Know What Your WAF Is Protecting Before You Ask It to Change
Aegisify WAF 1.20.13 combines local Configuration Scans, encrypted attack-surface inventory, verified WAF backup and restore, guarded recommendations, and optional redacted AI-assisted mapping through Aegisify Core.
Aegisify separates deterministic findings from optional AI analysis, binds recommendations to current evidence, limits one-click changes to low-risk allowlisted controls, verifies writes, and preserves rollback.
From Local Evidence to a Verified WAF Change
Each stage has a separate security boundary. Local scanning works without AI; AI requires explicit approval; automation is restricted; and restoration is validated before durable settings are replaced.
Click a stage to expand
01Back Updurable settings
02Scan Locallyno AI required
03Store Securelyencrypted snapshot
04Analyzeexplicit AI approval
05Apply Safelyallowlisted changes
06Verifyread back + rollback
Evaluate WordPress Posture and WAF Controls Locally First
The Configuration Findings workflow is deterministic. It does not need an AI provider to identify current settings, baseline differences, attack-surface conditions, and controls that deserve review.
The scanner combines current WAF settings with saved WordPress/application evidence, evaluates supported security and operational controls, then organizes them into Risk, Review, and Strength rows with a score and recommended state.
WordPress-side findings cover HTTPS, debug exposure, software updates, inactive code, file-modification policy, Application Passwords, writable paths, REST exposure, AJAX exposure, and other supported signals. The scanner does not silently update third-party software.
Build a Versioned Map of the WordPress Attack Surface
Each scan performs a bounded recollection, stores an encrypted snapshot, and compares it with the previous snapshot.
Runtime & Software Context
Inventory can include WordPress, PHP, database posture, plugin/theme state, scheduled hooks, application metadata, and current WAF coverage.
Routes, AJAX & Public URLs
The scanner can collect bounded metadata for application URLs, REST patterns/methods, AJAX actions, XML-RPC methods, post types, taxonomies, shortcodes, dynamic blocks, and observed APIs.
Added, Changed & Removed
Snapshots include an inventory hash, previous-hash relationship, item counts, and deltas so an administrator can see how the supported attack surface changed between scans rather than treating every assessment as isolated.
Encrypt the Evidence and Verify It After Writing
Aegisify stores inventory and AI-plan data in plugin-owned tables using authenticated encryption and integrity checks instead of treating configuration intelligence as disposable browser state.
Inventory and AI analysis records use AES-256-GCM encryption when available, with keys derived from WordPress authentication salts and purpose context. Inventory is SHA-256 hashed and read back after writing; an unverified row is removed instead of trusted.
The store retains version, scan type, timestamps, creator context, current/previous hashes, item counts, and deltas. Default inventory retention is 20 records, providing controlled history.
Separate Durable WAF Configuration From Runtime Evidence
A configuration backup recovers policy—not logs, temporary attack state, licensing, or inventory history.
Durable WAF Settings
Exports include supported WAF switches, rules, API policies, allowlists, and WAF-owned alert-recipient settings. Aegisify Core credentials, inventory snapshots, AI reports, licenses, logs, counters, and temporary data are excluded.
Check Before Write
Restore validates product identity, schema, version compatibility, package structure, option manifest, allowed option groups, and SHA-256 checksum before writing.
Acknowledge Blocking Changes
If an incoming backup differs from current configuration and contains active block controls, the administrator must explicitly acknowledge that the verified restore can immediately reject traffic.
Rollback Before Change
Aegisify snapshots the prior configuration before restore. If verification fails, it attempts to restore and verify that previous state.
AI Can Recommend. It Does Not Receive Permission to Reconfigure WordPress.
AI review is optional, separately authorized, routed through Aegisify Core, and constrained by local deterministic policy.
Before analysis, Aegisify checks that the saved inventory and live WAF configuration remain consistent. If settings changed, the administrator must scan again, then explicitly approve one redacted AI request.
The planning dossier is minimized and redacted. It can contain finding IDs, setting paths, redacted states, WAF posture, candidate targets, hashes, and required attack-surface context. AI must use supplied targets and defer unsafe changes to manual review.
Only Low-Risk, Allowlisted Changes Get a One-Click Path
The product intentionally makes higher-risk configuration slower and more deliberate.
Scan First. Back Up. Review the Evidence. Then Change.
Make WAF configuration auditable and recoverable instead of experimenting directly against production enforcement.
Common Questions About the Protected Workflow
Does Configuration Scan require AI?
No. Local Configuration Findings and encrypted inventory operate without AI. AI review is optional.
Does the inventory collect WordPress content or passwords?
The supplied 1.20.13 scanner explicitly excludes post content, user records, credentials, tokens, cookies, request bodies, database-row contents, private keys, and source-code contents from its supported inventory collection.
Can AI turn on blocking automatically?
No. The AI planning contract prohibits automatic blocking, authentication requirements, rate limits, DDoS changes, proxy trust, and arbitrary settings. Safe automation remains monitor/log-first and locally validated.
What happens if a restore cannot be verified?
Aegisify saves a rollback snapshot before the restore and attempts to put the previous WAF option snapshot back if the new state cannot be verified.
How can Aegisify AI help?
Ask about Aegisify or WordPress: errors, plugins, security, SEO, compatibility, troubleshooting, comparisons, or launch a free website scan.
