@pbn_hosting_sl
oficina@pbnhostingsl.com

Website Firewall – What It Blocks And What To Do If Something Legitimate Is Blocked

Website Firewall – What It Blocks And What To Do If Something Legitimate Is Blocked

Every site you host with us – whatever its type – is behind a website firewall. It reads each request before your site does and refuses the ones that are trying to break in, so most attacks never reach WordPress, Joomla, Drupal or your own code at all. There is nothing to install and nothing to switch on.

💡 Your own work is never second-guessed
Signing in, writing and editing pages, uploading media, installing plugins and themes, the database tool and the file manager are all left alone.

What it blocks

  • Reading files that must never be public – configuration and password files, backups, .env, cloud keys, version-control folders.
  • Climbing out of the site folder – requests with ../ tricks aimed at the server’s own files.
  • Injection – database commands, script tags and shell commands smuggled into a web address or a header.
  • Known attack tools – scanners that identify themselves, and headers used to bypass sign-in on other platforms.

On a typical day this refuses a large share of the traffic that reaches our servers – almost all of it automated scanning, not people.

What a blocked visitor sees

A short page titled Request blocked with a reference – a long code. The page says nothing about how the site is built, is never stored by your CDN, and search engines are told not to index it.

Seeing what was blocked on your site

Open your site and choose Website firewall in the left menu. It shows whether the firewall is on for that site and the most recent blocked requests: when, which address, why and the reference.

Something legitimate was blocked – what to do

  1. Ask the person who saw the page for the reference (or copy it yourself).
  2. Open a support ticket with the reference and the site name.
  3. We look the request up, and either adjust the firewall so that kind of request is allowed, or switch the firewall off for that one site while we do. You do not lose anything in the meantime; switching it back on later is one click on our side.

A payment provider calling your shop back, WordPress’s own scheduled tasks, certificate checks and the database tool are already exempt, so they should never be caught.

Share this article: