Hosting Terms
What is WAF?
What WAF really means, with the jargon taken out — plus the example that makes it obvious.
Straight answer first
A WAF reads incoming web requests looking for attack patterns — SQL injection, injected scripts, probes for known exploits — and blocks them before your application runs anything.
The sections below open it up properly — how it works, why a site owner should care, and a concrete example of it doing its job.
Written by the Hosting Seller staff · Checked 1 August 2026
0
Terms left unexplained
100+
Definitions, cross-linked
Real
Examples from real kit
Free
To read, naturally
It matches each request against maintained rule sets that are updated as new vulnerabilities become public. How quickly those rules arrive is the real product you are buying. Server-level WAFs, such as the Imunify360 running on our protected plans, catch requests below the application entirely.
False positives are the tax. Now and again a legitimate submission happens to look like an attack, and the cure is a narrow exception for that rule on that path rather than switching the shield off.
The everyday comparison
A scanner in the goods-in bay, checking parcels against a list of known dangerous contents that gets updated daily. Occasionally it holds a harmless package that happened to look wrong on the screen.
Keep that picture in mind and most of the documentation you will ever read on the subject stops being mysterious.
Why it matters if you run a site
A WAF buys you time and reach. It blocks exploitation of holes you have not patched yet, and it blocks a great many attempts you will never even hear about. Paired with a habit of updating, it covers both halves of the problem.
That is the test for any technical term, incidentally — not 'do I understand it fully' but 'do I know when it is the answer to my problem'. For this one, you now do.
What it looks like day to day
A plugin vulnerability goes public on Monday and the WAF rule sets recognise its exploit pattern by Tuesday. Sites behind it are covered right through the gap, before their owners have even read the news.
Perfectly ordinary once you have seen it, which is rather the point: most hosting concepts are simple machinery wearing an intimidating name.
How this turns up in your own account
You will meet it in the control panel and occasionally in a support conversation, usually already set the right way. If this term made sense, the natural next reads are Firewall, Malware, SQL Injection and Cross-Site Scripting.
Mailboxes on your own domain are part of the plan, never an add-on sold back to you at checkout.

Why we bothered with a hundred definitions
Every confusing term in hosting turns into a support ticket sooner or later, so we defined the hundred most common ones properly, once, in the plain English we would use across the counter.
What you pay on day one is what you pay at renewal, so the year-two invoice holds no surprises worth opening early.
- 100+ terms, all in plain English
- Everyday comparisons and real examples
- Related concepts linked together
- Written by the people on the desk
Why Hosting Seller
On every plan, as standard
Grounded in real kit
Examples point at hosting you would actually use, not at an abstract diagram.
The next reads, mapped
Read on into Firewall and Malware — terms rarely stand alone, so the neighbours are linked.
Plain English first
Every term defined for people who run sites, not for other sysadmins — jargon translated rather than restated.
The stakes spelled out
Not only what it is, but when it turns out to be the answer to a problem you are having.
One term, fully landed
WAF defined, pictured by comparison and placed in your own control panel — recognise-level in a single read.
Honest about what to skip
Most terms are recognise-level rather than operate-level, and the glossary says which is which.
First Steps
From choosing to live
- 1
Find it in your own account
Open the control panel and find where this concept lives — seeing it attached to your own site is what turns a definition into understanding.
- 2
Check what the defaults are
Our platform ships sensible defaults for this — check rather than assume, and you will know your setup instead of hoping about it.
- 3
Follow the terms next door
Concepts travel in packs — Firewall, Malware and SQL Injection finish this one's picture, and each is a two-minute read away.
In the Box
Packed with every plan
- A 99.9% uptime commitment, watched by monitoring day and night
- A backup taken daily, with restores you run yourself
- cPanel, the panel the rest of the trade already knows
- The Softaculous installer for one-click application setup
- Spam and virus filtering fitted to every mailbox
- Site migration done for you by our staff, at no charge
- LiteSpeed caching running at the server, not bolted on by plugin
- PHP versions picked per site from the panel
- DDoS filtering handled out at the network edge
- WordPress Toolkit, with updates applied for you
Across the Counter
The questions we get asked most
Does a WAF mean I can stop updating my site?
No, it bridges the gap rather than closing it. WAF rules recognise known attack patterns; patches remove the vulnerability itself. Each covers the other's blind spot, and running only one of them leaves a failure mode you can name in advance.
The WAF is blocking my contact form — what now?
A targeted exception for that rule on that path puts the form back while leaving the shield up everywhere else. Support can tune it in minutes. Turning the WAF off to fix one form is a trade nobody should take.
Is there a refund if it does not suit?
Yes — thirty days. Put the hosting through real work, and if it is not right, ask for the money back and you get it; there is no retention script to survive first. Domain registrations are the one carve-out, because registries take that fee the moment the name is placed.
Does hosting come with mailboxes?
It does — mailboxes on your own domain ship with every hosting plan, with webmail, IMAP, POP and SMTP access and spam filtering fitted as standard. There is also standalone email hosting for domains whose website lives somewhere else entirely.
Who actually runs the company?
Hosting Seller is a trading name of Bohzo Ltd, a company registered in England and Wales — a real business with a public record and terms published under English law. Looking that up is worth doing about any host before you hand over your domain.
What happens to my files if I leave?
The site and the files stay yours. Pull a full backup from the panel whenever you like, before or during cancellation. Domains remain registered in your name for the term you paid for and can move to any registrar once the standard 60-day window has passed.
Can I bring a domain I already own?
Yes, and transfers in are routine. Unlock the name at your present registrar, collect the auth code, then start the transfer from your client area. Whatever registration time is left comes across with it, and DNS keeps answering the whole way through.
Read next
SQL Injection
SQL injection smuggles database commands in through an input field — turning a search box or a login form i…
Malware
Website malware is hostile code planted on a site somebody has broken into — spam injections, redirects, ph…
Email Hosting
Proper mailboxes on your own domain, at one flat price.
Web Hosting
cPanel hosting on NVMe disks, with SSL, migration and year-one domain included.
Packing up and moving host? Take our checklist.
A plain running order for a move nobody notices: what to copy first, how to carry email across without dropping a single message, when to point DNS, and the two slips behind nearly every hour of downtime we get called about.
Whenever you're ready to order.
From a first website to a rack of servers, moving up is a change to your account rather than a migration.
See the plans