Before WordPress loads

Stop high-confidence threats before the heavy work begins.

Nexus Early WAF is a pre-WordPress protection layer for obvious exploit probes, dangerous paths and encoded request patterns, with visible runtime health and compatibility-minded safeguards.

Pre-WordPress checksIncident IDsFail-open safetyRules integrity
EARLY WAF GATEGATE ACTIVE
Sensitive pathHigh-confidence probe denied
Encoded payloadRule matched before bootstrap
Clean requestNormal WordPress route allowed

Pre-bootstrap protection

Reject qualifying exploit, traversal, sensitive-file and unsafe request patterns before normal WordPress loading.

Runtime integrity

The generated bridge, rules cache and loaded version have explicit health diagnostics.

Explainable response

When Nexus handles the request, the block includes a professional response, incident ID and local evidence.

A lightweight gate

Strict where the evidence is strong. Careful where WordPress needs context.

The early layer focuses on patterns that are highly unlikely to be legitimate. Compatibility-sensitive routes remain narrow exceptions rather than blanket bypasses.

  • Exploit paths, traversal and encoded payload checks
  • Dangerous query and request-method detection
  • Branded 403 response when the request reaches the PHP WAF layer
  • Local outbox for later Threat Network signal delivery
Capability map

Protection before the application stack.

Early WAF reduces wasted work without pretending that every WordPress decision can be made before WordPress exists.

High-confidence request rules

Detect known exploit-style paths, encoded traversal, backdoor probes and dangerous payload structures.

  • Path and query inspection
  • Method restrictions
  • Encoded pattern preservation

Bootstrap health

Verify that the generated firewall bootstrap and rules cache are installed, loaded and synchronized.

  • Loaded-version visibility
  • Refresh controls
  • Clear pending or mismatch states

Incident response

Return an intentional denial page and record the decision when the request reaches the Nexus layer.

  • HTTP 403 response
  • Incident identifiers
  • No-cache and noindex headers

Asynchronous signal sharing

Queue compact high-confidence signals locally and submit them later through the normal WordPress layer.

  • No live external call during the block
  • Bounded local outbox
  • Site-bound network identity
Operational flow

A request meets the perimeter.

The early layer acts before most plugins, themes and database work.

01

Arrive

The web request reaches the PHP protection path before normal WordPress execution.

02

Inspect

Nexus evaluates high-confidence path, query, method and runtime rules.

03

Decide

Narrow compatibility safeguards are applied only when supported by the request context.

04

Respond

The request is allowed or denied, and qualifying evidence is queued for later processing.

What Nexus does

Reject obvious malicious patterns early.

  • Keep early rules high confidence
  • Expose bootstrap and rules health
  • Preserve evidence and incident identifiers
  • Use fail-open behavior when integrity is uncertain
What Nexus avoids

Turn the perimeter into a fragile blacklist.

  • Trust fake WordPress cookie names
  • Wholly bypass logged-in-looking traffic
  • Make synchronous cloud calls during a block
  • Route server-denied files through PHP just for branding
Feature questions

What buyers usually want to know.

Does Early WAF run before all server rules?

No. Nginx, Apache or the hosting platform may reject a request before PHP. Early WAF is the earliest Nexus layer when the request is passed to PHP.

Will it block normal WordPress editors or oEmbed requests?

The rules include narrow compatibility logic for legitimate WordPress routes and clean oEmbed behavior. High-confidence exploit patterns remain blocked.

What happens if the generated bootstrap is not healthy?

Nexus exposes the status and uses fail-open behavior rather than risking a site-wide outage.

Does it contact the Threat Network before allowing a visitor?

No. Early signal delivery is queued locally and drained later through WordPress.

Lumiverse Nexus PRO

Give WordPress a perimeter that exists before WordPress.

Early WAF is optional, testable and included in Nexus PRO.