Technical summary
How should Sensitivity mode: balanced / strict (signature pack selection) be configured in Aegisify WAF, and what is the current default? is part of the WAF request-inspection, enforcement, visibility, or exception-management surface. This article is grounded in the supplied Aegisify WAF 1.20.13 plugin package. It documents current behavior and defaults rather than relying on older FAQ wording.
Where administrators configure or verify it
Primary wp-admin path: wp-admin → Aegisify WAF → WAF Rules / Settings. Exact controls can be distributed across the related tab/page when the feature is composed of multiple engines.
Current 1.20.13 defaults and related controls
The table below lists settings in the supplied current source that are directly related to this topic. The current default/bound/status shown is code-derived. Where the product does not define a named Medium preset, the shipped default is documented as the baseline operating point rather than inventing a value.
| Setting | Current default / bound / status | Why this default | How to tune safely |
|---|---|---|---|
ai_security.mode |
monitor | “monitor” is the shipped baseline so administrators can collect evidence and verify normal traffic or behavior before moving to stronger enforcement where applicable. | Where this control exposes Off / Monitor / Block: Off disables its decision path; Monitor records/evaluates without blocking; Block enforces the decision. Start with Monitor for uncertain traffic, then move to Block after reviewing false positives and exceptions. |
app_monitoring.mode_schema_version |
2 | The shipped value of 2 is the exact current default encoded by the plugin and should be treated as the baseline unless site evidence supports a change. | Treat this numeric value as the shipped baseline. Adjust one step at a time, document the reason, and verify the operational effect before making the setting more extreme. |
ddos.emergency_mode |
OFF / false | Disabled in the shipped baseline because enabling it can change live request handling, indexing behavior, automation, enforcement, or integration traffic and should be reviewed for the specific site first. | OFF leaves the behavior inactive. Turn it ON only after checking prerequisites and expected traffic/content because this setting can introduce enforcement, automation, indexing, outbound integration, or additional processing depending on the feature. |
managed_rules.mode_free |
block | Block is the shipped enforcement choice for this specific control, indicating that the current product considers a positive match sufficiently high confidence to stop by default. | Where this control exposes Off / Monitor / Block: Off disables its decision path; Monitor records/evaluates without blocking; Block enforces the decision. Start with Monitor for uncertain traffic, then move to Block after reviewing false positives and exceptions. |
managed_rules.mode_pro |
block | Block is the shipped enforcement choice for this specific control, indicating that the current product considers a positive match sufficiently high confidence to stop by default. | Where this control exposes Off / Monitor / Block: Off disables its decision path; Monitor records/evaluates without blocking; Block enforces the decision. Start with Monitor for uncertain traffic, then move to Block after reviewing false positives and exceptions. |
managed_rules.sensitivity |
balanced | “balanced” is the shipped baseline and is the closest current code-defined baseline/medium operating point. Use stricter behavior only after reviewing site-specific evidence. | Treat the shipped value as the baseline/medium operating point. A stricter profile generally increases sensitivity and may increase false positives or workload; a more permissive profile generally reduces intervention but can allow more unwanted activity. |
waf.mode |
observe | “observe” is the shipped baseline so administrators can collect evidence and verify normal traffic or behavior before moving to stronger enforcement where applicable. | Use the shipped observation mode while establishing a baseline. Move toward enforcement only when logs show the signal is reliable. Returning to monitor/observe is preferable to disabling a control entirely during false-positive tuning. |
ai_security.audit.include_provider_model |
ON / true | Enabled in the shipped baseline because the control provides broadly useful visibility, validation, compatibility, or protection without requiring a site-specific value. | ON activates the behavior; OFF removes that specific behavior. Use OFF only when the control is intentionally unnecessary, another trusted layer owns the function, or a compatibility investigation proves the control is involved. Re-enable after testing when protection is still required. |
Adjustment strategy
Change one control at a time, save it through the product UI, reproduce the legitimate and malicious/test flow, and review the product log/status surface. For enforcement controls, use Monitor/Observe first when normal behavior is uncertain; move to Block only after the signal is reliable. For thresholds, do not jump directly from the default to an extreme unless an active incident requires emergency containment and a recovery path exists.
Operational guidance
Use the feature’s logs and current request evidence as the tuning source. Compare normal traffic with the event that triggered the control, then change only the smallest setting required.
Technical keywords
Aegisify WAF, 1.20.13, balanced, mode, pack, selection, sensitivity, signature, strict, ai_security, app_monitoring, mode_schema_version, ddos, emergency_mode, managed_rules, mode_free
Source baseline
Verified package: Aegisify WAF 1.20.13. Primary source files: includes/class-aegiswaf-storage.php; includes/class-aegiswaf-ai-security.php; includes/class-aegiswaf-api-security.php; includes/class-aegiswaf-managed-rules.php; includes/ddos/class-aegiswaf-ddos-storage.php; includes/admin/pages/class-aegiswaf-page-waf-rules.php; includes/admin/pages/class-aegiswaf-page-logs.php; includes/admin/pages/class-aegiswaf-page-access.php. If a future plugin version changes these settings, support should re-read the installed version rather than carry these defaults forward automatically.
