Vulnerabilities
What is a WAF, and when is it worth paying for one?
Published 2026-07-14 · Last updated 2026-07-14 · Vantyris editorial
A WAF (Web Application Firewall) sits in front of your website and inspects every HTTP request before it reaches your server. It can block SQL injection probes. It can also stop the credential-stuffing bots and scripted attacks that go after /wp-login.php. It cannot fix a missing DMARC record, an expired TLS certificate, or an admin panel you left on the public internet. For most UK small businesses, the better first question is 'have I closed the hygiene gaps a WAF can't see?'
What this means for your business
- A WAF is a filter on web traffic, not a scanner. It reacts to patterns in live requests (bad URLs, suspicious payloads, bot signatures). It does not audit your DNS, email authentication, TLS configuration, or whether port 3389 is open on your office router.
- With a managed WAF (Cloudflare, Sucuri, AWS WAF, vendor bundles on hosting panels), you pay monthly and someone else tunes the rule sets. A self-hosted option (ModSecurity on Nginx/Apache) has lower recurring fees but costs you engineering time.
- On WordPress-heavy SMB sites, a WAF often blocks the noisy bot traffic that hammers
/wp-login.phpandxmlrpc.php. That reduces server load and cuts off a common entry path, but it does not replace patching plugins, enforcing 2FA, or removing user enumeration. - NCSC guidance treats web application firewalls as one layer in depth, not the first layer. Email authentication (SPF/DKIM/DMARC), TLS hygiene, and closing exposed admin ports typically deliver more impact per pound for non-technical owners.
How to fix
Run a hygiene baseline first (TLS, headers, DMARC, exposed ports). If you still see sustained application-layer attacks, or you handle sensitive forms without a developer on call, add a managed WAF at your CDN or host. Tune the rules in log-only mode before you let it block.
- Baseline what a WAF cannot fix. Run a passive external scan (the free Vantyris teaser or equivalent) and close the high-confidence findings first: enforce DMARC beyond
p=none, fix expired certificates, add HSTS and a sensible CSP, and close RDP/SSH on the public internet. A WAF in front of a site withp=noneDMARC still leaves anyone free to impersonate your brand by email. - Decide where the WAF will sit. Most SMBs put the WAF at the CDN edge (Cloudflare orange-cloud, Sucuri reverse proxy), because it sees traffic before it reaches the origin. If you have no CDN, check whether your host offers a one-click WAF add-on. The WAF must terminate TLS or see decrypted HTTP from a trusted upstream. A WAF that only sees encrypted blobs can't inspect payloads.
- Start in detection-only mode. Run the WAF in log/challenge mode for 1-2 weeks. Then review what it would have blocked, and separate real attacks from false positives on your booking widget, payment callback URLs, or admin paths. Only switch managed rule sets to block mode once you understand the false positives.
- Pair the WAF with rate limits on auth surfaces. Add explicit rate limits on
/wp-login.php,/xmlrpc.php, and any custom admin URL. A WAF without rate limiting still lets slow credential stuffing through. Cloudflare's free tier includes basic bot fight mode, and paid tiers add OWASP core rule sets. - Re-scan after the WAF is live. A passive hygiene scan will still flag the same TLS/DNS/header issues, because the WAF doesn't change those grades. What changes is how well you hold up against application-layer noise. Write down the WAF vendor and rule mode, and name the person who gets paged when it blocks legitimate traffic.
Owner: Site owner prioritises. Web host or CDN panel for the WAF toggle. Developer for custom rule exceptions. · Time: Hygiene baseline: 1-2 hours spread over a week. WAF rollout in log mode: 30-60 minutes. Tuning: ongoing through the first month.
Common gotchas
- Don't buy a WAF to make up for an unpatched plugin. A WAF might block some exploit payloads, but against a determined attacker with a fresh CVE, you still need to patch at source.
- Don't enable aggressive OWASP rules on day one without testing checkout, contact forms, and webhooks. Payment providers and CRM embeds often trip generic SQLi rules.
- Don't assume 'we're on Cloudflare' means a WAF is on. Orange-cloud DNS on its own gives you CDN and DDoS protection. On many plans the WAF rule sets are a separate toggle.
- A WAF on the website does nothing for email impersonation, leaked credentials reused on other services, or an employee opening a phishing link.
How to verify the fix
After a week in block mode, check your CDN or host dashboard for blocked-request counts. Run a Vantyris verified scan to confirm TLS, headers, and DNS findings are still tracked independently of the WAF. Then try a few harmless admin URLs yourself from a clean IP, to make sure an over-broad rule isn't locking you out.
Cyber Essentials alignment
This finding informs the following Cyber Essentials control areas (the UK government's baseline scheme, a sound checklist in any country):
- A1. Firewalls: boundary protection between the internet and your services.
- A2. Secure configuration: devices and services hardened against the weaknesses they ship with by default.
Vantyris is not a CE certifying body. The mapping above is informational.
Common follow-up questions
Is a WAF the same as a vulnerability scanner?
No. A scanner looks for misconfigurations and known weaknesses (certificates, headers, DNS, exposed services). A WAF filters live traffic. You want both roles filled, but not by the same product category.
Do I need a WAF if I only have a brochure WordPress site?
Often not at launch. If DMARC is enforced, TLS is current, admin login is rate-limited, and plugins auto-update, many brochure sites run fine without a paid WAF. Revisit when you add ecommerce, patient intake forms, or see sustained bot traffic in server logs.
What does a WAF cost for a small business?
Managed edge WAFs range from free basic bot protection (Cloudflare) to roughly £20-200/month for SMB-focused bundles (Sucuri, some host add-ons). Enterprise WAF contracts are a different category entirely. Budget for tuning time as well as the licence.
Can Vantyris replace a WAF?
No. Vantyris is a passive external hygiene scanner. It tells you in plain English what to fix, and its workflow and monitoring track whether your grades move. A WAF blocks live attack traffic in real time. Use Vantyris to prioritise fixes, and add a WAF when application-layer noise or compliance pressure justifies it.
References
Related explainers
- What a passive security scan can and cannot prove about your site.
- Content Security Policy: the header that stops most XSS attacks dead.
- WordPress REST API user enumeration: what it leaks, and the exact fix.
Want Vantyris to check your domain for this and 196 other problems?
The teaser scan is free and needs no card. A verified scan starts at $10€10£10A$15¥1,500AED 40 and comes with the workspace: finding workflow, score trend, three PDF layouts, share links and monitoring.
Written by Vantyris