Interactive dashboard
Requests, blocks and unique IPs in real time, with hourly charts and a breakdown by traffic type.
CoreWAF blocks bots, attacks and junk traffic from inside your own site.
No credit card · Setup in minutes · Cancel anytime
Requests, blocks and unique IPs in real time, with hourly charts and a breakdown by traffic type.
Under active attack, block all traffic in one click except your whitelist. Turn it off when the storm passes.
Classifies every visit: bots, crawlers, scrapers, AIs and search engines. See who comes in and block the rest.
Block by IP, CIDR, User-Agent or URL with exact operators: contains, starts, ends and exact.
Whatever you mark as legit is never blocked, no matter what. One click to unblock.
See where traffic and attacks come from: top IPs, User-Agents, URLs and countries.
You start protected: preset rules against known bots, attacks and abuse, updated daily.
Real people who know the product. We help you set things up and stop attacks when it matters.
No DNS changes · No proxy mode.
Other WAF and CDN providers
Your server remains the sole entry point
Yes. CoreWAF lives inside your site, not at the edge, so they coexist without conflict. In fact, CoreWAF gives you real data of what your site received after the CDN filter — something the Cloudflare panel doesn't show.
Minutes. Sign up, add the domain, paste a single line in your site. No DNS, no migrations, no restarts.
Only blocks what you define. There are no aggressive global rules like a stock OWASP CRS. If a legitimate IP or User-Agent gets caught, you whitelist it in one click and it overrides any blacklist.
We warn you before the cap and you can upgrade in one click. We never cut service without giving you room.
Fail-open by design: if the WAF logic fails, your site keeps serving traffic as if it weren't there. Blocking real visitors is worse than not blocking attacks for a minute.