Inline WAF · No proxy · No DNS

Protect your site from attacks. Don't lose sales.

CoreWAF blocks bots, attacks and junk traffic from inside your own site.

No credit card · Setup in minutes · Cancel anytime

CoreWAF dashboard: requests, blocks and real-time metrics

How it works

Interactive dashboard

Requests, blocks and unique IPs in real time, with hourly charts and a breakdown by traffic type.

Under Attack mode

Under active attack, block all traffic in one click except your whitelist. Turn it off when the storm passes.

Bots & AIs under control

Classifies every visit: bots, crawlers, scrapers, AIs and search engines. See who comes in and block the rest.

Rules your way

Block by IP, CIDR, User-Agent or URL with exact operators: contains, starts, ends and exact.

Priority whitelist

Whatever you mark as legit is never blocked, no matter what. One click to unblock.

Top IPs, URLs & countries

See where traffic and attacks come from: top IPs, User-Agents, URLs and countries.

Ready-made rules

You start protected: preset rules against known bots, attacks and abuse, updated daily.

Quality support

Real people who know the product. We help you set things up and stop attacks when it matters.

What makes us different?

No DNS changes · No proxy mode.

Traditional proxy WAF

Intercepts traffic before it reaches your server

Other WAF and CDN providers

  • You lose DNS control and add slow wait times
  • If the provider goes down, your site goes down
  • Generic rules with a high false-positive rate
  • You lose access to logs — you depend on your provider
  • SSL certificate management under third-party control
  • Incompatible or problematic when combined with other CDNs

You pay for volume, not features.

500 K

hits / mo

€1.95 /mo

No API access

Start

25 M

hits / mo

€9.95 /mo

API access

Start

Need more?

Enterprise

Contact us

API access

Contact us
FAQ

Frequently asked

Does it work if I already have Cloudflare or Sucuri in front?

Yes. CoreWAF lives inside your site, not at the edge, so they coexist without conflict. In fact, CoreWAF gives you real data of what your site received after the CDN filter — something the Cloudflare panel doesn't show.

How long does setup take?

Minutes. Sign up, add the domain, paste a single line in your site. No DNS, no migrations, no restarts.

Are there false positives?

Only blocks what you define. There are no aggressive global rules like a stock OWASP CRS. If a legitimate IP or User-Agent gets caught, you whitelist it in one click and it overrides any blacklist.

What if I exceed my plan's hits?

We warn you before the cap and you can upgrade in one click. We never cut service without giving you room.

What happens if CoreWAF stops responding?

Fail-open by design: if the WAF logic fails, your site keeps serving traffic as if it weren't there. Blocking real visitors is worse than not blocking attacks for a minute.

Try it on your domain. Free trial.

No credit card, no commitment. If it doesn't convince you, close the account and that's it.