Service · Cybersecurity

Web application firewall (WAF)

Every public web application is probed by automated scanners around the clock. Consider a home textiles brand in İzmir that sells on Trendyol and also through its own WooCommerce store. Its admin login sees thousands of password guesses each night, bots grab limited-stock items into baskets and leave it there, and the server logs are full of requests hunting for a known flaw in an old plugin. During big sale periods traffic spikes, the site slows and genuine buyers stall at checkout. A web application firewall filters that traffic before it reaches the site. It stops known attack patterns, rate-limits sensitive actions such as login and checkout, and acts as a temporary shield when a new plugin vulnerability appears and the fix is not yet installed. Left on default settings, though, a WAF can just as easily block your payment provider's callback or a marketplace sync. The real work lies in tuning the rules to your site, and we do it remotely without moving your shop anywhere.

Ahead of the server
attacks end before the application sees them
Bot control
for login, basket and search
Virtual patching
until the plugin update is installed
No migration
your site stays with its current host

What the work covers in practice

Out-of-the-box rules are a starting point. The value comes from tuning them to the way your particular application behaves.

Agree the scope with the engineer who will do the work

Choosing the model

A cloud WAF in front of your domain, your host's built-in WAF, or ModSecurity on the server itself. The choice depends on traffic, platform and budget.

Core protection

Defences against the classic web attacks, including SQL injection, cross-site scripting and requests aimed at published plugin flaws, with rule sets tailored to WordPress, WooCommerce, OpenCart and Magento.

Bot handling

Per-address request limits on login, password reset, add-to-basket and search. Useful crawlers such as search engines and price comparison services are allowed in.

Partner allowances

Callbacks from iyzico, PayTR or your bank's virtual POS, courier integrations, marketplace feeds and accounting links are explicitly allowed so legitimate automation keeps flowing.

Location rules

If you only sell in Turkey and a few export markets, the admin area can be limited to certain countries while the storefront stays open to everyone.

Monthly check

A short review of blocked requests, false positives and trends, and a fresh look at limits and rules before every big sales event.

How we approach the job, from first call to handover

The WAF watches before it acts, so no order is lost to a false alarm.

01

Analysis

Platform, hosting, integrations and access patterns. Server logs tell us what kind of attacks already hit your site.

02

Log-only mode

The WAF sits in front of the site but blocks nothing yet. For a week or two it records what it would stop, and we review that list.

03

Tuning and enforcement

Exceptions for legitimate traffic, then a switch to blocking. Checkout, customer login and order flow are tested with realistic scenarios.

04

Operation

Monitoring, adjustments whenever a plugin or integration is added, and fast virtual patches when a critical flaw is announced.

A WAF buys time for updates; it does not replace them. Once a flaw in a popular plugin is published, automated exploitation often starts the same day. The WAF holds those requests back while you test and apply the update safely, but it is no excuse to skip the update.

Frequently asked questions

Cloud WAFs from large providers absorb most application-layer floods and usually come bundled with network-layer DDoS protection. A WAF running on your own server cannot reduce the traffic that reaches it, so for sites at real risk of floods we recommend the cloud option.

Hosted platforms take care of the infrastructure and baseline protection themselves, so adding your own WAF is usually unnecessary and sometimes unsupported. The focus there shifts to admin accounts, multi-factor sign-in and installed apps. A self-hosted WooCommerce, OpenCart or Magento store is where a WAF pays off directly.

We find the blocked request in the logs, work out why and add a targeted exception if needed. The approximate time and, if possible, the customer's IP address are enough to go on. Contract clients can report it via helpme@apply.tr.

The provider's fee depends on the plan and your traffic and is billed to you directly; a small site often manages with an entry-level plan. Our set-up and tuning work is separate, either as a fixed quote or at €55 per hour plus VAT against an estimate, and ongoing monitoring can be included in a service plan.

Put a shield in front of your store

Tell us about your platform, hosting and payment and shipping integrations. We will recommend the right WAF approach.

Availability
Weekdays 09:00-18:00 Turkey time (GMT+3); an answer follows by the next working day
Calls
By video, over Microsoft Teams or Google Meet

The only cookies here are the essential ones: they keep the site running and remember the city you picked. Nothing is used for advertising or tracking. See our privacy notice for more.