Aller au contenu

Security

Ce contenu n’est pas encore disponible dans votre langue.

The Security page holds the protections you configure per site. They complement the platform’s CrowdSec firewall, which runs for every site automatically: CrowdSec reacts to attacking clients across the platform, while these rules enforce what your site should never serve, whoever asks.

Every rule runs in the site’s Varnish instance and applies immediately when you save, without a restart. A request rejected by these rules receives a 403 with an Access Denied page and the header X-Cache: BLOCKED, which is how you tell them apart from a CrowdSec ban.

Rule Default
Geo blocking No countries blocked
Block XML-RPC and trackbacks On
Block author enumeration On
Block sensitive file exposure On
Block PHP execution in uploads On
Security headers On
Block known vulnerability scanners On
Block AI bots Off
Block empty user agent Off
Block custom user agents None

Country Filtering rejects every request coming from the countries you select. The country is determined from the visitor’s IP address using the MaxMind GeoLite2 Country database, and countries are stored as ISO 3166-1 two-letter codes.

Geo blocking is evaluated before the cache bypass rules, so it also applies to logged-in users and to /wp-admin.

Rule Blocks
Block XML-RPC & Trackbacks /xmlrpc.php and /wp-trackback.php
Block Author Enumeration Any URL whose query string contains author= followed by a number, such as /?author=1
Block Sensitive File Exposure URLs containing wp-config.php, wp-config-sample.php, .htaccess or /.git/, ending in .env, or ending in /readme.html or /license.txt (case-insensitive)
Block PHP Execution in Uploads Requests for .php, .php3 to .php9 and .phtml files under /wp-content/uploads/

XML-RPC is used for login brute forcing and pingback abuse, but some legitimate tools depend on it: Jetpack, the WordPress mobile apps and some remote publishing clients. Disable the rule if you use one of them. When it is disabled, XML-RPC requests are passed to the origin and never cached.

Author enumeration reveals usernames through ?author=N redirects. The rule does not cover the REST API’s /wp-json/wp/v2/users endpoint; restrict that endpoint in WordPress if usernames must stay private.

PHP execution in uploads stops the most common way a compromised upload form is exploited: requesting a PHP file that an attacker managed to place in the uploads directory.

Add Security Headers adds these headers to every response from the site’s cache:

Header Default value
X-Frame-Options SAMEORIGIN
X-Content-Type-Options nosniff
Referrer-Policy strict-origin-when-cross-origin
Permissions-Policy camera=(), microphone=(), geolocation=(), payment=(), usb=()

A header your site already sends is never overridden. A site that deliberately allows framing, or sets a stricter policy, keeps its own value.

Each value can be edited per site. Leave a field empty to stop sending that header, and use Reset to defaults to restore the table above. Values may contain printable ASCII characters only, without double quotes, up to 512 characters.

Rule Blocks
Block Known Vulnerability Scanners User agents containing sqlmap, nikto, nmap, masscan, zgrab, wpscan, dirbuster, gobuster, nuclei, whatweb, acunetix, nessus, hydra or medusa
Block AI Bots AI crawlers and training bots: GPTBot, ChatGPT-User, Claude-Web, anthropic-ai, Google-Extended, PerplexityBot, cohere-ai, Bytespider, CCBot, DataForSeoBot, omgili, FacebookBot, Applebot-Extended, YouBot, Diffbot, ImagesiftBot, img2dataset, Scrapy
Block Empty User-Agent Requests without a User-Agent header
Block Custom User-Agents Any user agent containing one of the names you list

User agent matching is case-insensitive. The scanner rule catches tools run with their default settings; an attacker can change a user agent at will, so treat it as noise reduction. CrowdSec’s behavioral detection catches those tools by what they do rather than by their name.

Block Empty User-Agent is off by default because some health checks, monitoring tools and scripts send no user agent. Enable it only if none of yours do.

Custom user agents are matched as substrings: SemrushBot also matches SemrushBot-SA/0.97. You can list up to 50 entries.

The hardening and bot rules run after the cache bypass checks. Requests that bypass the cache, such as those carrying a logged-in cookie or targeting an excluded path, are not evaluated against them. Geo blocking is the exception and applies to every request. What gets cached lists the complete evaluation order.