Security
The Security page holds the protections you configure per site. They complement the platform’s CrowdSec firewall, which runs for every site automatically: CrowdSec reacts to attacking clients across the platform, while these rules enforce what your site should never serve, whoever asks.
Every rule runs in the site’s Varnish instance and applies immediately when
you save, without a restart. A request rejected by these rules receives a
403 with an Access Denied page and the header X-Cache: BLOCKED, which
is how you tell them apart from a CrowdSec ban.
Defaults
Section titled “Defaults”| Rule | Default |
|---|---|
| Geo blocking | No countries blocked |
| Block XML-RPC and trackbacks | On |
| Block author enumeration | On |
| Block sensitive file exposure | On |
| Block PHP execution in uploads | On |
| Security headers | On |
| Block known vulnerability scanners | On |
| Block AI bots | Off |
| Block empty user agent | Off |
| Block custom user agents | None |
Geo blocking
Section titled “Geo blocking”Country Filtering rejects every request coming from the countries you select. The country is determined from the visitor’s IP address using the MaxMind GeoLite2 Country database, and countries are stored as ISO 3166-1 two-letter codes.
Geo blocking is evaluated before the cache bypass rules, so it also applies
to logged-in users and to /wp-admin.
WordPress hardening
Section titled “WordPress hardening”| Rule | Blocks |
|---|---|
| Block XML-RPC & Trackbacks | /xmlrpc.php and /wp-trackback.php |
| Block Author Enumeration | Any URL whose query string contains author= followed by a number, such as /?author=1 |
| Block Sensitive File Exposure | URLs containing wp-config.php, wp-config-sample.php, .htaccess or /.git/, ending in .env, or ending in /readme.html or /license.txt (case-insensitive) |
| Block PHP Execution in Uploads | Requests for .php, .php3 to .php9 and .phtml files under /wp-content/uploads/ |
XML-RPC is used for login brute forcing and pingback abuse, but some legitimate tools depend on it: Jetpack, the WordPress mobile apps and some remote publishing clients. Disable the rule if you use one of them. When it is disabled, XML-RPC requests are passed to the origin and never cached.
Author enumeration reveals usernames through ?author=N redirects. The
rule does not cover the REST API’s /wp-json/wp/v2/users endpoint; restrict
that endpoint in WordPress if usernames must stay private.
PHP execution in uploads stops the most common way a compromised upload form is exploited: requesting a PHP file that an attacker managed to place in the uploads directory.
Security headers
Section titled “Security headers”Add Security Headers adds these headers to every response from the site’s cache:
| Header | Default value |
|---|---|
X-Frame-Options |
SAMEORIGIN |
X-Content-Type-Options |
nosniff |
Referrer-Policy |
strict-origin-when-cross-origin |
Permissions-Policy |
camera=(), microphone=(), geolocation=(), payment=(), usb=() |
A header your site already sends is never overridden. A site that deliberately allows framing, or sets a stricter policy, keeps its own value.
Each value can be edited per site. Leave a field empty to stop sending that header, and use Reset to defaults to restore the table above. Values may contain printable ASCII characters only, without double quotes, up to 512 characters.
Bot and scanner protection
Section titled “Bot and scanner protection”| Rule | Blocks |
|---|---|
| Block Known Vulnerability Scanners | User agents containing sqlmap, nikto, nmap, masscan, zgrab, wpscan, dirbuster, gobuster, nuclei, whatweb, acunetix, nessus, hydra or medusa |
| Block AI Bots | AI crawlers and training bots: GPTBot, ChatGPT-User, Claude-Web, anthropic-ai, Google-Extended, PerplexityBot, cohere-ai, Bytespider, CCBot, DataForSeoBot, omgili, FacebookBot, Applebot-Extended, YouBot, Diffbot, ImagesiftBot, img2dataset, Scrapy |
| Block Empty User-Agent | Requests without a User-Agent header |
| Block Custom User-Agents | Any user agent containing one of the names you list |
User agent matching is case-insensitive. The scanner rule catches tools run with their default settings; an attacker can change a user agent at will, so treat it as noise reduction. CrowdSec’s behavioral detection catches those tools by what they do rather than by their name.
Block Empty User-Agent is off by default because some health checks, monitoring tools and scripts send no user agent. Enable it only if none of yours do.
Custom user agents are matched as substrings: SemrushBot also matches
SemrushBot-SA/0.97. You can list up to 50 entries.
How these rules interact with caching
Section titled “How these rules interact with caching”The hardening and bot rules run after the cache bypass checks. Requests that bypass the cache, such as those carrying a logged-in cookie or targeting an excluded path, are not evaluated against them. Geo blocking is the exception and applies to every request. What gets cached lists the complete evaluation order.