← CloudScale Plugin Help/CloudScale Cyber and Devtools: Free WordPress Security, AI Penetration Testing & Developer Toolkit
Request Firewall
Eighteen rules that stand in front of every anonymous request and refuse SQL injection, cross-site scripting, code execution, object injection, file inclusion, traversal, XML attacks and more before WordPress runs. Every value is decoded the way the target would read it, so encoded payloads are caught. Starts in Log only so you can see what it would refuse on your own traffic, then one switch to Block.


🛡️ The Attack Is Refused Before WordPress Runs
The firewall decides as soon as WordPress has loaded its plugins, before the request is routed, before your theme, and before any plugin’s form, AJAX or REST handler runs. A request carrying an attack never reaches the vulnerable code it was aimed at, whichever plugin that code lives in, whether or not anyone has heard of the flaw yet.
Eighteen Rules, in Three Families
Request shape, inspected everywhere, because no reader ever needs them: directory traversal in the path, executable files requested from the uploads folder, uploads named as executable code, probes for configuration and backup files such as .env and wp-config.php.bak, known scanning tools, line-break injection and null bytes.
Parameter content, inspected in every query value, form field, cookie, JSON body and the forwarding headers applications read back: SQL injection, cross-site scripting, code and command execution and template injection, PHP stream wrappers, remote and local file inclusion, serialized PHP objects, prototype pollution, Log4Shell-style lookups, and two rules for whole classes of plugin CVE (below).
Request body, for the payloads that never become a form field: batched XML-RPC calls that carry hundreds of login attempts in one request, and XML external entity declarations.
Encoded payloads are decoded first
Almost every way past a pattern firewall is an encoding of a payload it already knows: a value percent-encoded twice, an HTML-entity script element, a MySQL comment wrapped around UNION, fifty spaces where one would do. CloudScale decodes and normalises every value the way the target will read it before any rule looks at it, so each rule is written once, against the plain form, and still catches the disguises. Seventy-three payloads proven to bypass an earlier version are now a permanent build gate.
Rules for whole classes of plugin vulnerability
A firewall that matches payloads is always one encoding behind. Some attacks, though, need a precondition that no encoding changes:
- A forged submitter. Formidable Forms up to 6.33.1 (CVE-2026-18331) trusted a form field naming who submitted the entry. An anonymous visitor who set it to an administrator’s user ID got their script run in the administrator’s browser. A guest’s form sends 0; a positive ID with no login cookie is refused.
- A request for the administrator role. Registration-form plugins that map a public field to the new account’s role (Bricksforge CVE-2026-14956, Advanced Form Integration CVE-2026-11794), and unauthenticated settings writes that change the default role, all need the word
administratorin a role field from someone who is not signed in. That request is refused.
Built so you can leave it on
- Log first. Log only records what would have been refused and refuses nothing. Read a week of your own traffic in Recent Matches, then switch to Block.
- Your readers are not attackers. Searches and comment text are not refused for mentioning an attack, so a reader searching for sql injection gets results. Signed-in authors are never filtered, so a post with SQL in a code block saves normally.
- One noisy rule never forces the whole thing off. Any rule can be switched off on its own.
- It fails open. If the engine ever errors, the request proceeds.
- It shows its cost. The panel reports the measured time per inspected request, average and worst case.
- It never keeps the payload. Recent Matches stores the minute, address, country, rule, action, method and path. Never the query string, never the body.
Repeat offenders are banned, not just refused
In Block mode every match is counted. An address that keeps tripping rules is a scanner working through a list, and it is handed to Automatic IP Blocking: the same allowlist, the same escalating ban from an hour to a week, the same Telegram alert. A burst of 404s is counted the same way against a much more generous threshold, because stale links are innocent and a directory scanner produces hundreds.
What it does not do
It does not carry a rule written for each newly disclosed vulnerability by a research team. It matches the shapes attacks share, and the preconditions whole classes of them need; for a specific vulnerable plugin, use a shield. It never inspects WP-CLI, scheduled tasks or your own server calling itself.