Protection layers SW Edge · SW App

Four layers between the internet and your origin.

Sitewrap stacks firewall, probe defense, form protection, and admin gating so automated abuse dies early — while real visitors and unlocked operators keep moving. Works in front of any CMS or static site.

01 · Firewall

Block, allow, rate-limit, ban

Master switch, IP allowlists, blocklists, rate limits, and 404 ban windows absorb scanners before they become origin CPU.

  • Immediate deny for blocked IPs
  • Trusted IPs bypass every firewall block
  • Rules sync to Sitewrap Edge where possible
02 · Path defense

Stop probes and private routes early

Block suspicious probe paths, junk files, and private-route patterns before they reach your CMS, app, or static host.

  • Suspicious probe handling
  • Route blacklist for private paths
  • WordPress-specific extras on /supported-cms/wordpress
03 · Forms

Spam dies before it becomes a lead

Honeypots, minimum time-on-page, signed tokens, bot UA checks, and per-IP form rate limits keep Forms and Leads clean.

  • Reject or silent-block modes
  • Works on proxied HTML forms
  • Sensitive field values stay out of storage
04 · Admin gate

Login is not a public endpoint

Gate admin and login screens until Sitewrap unlocks them with a passwordless flow — so random scans never reach the unlock screen.

  • Magic link + short code unlock
  • Unlock cookie on the customer domain
  • Works with remapped admin paths
Firewall Last 24h
Blocked1,284
Unique IPs96
Bots81%
Humans19%
Rate limit37.76.x.x Suspicious probe/.env XML-RPC blocked/xmlrpc.php

See what Sitewrap stopped.

Review blocked IPs, reasons, top paths, and request previews in the Firewall dashboard — then block or allow in one click.

Why teams wrap for securityEdge-first

Security that fits how websites actually get attacked.

Most abuse is automated. Sitewrap stops the noisy stuff at the edge so your origin stays available for real visitors and real work — any CMS or static site.

Is this only for WordPress?

No. Firewall, form protection, bot controls, route blacklist, and admin gating work in front of any website. WordPress gets extra defaults — covered under Supported CMS → WordPress.

Where are rules enforced?

Controls run in Sitewrap App and sync to Sitewrap Edge where possible — so denials happen before traffic becomes expensive origin work.

Can we allow our office IP through everything?

Yes. Allowlisted IPs bypass firewall blocks so trusted operators, agencies, and monitoring can keep working while abuse stays blocked.

How do analytics and security treat IPs?

Request log and live analytics mask IPs by default. The Firewall dashboard shows full IPs so you can ban offenders and review security events accurately.

What about form spam?

Sitewrap can require honeypots, minimum time on page, signed tokens, bot UA checks, and per-IP rate limits before a submission becomes a lead or reaches your origin.

Wrap your site with edge security that operators can run.

Create a Sitewrap account, turn on the firewall, harden exposed surfaces, and keep admin gated — without rebuilding your website.