Aegisify company logo
Aegisify WAF Decision Metrics2026-08-12T03:08:42+00:00
Aegisify WAF — Overview & Decision Metrics

A WordPress WAF Dashboard Should Explain Pressure, Not Celebrate a Block Count

Aegisify WAF 1.20.13 brings current enforcement, attack families, module pressure, targeted routes, source activity, monitoring health, recent alerts, and service status into one operating view so administrators can decide what needs investigation before changing policy.

A large number is not automatically good security.More blocks can mean more hostile traffic, an overbroad rule, a broken integration, or simply more visitors. Aegisify gives the surrounding evidence needed to tell those situations apart.

1Observe24-hour activity
2Comparemodules + routes
3Decideinvestigate or tune

Decision Flow

Read the Dashboard From Context to Action

The Overview is designed as a triage surface. Open each stage to see what the 1.20.13 dashboard contributes to a decision.

Click a stage to expand

01Posturemode + license
Confirm Free or Pro state, Core-reported license status, module enablement, and whether expected enforcement classes and the log table are available.
02Activity24-hour KPIs
Review alerts, blocks, rate limits, challenges, DDoS actions, errors, and the most recent event instead of treating one action as the entire security picture.
03Pressureweighted signals
Use the dashboard Risk Score and module-pressure visualization as triage indicators. They summarize enforcement pressure; they are not a probability that the site is compromised.
04Targetsroutes + methods
Identify security-event endpoints and HTTP methods receiving attention. A concentrated route may justify a narrow endpoint policy rather than a global rule change.
05SourcesIPs + actions
Compare top sources, block percentages, rate limits, and challenge activity with known integrations, proxies, crawlers, customers, and operational services.
06Evidencealerts + logs
Open representative events in Logs and Attack Story before escalating. The dashboard is the starting point; event evidence explains why a policy fired.
What the Overview Measures

Security Health Is a Set of Signals, Not One Vanity Metric

Aegisify surfaces several 24-hour measures because each tells a different part of the story.

01 — Alert Activity

Alerts and Recent High-Signal Events

Alerts show requests that deserve attention, including blocks, challenges, rate limits, and errors. Recent Alerts exposes time, category, action, source and route so an administrator can move directly from summary to evidence.

02 — Enforcement

Blocks, Challenges, and Rate Limits

Separate action counters show how often Aegisify rejected, challenged, or constrained requests. The hourly sparklines help distinguish a short burst from sustained pressure and make post-change comparisons easier.

03 — Application Health

Errors and DDoS Actions

Critical errors sit beside enforcement metrics because a firewall change that increases failures can be operationally significant even when security blocks are rising. DDoS actions are tracked separately from ordinary WAF enforcement.

04 — Attack Families

Top Security Categories

Category distribution helps identify whether current activity is dominated by managed attack signatures, API behavior, bot activity, DDoS pressure, AI security signals, or Attack Story evidence rather than assuming every event represents the same threat.

How the displayed Risk Score works: the current Overview weights 24-hour errors more heavily than blocks, blocks more heavily than rate limits, and rate limits more heavily than challenges, then caps the result at 100. Treat it as an operational pressure gauge—not a breach score, vulnerability score, or guarantee of compromise.
Eight Visual Decision Views

See What Is Changing Before You Change Enforcement

The 1.20.13 Overview adds eight visualizations designed to answer different operational questions.

Volume & Category

Threat Volume by Module + Attack Categories

Hourly stacked activity separates WAF, API & Application, Abuse & Bots, AI Security, DDoS, and Attack Story. Category distribution shows which event families are driving the period.

Pressure & Targeting

Module Pressure + Security-Event Endpoints

Module pressure weights blocks above rate limits and challenges. The endpoint view ranks routes with security findings or enforcement, helping administrators focus tuning on the application surface actually receiving pressure.

Methods & Sources

Method Mix, Enforcement Trend, IP Risk, Top Offenders

Review HTTP method distribution, hourly action trends, source activity versus block percentage, and high-volume sources by blocks and rate limits. These views are investigation aids, not automated attacker attribution.

Service Status

Know Whether a Control Is Enabled and Whether Its Runtime Is Available

A configuration switch does not help if the expected runtime component or evidence store is unavailable.

The Service Status area checks core WAF posture alongside Abuse & Bots, AI Security, API & Application, DDoS, Managed Rules, WAF Rules, and Logging. Aegisify distinguishes disabled controls from conditions where a supporting class or the log table appears missing or unavailable.

The dashboard also produces practical configuration hints. Examples include Managed Rules being off, API & Application protection being disabled, DDoS being configured to affect logged-in users, or the event table failing its health check. These warnings are more useful than a generic red indicator because they identify the operating condition that deserves review.

Interpretation matters: a healthy green service state means the expected component appears enabled and available. It does not prove that every route is protected, every rule is correctly tuned, or every attack will be stopped.
Decision Discipline

Use Metrics to Narrow the Question

The best dashboard outcome is a smaller, evidence-backed change—not a reflex to make the entire firewall stricter.

01

Find the Change

Compare the last 24 hours with the site’s normal pattern. Look for a new module spike, a new attack family, a route that suddenly dominates, or an enforcement action that changed after a deployment or policy update.

02

Open Representative Evidence

Review recent alerts and logs for the route, method, category, action and source. Check whether the source belongs to an expected service and whether the target is part of login, checkout, API, webhook, crawler or administrative traffic.

03

Apply the Smallest Effective Adjustment

Prefer a narrow endpoint policy, targeted threshold, specific allow entry, or corrected integration over a site-wide relaxation. After the change, return to the Overview and verify that pressure falls without creating new errors or business disruption.

What the Dashboard Does Not Prove

Decision Metrics Need Operational Context

A firewall dashboard summarizes what the application-layer controls observed and did. It does not independently establish attacker identity, business impact, or successful compromise.

Source IPs can belong to proxies, shared networks, crawlers, SaaS platforms or customers. A targeted route can be popular because it is business-critical, not because it is vulnerable. A high block percentage can reflect accurate enforcement or an overly narrow policy. Use the Overview to find the question, then use Logs, Attack Story, application behavior and infrastructure telemetry to answer it.

Operate With Context

Start With Visibility Before Increasing Enforcement

Use Aegisify WAF to establish a traffic baseline, understand the routes and modules generating security evidence, and tune protection from observed behavior rather than assumptions.

Overview FAQ

Common Questions About WAF Decision Metrics

Does a higher dashboard Risk Score mean the site is compromised?

No. The displayed score is a weighted summary of recent errors and enforcement actions. It is useful for prioritizing review, but it is not compromise probability, vulnerability severity, or incident confirmation.

Why not judge the firewall by total blocks?

Because block volume has no meaning without traffic, route, source, category, and operational context. An overbroad rule can increase blocks while making the site less usable.

What should I review after a sudden spike?

Start with the affected module, route, attack family, action trend and source distribution. Then open representative log evidence before changing policy.

Make WAF Data Actionable

See the Pressure. Find the Cause. Tune the Right Control.

Aegisify WAF turns request activity into a decision surface so WordPress teams can protect important routes without treating every event as the same problem.