Absorb scanners before they become origin load
Blocklists, allowlists, rate limits, and 404 bans run in Sitewrap so abusive traffic never needs to wake your CMS, app server, or host.
- ✓IP blocklist with immediate deny
- ✓Allowlist bypass for trusted operators
- ✓404 ban windows for probe-heavy bots
Harden the noisy surfaces without origin rewrites
Block suspicious probes, private path patterns, and common attack files at Sitewrap Edge — then tune rules in the dashboard without SSH.
- ✓Suspicious probe handling (.env, .git, random PHP)
- ✓Route blacklist for private paths
- ✓Rules sync to Sitewrap Edge where possible
Security visibility without careless exposure
The Firewall dashboard shows blocked IPs, reasons, top paths, and bots vs humans. Everyday analytics stay masked; security views keep full IPs for ban workflows.
- ✓24h blocked counts and action breakdown
- ✓One-click block / unblock with reasons
- ✓Audit trail for who changed what