Monitor Important WordPress Application Paths Before You Give the Firewall Permission to Block Them
Aegisify WAF 1.20.13 lets administrators select same-site application URLs, track suspicious managed-rule, custom-rule and heuristic evidence, choose Monitor, Monitor & Alert, or Risk Score Enforcement per target, and control when repeated evidence becomes a notification or block.
Choose the Level of Control Per Application URL
Aegisify preserves the target and its history when monitoring is disabled and keeps notification behavior separate from evidence collection.
Click a mode to expand
01Monitorevidence only
02Monitor & Alertnotify on policy
03Risk Scoreexplicit enforcement
04Methodsexpected verbs
05Recoveryadmin safeguard
06Trusted PathAegisify transport
Monitor Same-Site Application Surfaces With Bounded Configuration
The application monitor is designed for selected WordPress-handled paths, not arbitrary external uptime monitoring.
Targets Stay on the WordPress Site
Inventory URLs are accepted only when their host matches the WordPress home or site host. That keeps App Monitor focused on application surfaces this WordPress WAF can actually inspect.
Exact and Wildcard Paths
Targets use sanitized path patterns with optional * and ? wildcards. Administrators can focus on a specific route or a bounded path family instead of monitoring every request equally.
Up to 200 Application Targets
The implementation bounds application targets at 200 and exposes dashboard windows, top-item controls, rows per page and alert-history limits so operational views remain manageable.
Hits, Alerts, Blocks and Last Decision
The monitoring table records first/last seen, hit, alert and block counts plus the last method, action, rule, risk score, threshold, evidence count, confidence and decision reason for each target.
Blocking Requires More Than “Something Looked Odd”
The default decision policy requires an explicit enforcement switch plus corroborating block-eligible evidence.
Risk Score 10
The default block-score threshold is 10. Administrators can configure it within the bounded decision-policy range rather than relying on a hidden, fixed threshold.
Two Independent Signals
By default, the request also needs at least two independent block-eligible signals. A high score without enough independent evidence is logged as insufficient evidence rather than automatically rejected.
Explicit Custom and Policy Blocks
The default policy allows narrowly explicit custom Block rules and direct policy blocks. Single critical managed signatures are not allowed to bypass the two-signal requirement unless an administrator enables that option.
Managed Rules, Custom Rules, Heuristics and Context Remain Distinct
App Monitor evaluates multiple evidence families and preserves the difference between detection score and block-eligible score.
For a matching application target, Aegisify normalizes the request and evaluates Managed Attack Protection in log mode, custom WAF rules, and Heuristics. The enforcement-decision layer then converts those results into structured signals and evidence. Context such as an unexpected HTTP method can contribute detection context without automatically becoming block-eligible evidence.
This separation matters because a weak signal can be useful for investigation without deserving rejection. The final record includes the resulting score, evidence count, threshold, confidence and reason—such as monitor-only, below threshold, insufficient independent evidence, explicit custom block, critical single signature, or score-and-evidence threshold reached.
Aggregate Repeated Evidence Instead of Emailing Every Event
Notification thresholds and cooldowns are separate from monitoring and enforcement.
The default application alert policy requires either a qualifying direct/block condition, a score of at least 10 with at least two independent evidence families, or three repeated events inside a 300-second aggregation window. The default notification cooldown is 600 seconds per target and signal fingerprint, reducing repeated delivery for the same condition.
Administrators can tune repeated-event minimums, aggregation windows, minimum risk score, minimum evidence, and cooldown. Up to 50 unique valid recipients can be configured. Provider credentials remain in Aegisify Core; the monitoring event log does not store request bodies, cookies, credentials, or recipient addresses as event evidence.
The Alerts dashboard also combines application, REST and AJAX monitoring status, cumulative hits/alerts/blocks, delivery status, recent monitoring events and alert trends. Monitoring remains useful even when notifications are disabled.
Promote a Target From Visibility to Enforcement
Use the three modes as a deployment sequence rather than choosing the strongest setting first.
Add the Route in Monitor
Exercise normal users, integrations, forms, APIs and administrators. Review which rule families fire and whether expected methods and path patterns are correct.
Enable Monitor & Alert
Use aggregation and cooldown controls to confirm that the evidence is meaningful enough to notify responders without producing one-message-per-request noise.
Authorize Risk Score Enforcement
Move only understood targets into enforcement, keep the score/evidence policy conservative, then verify logs, user workflows and error rates after the change.
Keep the Latest Decision State Per Target
The monitor statistics table preserves cumulative hit, alert and block counts plus the most recent score, threshold, evidence count, confidence and decision reason, giving administrators a compact record of how each target is behaving over time.
Observe First. Alert on Evidence. Enforce Deliberately.
Use App Monitor when a WordPress application route deserves tighter attention than the global WAF baseline but still needs controlled change management.
Common Questions
Does adding a target immediately block traffic?
No. New inventory-derived targets are created in Monitor mode. Blocking requires an explicit move to Risk Score Enforcement and a block-authorizing decision.
Can one weak signal block a monitored application by default?
No. The default policy requires score 10 and two independent block-eligible signals. Single critical managed signatures do not bypass that requirement unless the administrator explicitly enables that behavior.
Does turning alerts off stop evidence collection?
No. Application URL alerts and REST/AJAX alerts have independent notification switches. Monitoring and evidence logging can continue when email delivery is off.
How can Aegisify AI help?
Ask about Aegisify or WordPress: errors, plugins, security, SEO, compatibility, troubleshooting, comparisons, or launch a free website scan.
