What security protections does Faaaster offer?
The site's Security tab groups its protections into cards: Server security (Nginx hardening, read only), Bot protection, Application firewall, Custom rules (IP rules and HTTP rules), then Integrity check and Vulnerabilities. The cards displayed depend on your site and on the environment you have open. With the Viewer role, you can view the tab but its settings are grayed out.
Contents
- Nginx Hardening
- CrowdSec, global IP and AppSec protection
- Read only
- Site IP rules
- HTTP rules
- Integrity check
- "Under Attack" protection
Nginx Hardening
Server security card. According to the interface: "Nginx Hardening will automatically harden your Nginx configuration to secure your website." In particular, it blocks xmlrpc, .htaccess files and .git files.
Only turn this protection off if you know what you're doing.

CrowdSec, global IP and AppSec protection
On some sites, the Server security card shows the Crowdsec Security row: "Enable Crowdsec protection to protect your website against malicious traffic and attacks."
On the others, this row doesn't exist; instead, the production environment shows two cards:
- Bot protection, Global IP protection row โ "Challenges IP addresses flagged by Faaaster's protections and shared reputation sources.";
- Application firewall, AppSec row โ "Analyzes HTTP requests and challenges detected exploit attempts."
Read only
"Lock the files for writing to prevent any modification of the code. The /wp-content/uploads directory will remain open for writes."
Useful for freezing a site in production: no plugin or update can modify the code anymore.
Site IP rules
Custom rules card, Site IP rules row: "Challenges suspicious IPs and allows trusted IPs for this site. A bypass skips IP protections, AppSec and HTTP rules, except for a manual block by the platform."
The Manage IPs button opens the Site IP blocking and bypass window, where each address gets the Challenge or Allow (full bypass) action. The row's switch turns these rules on or suspends them.

HTTP rules
Same card, HTTP rules row: "Protection rules applied at the origin (challenge, block, stop the rule chain)." The Manage rules button opens the Custom HTTP rules window.
Integrity check
The Check integrity button runs a check of the site's files against the official WordPress versions. The Vulnerabilities section lists the vulnerabilities detected.
๐ How do I read the integrity check?
"Under Attack" protection
Bot protection card, on the production environment: this protection challenges visitors when your site is under attack. In Automatic mode, the recommended setting, it kicks in and eases off on its own. Its modes and how it works are covered in a dedicated article.
๐ How does "Under Attack" protection work?
๐ How do I change my site's PHP version? ยท My site is slow
Updated on: 10/03/2026
Thank you!
