Skip to main content
HostingSeller
Shop plans

Trade Terms

The WAF Is Free. The False Positive Is the Part That Costs You

The rule set protects client sites whose plugin lists you have never seen — right up until it holds a legitimate enquiry and the client rings you about it.

Straight answer first

A WAF inspects the content of web requests and refuses the ones matching known attack patterns, which for a reseller means it defends dozens of client sites whose plugin lists you do not control and cannot audit. It is the highest-leverage protection available on a client book you did not build.

It also produces the only security ticket you will get regularly. Every so often a legitimate submission looks like an injection attempt, the form stops working, and the correct response is a narrow exception on that rule and that path — never switching the shield off for the whole account.

Written by the Hosting Seller staff · Checked 4 August 2026

0

Questions we do not duck

100+

Entries, cross-linked

Real

Kit named as it ships

Free

To read, and to quote from

The product you are really buying is the update cadence. Rule sets track newly published vulnerabilities, and the gap between disclosure and rule is the window in which your least-maintained client is exposed. Server-level protection catches those requests below the application, which matters when the vulnerable thing is a plugin nobody has touched since launch day.

For a reseller the arithmetic is simple. You cannot patch forty client sites on Monday morning, and you cannot make forty clients approve an update. A WAF covers the interval between a flaw becoming public and a client agreeing to pay for maintenance.

The one security ticket you will get regularly

It arrives as 'our contact form has stopped working' and almost never as 'we have been attacked'. Somebody pasted a block of text containing an apostrophe and a stray SQL-shaped fragment, the rule fired, and the submission died behind a generic error the client cannot interpret.

Handle it as a reseller rather than as a sysadmin: reproduce it yourself first, capture the exact submission that fails, then escalate with that payload attached. A support desk can tune a specific rule on a specific path in minutes when it has the evidence, and in hours when it has only a description.

What it is worth to your package price

This is one of the few security features that genuinely differentiates a hosting package, because the client can follow the promise: attacks against known holes are stopped before the site runs any code. It also removes unbilled labour from your week, which is the sort of margin that never appears on an invoice.

Resist selling it as a guarantee. A WAF narrows the window; it does not close it. Wording that promises protection rather than immunity is the wording you can still stand behind after an incident.

Tuning it without switching it off

The temptation, when a client is shouting, is to disable protection across the whole account and move on. That trade sells a permanent risk to buy ten minutes, and it is the worst habit in reseller support. One rule, one path, one exception — documented against that client account so the next person to look does not have to wonder why.

Keep a note per client of every exception you have requested. When the same site produces its third, you are no longer looking at a false positive; you are looking at a plugin that needs replacing, and that conversation is billable.

What you can safely put in writing

In a proposal: 'Every site we host is screened by a web application firewall, with rules updated as new vulnerabilities are published.' Specific, true, and it names nobody. In a maintenance retainer, state plainly that screening is not a substitute for updates, and that unpatched components remain the client's exposure unless they buy the maintenance line.

That second sentence is the one that protects the relationship. It is also the one that sells maintenance, because it makes the choice explicit instead of leaving the client to assume you absorbed the risk for free.

A shield icon standing in for site security and DDoS filtering

A trade file, not a beginner's guide

Written for people who resell hosting: what a term means, what it does to the support queue, and how to word it for a client who is not going to read your second paragraph.

Reseller tiers carry a 7-day money-back window and nothing to pay at setup, so testing whether the business idea holds costs you a week rather than a year.

  • Terms defined for people who resell, not for first-timers
  • The failure mode named before it reaches you
  • Wording you can lift straight into a proposal
  • Cross-linked so one lookup answers the next

Why Hosting Seller

On every plan, as standard

Cover for sites you did not build

Rule-based screening protects the client whose plugin list you have never seen and whose updates nobody is paying you to run.

The false positive, handled properly

Reproduce, capture the payload, escalate with evidence. Minutes rather than hours, and no protection switched off to buy peace.

A feature clients understand

Attack screening is one of the few security lines that survives contact with a non-technical buyer without turning into jargon.

Wording that survives an incident

Protection, not immunity. The distinction reads as pedantry today and as the reason you kept the client after something goes wrong.

A route into billable maintenance

The third exception on one site is not a false positive. It is a plugin conversation, and that conversation has an invoice attached.

Layer discipline

Connection filtering and request screening do different jobs at different heights, and a reseller who confuses them promises the wrong thing.

First Steps

From choosing to live

  1. 1

    Reproduce it before you escalate

    Submit the failing form yourself and capture the exact input. A payload in the ticket turns a two-day thread into a ten-minute fix.

  2. 2

    Ask for one exception, not an exemption

    Narrow it to the rule and the path. Blanket exclusions get forgotten, and forgotten exclusions become the incident nobody can explain.

  3. 3

    Log it against the client

    Keep the exception history per account. It turns a vague sense that a site is trouble into evidence you can bill against.

In the Box

Packed with every plan

  • Imunify360 standing over every client site
  • Free SSL on every client site, reissued before it lapses
  • Daily backups taken across every client account
  • WHM for you, and a cPanel of their own for every client
  • Packages you build, name and price yourself
  • A 7-day money-back window on reseller plans
  • Nothing charged at setup on any reseller tier
  • Softaculous inside every account you create
  • Real people answering, for you and for your clients
  • cPanel, the panel the rest of the trade already knows

Across the Counter

Things people ask us all the time

A client's form is being blocked and they want protection turned off — how do I refuse without losing them?

Do not frame it as a refusal. Tell them the form will be working shortly and that you are fixing the rule rather than removing the guard, because removing it exposes every other page on their site. Then actually fix it quickly. Clients accept a narrow technical answer delivered fast far more readily than a broad one delivered slowly.

Can I charge for a WAF as an add-on, or should it be included?

Include it. Screening applies at the server across the accounts you create, so carving it out as a paid extra means advertising that some of your clients are deliberately less protected — a sentence you never want a prospect to read. Charge for maintenance instead, which is genuinely per-client work and genuinely optional.

Does having a WAF let me stop chasing clients about plugin updates?

No, and treating it that way is how resellers end up cleaning sites for free. Screening blocks known attack shapes; updates remove the flaw. Keep chasing, and put the chasing on an invoice — the WAF simply buys you time to have that conversation instead of an emergency.

One client site produces false positives constantly. Is that a hosting problem?

It is a component problem wearing a hosting costume. A site that repeatedly submits input shaped like an attack usually contains a form builder or import tool doing something careless. Document the exceptions, show the client the list, and quote for replacing the component. That is the point where a nuisance turns into work you are paid for.

Read next

Moving your site to another host? Start with this checklist.

A step-by-step order of work for a move your visitors never spot: which files to copy first, how to carry email across without losing one message, the right moment to repoint DNS, and the two mistakes behind nearly every hour of downtime people ring us about.

One email brings the checklist, then now and again a note about running a site properly. Leave the list whenever you feel like it. Our privacy policy spells out the rest.

Sell it as yours.

Reseller tiers with room for up to 500 cPanel accounts, free SSL on every client site, and a 7-day money-back window while you test the idea.

See Plesk Reseller Hosting plans