Special OfferSave up to 35% on multi-year hosting plans + Free AutoSSL & Domain setup!
Get Started
GuideSSL & Security

Managing ModSecurity Web Application Firewall (WAF) and IP Blocker in cPanel

How Hostinov enterprise WAF shields websites from SQL injection, XSS, and bot scanners, and how to block abusive IP addresses.

Hostinov Engineering TeamUpdated: 2026-09-133 min read7,400 views330 found helpful
Tags:#SSL & Security#Hosting#Cloud

ModSecurity WAF Protection#

ModSecurity inspects incoming HTTP/HTTPS traffic at the web server layer to block SQL injections, cross-site scripting (XSS), and malicious scanning bots before they reach your PHP scripts.


Using cPanel IP Blocker#

To block an abusive IP address or subnet:

  1. 1
    In cPanel, go to Security -> IP Blocker.
  2. 2
    Enter the IP (e.g. 198.51.100.4) or CIDR range and click Add.

Was this article helpful to you?

Your feedback helps our sysadmins keep technical guides accurate.

24/7 Priority Support

Need a sysadmin to configure this for you?

Our tier-3 systems architects are available 24/7 to assist with migration, DNS records, or SSL issues.