ModSecurity is a web application firewall. It checks requests to your website and blocks typical attacks such as SQL injection, cross-site scripting or brute-force attempts. In rare cases it also blocks legitimate actions, for example when saving a form or in the admin area of a CMS.
Turn ModSecurity on or off for all domains
- Log in to cPanel.
- In the Security section, click ModSecurity.
- Click Disable at the top to turn ModSecurity off for all domains, or Enable to turn it back on.
For individual domains only
- In the Configure Individual Domains list, find the domain.
- Click Off or On next to it.
Important: We recommend keeping ModSecurity enabled. Only disable it briefly to find out whether an error (for example 403 Forbidden) is caused by ModSecurity, then turn it back on. If the problem keeps occurring, open a support ticket with the affected URL and the time. We will check the triggered rule and adjust it specifically if needed.