The firewall plugin adds a web application firewall (WAF) and hardening controls.
Protections
- WAF shields — SQL injection, XSS, remote file inclusion, and directory traversal.
- Security headers — X-Frame-Options, CSP, HSTS, Referrer-Policy, Permissions-Policy.
- IP management — trusted IPs, a blocklist, and auto-ban when the WAF threshold is exceeded.
- Password policy — enforce length, uppercase, number, and special-character rules.
- Access control — admin secret URL, frontend super-user block, and upload restrictions.