Hosting Glossary
WAF (Web Application Firewall)
What WAF actually means, minus the jargon — with the example that makes it obvious.
The short answer
A WAF inspects web requests for attack patterns — SQL injection, script injection, known exploit probes — and blocks them before your application executes anything.
The sections below unpack it properly — how it works, why a site owner should care, and a concrete example of it in the wild.
0
Jargon left unexplained
100+
Linked definitions
Real
Platform examples
Free
To read, obviously
It works by maintained rule sets matched against each request, updated as new vulnerabilities emerge — the update cadence being the real product. Server-level WAFs (Imunify360 on our protected plans) intercept below the application entirely.
False positives are its tax: occasionally legitimate input matches attack shapes, cured by targeted rule exceptions rather than disabling the shield.
The analogy version
A mailroom scanner reading parcels for known dangerous contents — updated daily on what danger looks like, and occasionally holding a harmless parcel that resembled one.
Hold onto that picture and most of the documentation you'll ever read about it becomes considerably less mysterious.
Why it matters to a site owner
The WAF buys time and coverage — blocking exploitation of vulnerabilities you haven't patched yet and attacks you'll never hear about; paired with update discipline, it closes both halves of the risk.
That's the test for every technical term, incidentally — not 'do I understand it fully' but 'do I know when it's the answer to my problem'. For this one, now you do.
What it looks like in practice
A plugin vulnerability is disclosed on Monday; the WAF rules recognise its exploit pattern by Tuesday — sites behind it are shielded through the window before their owners even read the news.
Ordinary, once seen — which is the point: most hosting concepts are simple machinery wearing intimidating names.
How this shows up in your hosting
You'll meet it in the control panel and occasionally in a support conversation — usually already configured the right way. If this term made sense, the natural next reads are Firewall, Malware, SQL Injection and Cross-Site Scripting.
Business email on your own domain is included, not sold back as an add-on.

Why we wrote a hundred definitions
Every confusing term in hosting eventually becomes a support ticket — so we defined the hundred most common ones properly, once, in the plain English we'd use on the phone.
Renewal prices match signup prices, so the year-two invoice is the most boring email you'll get from us.
- 100+ terms, plain English
- Analogies and real examples
- Cross-linked related concepts
- Written by the support desk
Why HostingAlly
What you get with every plan
Linked, not siloed
Related terms cross-reference, so one lookup becomes a working understanding.
Honest about what you can skip
Most terms are recognise-level, not operate-level — the glossary says which is which.
Plain English first
Every term defined for site owners, not for other sysadmins — jargon translated, not restated.
The practical stakes named
Not just what it is — when it's the answer to a problem you're having.
Grounded in a real platform
Examples reference the hosting you'd actually use, not abstract diagrams.
Analogies that stick
Each concept gets a picture you'll remember at the moment you actually need it.
Getting Started
How to get going
- 1
Spot it in your own setup
Open your control panel and find where this concept lives — seeing it attached to your own site is what converts definition into understanding.
- 2
Check the defaults
Our platform ships sane defaults for this — verify rather than assume, and you'll know your setup instead of hoping about it.
- 3
Follow the related terms
Concepts travel in packs — Firewall, Malware and SQL Injection complete this one's picture, and each is a two-minute read away.
Included
What's covered on our plans
- Email accounts on your own domain
- LiteSpeed server-level caching
- Renewal prices that match signup prices
- No setup fees, ever
- cPanel — the industry-standard control panel
- Free SSL certificate on every plan, renewed automatically
- NVMe SSD storage as standard
- Free domain for the first year on annual plans
- 99.9% uptime commitment, monitored around the clock
- Per-site PHP version selection
FAQ
Your questions, answered
Does a WAF replace updating my site?
It bridges, not replaces — WAF rules cover known patterns while patches remove the vulnerabilities themselves. The pair covers each other's gaps; either alone leaves a known failure mode open.
My form gets blocked by the WAF — now what?
A targeted exception — that rule, that path — restores the form while keeping the shield. Support tunes it in minutes; disabling the WAF to fix a form is the wrong trade by orders of magnitude.
Do prices go up at renewal?
No — the price you sign up at is the price you renew at. We don't run teaser-rate economics, so there's no year-two ambush to plan around, and your bookkeeping can rely on the number staying put.
Are backups included, and can I restore them myself?
Daily automatic backups are standard, restorable from the panel in minutes — files, databases or both, at 3am without a ticket if that's when you need it. For extra cover, you're welcome to run your own offsite copies alongside.
Is there a money-back guarantee?
Yes — try the hosting properly and if it doesn't fit, the refund process is a request, not a retention gauntlet. Domain registrations are the one standard carve-out, since registries make those non-refundable the moment they're placed.
Where is your company based?
HostingAlly is a trading name of Bohzo Ltd, a company registered in England and Wales — a real, verifiable business with published terms under English law, which is worth checking about any host before you hand them your domain.
Which control panel do you provide?
cPanel — the industry standard, which means every tutorial on the internet matches your screen, your backups restore anywhere cPanel runs, and skills learned here transfer for life. Plesk and DirectAdmin options exist on specific plans for those who prefer them.
Keep exploring
SQL Injection
SQL injection smuggles database commands through input fields — turning a search box or login form into a c…
Cross-Site Scripting (XSS)
XSS plants attacker-controlled script into pages other visitors view — hijacking sessions, defacing content…
VPS Hosting
KVM virtual servers with root access, DDoS protection and flat pricing.
WordPress Hosting
Managed WordPress with LiteSpeed caching, staging and automatic backups.
Ready when you are.
Fast NVMe hosting, free SSL and migration, and real people on support around the clock — at prices that stay put.
See Hosting Plans