What is the ModSecurity web application firewall?
ModSecurity is a web application firewall (WAF) that runs on every Dirham A Day server. While the CSF firewall filters network traffic, ModSecurity inspects the actual web requests hitting your site and blocks ones that look like attacks.
It protects against common web threats such as:
- SQL injection (attempts to manipulate your database through form fields or URLs)
- Cross-site scripting (XSS)
- Malicious file uploads and known exploit patterns
- Automated attacks against WordPress and other applications
It uses a maintained ruleset that recognises the signatures of known attacks, so vulnerable plugins and scripts get an extra layer of defence even before you patch them. This runs automatically; there is nothing to install.
Occasionally, a legitimate action, such as submitting a form with unusual characters or a large content edit, can trip a rule and produce a 403 Forbidden error. If a normal task on your own site is being blocked, note the exact page and what you were doing, then contact our 24/7 team on WhatsApp +971 58 553 6767 or support@dirhamaday.ae. We can review the ModSecurity logs and, if appropriate, adjust or whitelist the specific rule for your account without weakening your overall protection.
Still need a hand? Our UAE-based team is here 24/7.