WAF & DDOS SERVICES
What we do.
01
WAF setup & tuning
OWASP rules plus Magento/WordPress-specific rules, tuned to avoid false positives.
02
DDoS mitigation
Layer 3/4 and layer 7 attack protection with always-on CDN.
03
Virtual patching
Block known exploits before you can deploy the patch.
04
Rate limiting
Protect login, checkout, search and APIs from abuse.
05
Geo & IP rules
Block high-risk countries or allowlist admin access.
06
Monitoring & reports
Monthly attack report and rule reviews.
WHAT YOU GET
Tuned, not just switched on.
A default WAF blocks real customers or lets attacks through. We tune rules to your platform and traffic.
✓Fixed price — no surprise invoices
✓UK engineers who know Magento & WordPress
✓Post-incident report with root cause
✓Blocklist & Google warning removal
✓30-day re-infection guarantee
✓Hardening so it doesn’t happen again
PRICING
Simple monthly or annual plans.
50% OFFLaunch sale — plus an extra 20% off with code EXTRA20
BASIC
Single site
£14
£7/mo
per month, billed monthly
✓Cloud WAF + CDN
✓OWASP core rules
✓Basic DDoS protection
PRO
Stores
£28
£14/mo
per month, billed monthly
✓Everything in Basic
✓Magento/WP custom rules
✓Rate limiting
✓Monthly report
BUSINESS
High-traffic & enterprise
£94
£47/mo
per month, billed monthly
✓Everything in Pro
✓Advanced layer-7 DDoS
✓Virtual patching
✓Custom rules on request
ONE-OFF OPTION
WAF migration & setup
One-off: DNS cutover, SSL and rule tuning with zero downtime.
£390£195
Order →✓ No setup fees on annual plans✓ Rolling monthly after 3 months✓ You own every account & asset✓ UK-based specialists✓ Prices exclude VAT
RESULTS & REVIEWS
Proof, not promises.
Google4.9 ★★★★★120+ reviews
Clutch4.9 ★★★★★40+ reviews
SUCCESS STORY · EVENTS
Layer-7 DDoS absorbed during on-sale
0 mindowntime
4.1Mmalicious requests blocked
38%less origin load
WAF rules tuned for launch traffic, rate limits on queue and checkout, origin locked behind the CDN.
Read the story →
SUCCESS STORY · BEAUTY
Card skimmer removed and PCI restored in 6 hours
6hto clean & patch
0re-infections
PCIcompliance restored
Found and removed a Magecart skimmer, patched to the latest release, added CSP/SRI and a cloud WAF.
Read the story →
★★★★★
“Our biggest on-sale ever and the site didn’t flinch.”
Chris E.CTO, ticketing platform
★★★★★
“False positives gone after they tuned the rules.”
Maria V.Ops Lead, marketplace
★★★★★
“We were hacked on a Friday night. They had it cleaned and patched before Saturday morning.”
Emma L.Operations Director, beauty store
FREE · NO OBLIGATION
Get a free WAF review.
✓ Free security scan within 24 hours
✓ Malware, blocklist & vulnerability check
✓ Emergency? Call-back within 1 hour
GUIDES & INSIGHTS
Learn from our engineers.
SECURITY · 9 MIN READHow to stop spam and bot attacks on Adobe Commerce CloudFake registrations, newsletter spam and card testing on Adobe Commerce Cloud — how to detect them and block them with Fastly WAF, reCAPTCHA and rate limits.Read the guide →PERFORMANCE · 8 MIN READIs Cloudflare worth it? 9 benefits for ecommerce and business websitesFaster pages, DDoS protection, a WAF, bot management and lower hosting costs — the real benefits of Cloudflare and when it’s worth paying for Pro or Business.Read the guide →SECURITY · 6 MIN READDDoS protection for small business websitesWhat DDoS attacks are, why small businesses are targeted, and affordable ways to protect your website with a CDN, WAF and rate limiting.Read the guide →
WAF & DDoS questions, answered.
Cloudflare suits most sites; AWS WAF fits stores already on AWS. We recommend after the review.
Yes — we allowlist your team and protect the admin URL.
Our launch prices are already 50% off. EXTRA20 takes a further 20% off your first term — enter it above or mention it when you request a quote.
Yes — bundles across SEO, ads, email and tracking get an additional multi-service discount.