KakapoWPKakapoWP
Log inTry for free
Kakapo Security

Bad request filter

Why should your site answer ../?

The filter looks at requests before WordPress processes them. Classic attack patterns such as SQL injection, XSS, ../ and php:// are rejected. Logged-in administrators are exempt, so the filter does not get in your way while you work.

Bad request filter

Blocks SQL injection patterns · Detects XSS, ../ and php://

ActiveSettings

What the bad request filter offers

Blocks SQL injection patterns
Detects XSS, ../ and php://
Scanner bots can be turned away with 403
Logged-in admins are excluded

Here's how it works

1

A request comes in

2

Pattern check ahead of WordPress

3

A hit is rejected

FAQ about the bad request filter

Which patterns does the filter detect?
Classic attack patterns: SQL injection, XSS, path traversal with ../ and php:// wrappers. If a request matches, it is rejected before WordPress answers it.
Does the filter block me too?
Logged-in administrators are exempt. So a post with conspicuous code in the editor stays possible.
What about sqlmap or nikto?
Known scanners such as sqlmap, nikto or nmap can additionally be turned away with 403. You switch that on separately from the pattern filter.

More security features

Ready?

Try Security free for 24 hours.

No credit card, no risk. Up and running in 2 minutes.

Try it for free now