Skip to main content
.com from $2.99, and WHOIS privacy costs nothing

Hosting Glossary

What is WAF?

What WAF actually means, minus the jargon — with the example that makes it obvious.

The short answer

A WAF inspects web requests for attack patterns — SQL injection, script injection, known exploit probes — and blocks them before your application executes anything.

The sections below unpack it properly — how it works, why a site owner should care, and a concrete example of it in the wild.

Written by the HostingAlly team · Last revised 27 July 2026

0

Jargon left unexplained

100+

Linked definitions

Real

Platform examples

Free

To read, obviously

It works by maintained rule sets matched against each request, updated as new vulnerabilities emerge — the update cadence being the real product. Server-level WAFs (Imunify360 on our protected plans) intercept below the application entirely.

False positives are its tax: occasionally legitimate input matches attack shapes, cured by targeted rule exceptions rather than disabling the shield.

The analogy version

A mailroom scanner reading parcels for known dangerous contents — updated daily on what danger looks like, and occasionally holding a harmless parcel that resembled one.

Hold onto that picture and most of the documentation you'll ever read about it becomes considerably less mysterious.

Why it matters to a site owner

The WAF buys time and coverage — blocking exploitation of vulnerabilities you haven't patched yet and attacks you'll never hear about; paired with update discipline, it closes both halves of the risk.

That's the test for every technical term, incidentally — not 'do I understand it fully' but 'do I know when it's the answer to my problem'. For this one, now you do.

What it looks like in practice

A plugin vulnerability is disclosed on Monday; the WAF rules recognise its exploit pattern by Tuesday — sites behind it are shielded through the window before their owners even read the news.

Ordinary, once seen — which is the point: most hosting concepts are simple machinery wearing intimidating names.

How this shows up in your hosting

You'll meet it in the control panel and occasionally in a support conversation — usually already configured the right way. If this term made sense, the natural next reads are Firewall, Malware, SQL Injection and Cross-Site Scripting.

Business email on your own domain is included, not sold back as an add-on.

A shield icon standing for DDoS protection and site security

Why we wrote a hundred definitions

Every confusing term in hosting eventually becomes a support ticket — so we defined the hundred most common ones properly, once, in the plain English we'd use on the phone.

Renewal prices match signup prices, so the year-two invoice is the most boring email you'll get from us.

  • 100+ terms, plain English
  • Analogies and real examples
  • Cross-linked related concepts
  • Written by the support desk

Why HostingAlly

Every plan includes this, whatever you pay

Grounded in a real platform

Examples reference the hosting you'd actually use, not abstract diagrams.

The next reads, mapped

This entry connects to Firewall and Malware — concepts travel in packs, and the pack is linked.

Plain English first

Every term defined for site owners, not for other sysadmins — jargon translated, not restated.

The practical stakes named

Not just what it is — when it's the answer to a problem you're having.

One term, fully landed

WAF defined, pictured by analogy and placed in your own control panel — recognise-level in a single read.

Honest about what you can skip

Most terms are recognise-level, not operate-level — the glossary says which is which.

Getting Started

How to get going

  1. 1

    Spot it in your own setup

    Open your control panel and find where this concept lives — seeing it attached to your own site is what converts definition into understanding.

  2. 2

    Check the defaults

    Our platform ships sane defaults for this — verify rather than assume, and you'll know your setup instead of hoping about it.

  3. 3

    Follow the related terms

    Concepts travel in packs — Firewall, Malware and SQL Injection complete this one's picture, and each is a two-minute read away.

Included

What's covered on our plans

  • 99.9% uptime commitment, monitored around the clock
  • Daily automatic backups with self-service restores
  • cPanel — the industry-standard control panel
  • Softaculous one-click app installer
  • Spam and virus filtering on every mailbox
  • Free website migration handled by our team
  • LiteSpeed server-level caching
  • Per-site PHP version selection
  • DDoS protection at the network level
  • WordPress Toolkit with automatic updates

FAQ

Your questions, answered

Does a WAF replace updating my site?

It bridges, not replaces — WAF rules cover known patterns while patches remove the vulnerabilities themselves. The pair covers each other's gaps; either alone leaves a known failure mode open.

My form gets blocked by the WAF — now what?

A targeted exception — that rule, that path — restores the form while keeping the shield. Support tunes it in minutes; disabling the WAF to fix a form is the wrong trade by orders of magnitude.

Is there a money-back guarantee?

Yes — try the hosting properly and if it doesn't fit, the refund process is a request, not a retention gauntlet. Domain registrations are the one standard carve-out, since registries make those non-refundable the moment they're placed.

Do you include email with hosting?

Yes — mailboxes on your own domain come with every hosting plan, with webmail, IMAP/POP/SMTP access and spam filtering. Standalone email hosting also exists for domains whose websites live elsewhere.

Where is your company based?

HostingAlly is a trading name of Fairdeal Renovations Limited, a company registered in England and Wales — a real, verifiable business with published terms under English law, which is worth checking about any host before you hand them your domain.

What happens to my data if I cancel?

Your site and files remain yours — download a full backup from the panel any time, before or during cancellation. Domains stay registered to you for their paid term and can transfer to any registrar after the standard 60-day window.

Can I transfer a domain I already own?

Yes — transfers in are routine: unlock the domain at the current registrar, grab the auth code, and start the transfer from your client area. The remaining registration time carries over, and DNS keeps working throughout.

Planning to switch hosts? Grab the checklist here.

The steps that keep a site migration dull rather than dramatic: what to back up first, how to shift email across without losing a single message, when to touch DNS, and the two mistakes behind nearly every hour of downtime we come across.

One email carrying the checklist, plus the odd bit of hosting advice. Unsubscribe whenever you want: see our privacy policy.

Ready when you are.

From your first site to a fleet of servers, the upgrade path is an account change, not a migration.

View Email Hosting plans