Aegisify company logo

Which managed-rule attack categories are active in Aegisify WAF 1.20.13, and are managed signatures Pro-gated?

Technical summary

Which managed-rule attack categories are active in Aegisify WAF 1.20.13, and are managed signatures Pro-gated? controls deterministic request inspection and matching for common web-attack techniques, custom rules, managed signatures, and heuristics. This article is grounded in the supplied Aegisify WAF 1.20.13 plugin package. It documents current behavior and defaults rather than relying on older FAQ wording.

Current-version correction

The old “always available” Free/Pro category split is not current WAF 1.20.13 behavior. The supplied managed-signature engine returns without evaluating any managed signatures unless AegisWAF_Pro_Gate::is_active() is true. Therefore SQL injection, XSS, path traversal, RCE, LFI/RFI, SSRF, command injection, NoSQL injection, file-upload, and related managed signature categories should be documented as part of the current Pro-gated managed-rule engine, not as a guaranteed Free subset. Custom rules and other WAF layers have their own separate license/behavior rules.

Where administrators configure or verify it

Primary wp-admin path: wp-admin → Aegisify WAF → WAF Rules / Settings. Exact controls can be distributed across the related tab/page when the feature is composed of multiple engines.

Current 1.20.13 defaults and related controls

The table below lists settings in the supplied current source that are directly related to this topic. The current default/bound/status shown is code-derived. Where the product does not define a named Medium preset, the shipped default is documented as the baseline operating point rather than inventing a value.

Setting Current default / bound / status Why this default How to tune safely
managed_rules.enabled ON / true Enabled in the shipped baseline because the control provides broadly useful visibility, validation, compatibility, or protection without requiring a site-specific value. ON activates the behavior; OFF removes that specific behavior. Use OFF only when the control is intentionally unnecessary, another trusted layer owns the function, or a compatibility investigation proves the control is involved. Re-enable after testing when protection is still required.
managed_rules.mode_pro block Block is the shipped enforcement choice for this specific control, indicating that the current product considers a positive match sufficiently high confidence to stop by default. Where this control exposes Off / Monitor / Block: Off disables its decision path; Monitor records/evaluates without blocking; Block enforces the decision. Start with Monitor for uncertain traffic, then move to Block after reviewing false positives and exceptions.
managed_rules.sensitivity balanced “balanced” is the shipped baseline and is the closest current code-defined baseline/medium operating point. Use stricter behavior only after reviewing site-specific evidence. Treat the shipped value as the baseline/medium operating point. A stricter profile generally increases sensitivity and may increase false positives or workload; a more permissive profile generally reduces intervention but can allow more unwanted activity.
managed_rules.categories.sqli ON / true Enabled in the shipped baseline as the product’s current safe operating choice for this control. ON activates the behavior; OFF removes that specific behavior. Use OFF only when the control is intentionally unnecessary, another trusted layer owns the function, or a compatibility investigation proves the control is involved. Re-enable after testing when protection is still required.
managed_rules.categories.xss ON / true Enabled in the shipped baseline as the product’s current safe operating choice for this control. ON activates the behavior; OFF removes that specific behavior. Use OFF only when the control is intentionally unnecessary, another trusted layer owns the function, or a compatibility investigation proves the control is involved. Re-enable after testing when protection is still required.
managed_rules.categories.rce ON / true Enabled in the shipped baseline as the product’s current safe operating choice for this control. ON activates the behavior; OFF removes that specific behavior. Use OFF only when the control is intentionally unnecessary, another trusted layer owns the function, or a compatibility investigation proves the control is involved. Re-enable after testing when protection is still required.
managed_rules.categories.path_traversal ON / true Enabled in the shipped baseline as the product’s current safe operating choice for this control. ON activates the behavior; OFF removes that specific behavior. Use OFF only when the control is intentionally unnecessary, another trusted layer owns the function, or a compatibility investigation proves the control is involved. Re-enable after testing when protection is still required.
managed_rules.categories.ssrf ON / true Enabled in the shipped baseline as the product’s current safe operating choice for this control. ON activates the behavior; OFF removes that specific behavior. Use OFF only when the control is intentionally unnecessary, another trusted layer owns the function, or a compatibility investigation proves the control is involved. Re-enable after testing when protection is still required.

Adjustment strategy

Change one control at a time, save it through the product UI, reproduce the legitimate and malicious/test flow, and review the product log/status surface. For enforcement controls, use Monitor/Observe first when normal behavior is uncertain; move to Block only after the signal is reliable. For thresholds, do not jump directly from the default to an extreme unless an active incident requires emergency containment and a recovery path exists.

Operational guidance

On a production WordPress site, a sudden block spike after a plugin/API deployment should first be investigated in WAF logs. Narrow the issue to the exact route, rule family, client identity, or payload characteristic. Prefer a precise exclusion/allowlist or threshold adjustment over disabling broad protection.

Technical keywords

Aegisify WAF, 1.20.13, always, available, categories, custom, managed, path, rule, rules, signature, sqli, traversal, xss, managed_rules, enabled

Source baseline

Verified package: Aegisify WAF 1.20.13. Primary source files: includes/class-aegiswaf-storage.php; includes/class-aegiswaf-ai-security.php; includes/class-aegiswaf-api-security.php; includes/class-aegiswaf-managed-rules.php; includes/ddos/class-aegiswaf-ddos-storage.php; includes/admin/pages/class-aegiswaf-page-waf-rules.php; includes/admin/pages/class-aegiswaf-page-logs.php; includes/admin/pages/class-aegiswaf-page-access.php. If a future plugin version changes these settings, support should re-read the installed version rather than carry these defaults forward automatically.

2026-01-12T23:30:46+00:00January 12th, 2026||

Find this article interesting, please share.