Managed WAF for Drupal without a module
Campus and agency teams rarely lose sleep over one polished main Drupal site. They lose sleep over the estate: college sites, research labs, alumni portals, agency microsites — mixed hosts, mixed contrib, uneven patch windows. ProtectMyWebsite is a managed WAF for Drupal without a module: one DNS change (or we handle DNS), rules at the edge, Drupal and editors unchanged. Short product page: /waf-for/drupal. This guide goes deeper — why a security module is the wrong edge layer, how Drupal edge WAF for campuses covers multi-site estates, how a Drupal virtual patch WAF buys time on contrib XSS weeks, and how count → promote (Promote Copilot explains; it does not auto-block) protects Webforms without day-one denies.
Edge WAF vs Drupal security modules
A Drupal security module runs inside the application. The request has already reached PHP and often the same process that serves editors and forms. That can help with hardening — but it is not stopping exploit noise before origin.
An edge-managed WAF sits in front: (1) Login floods, Form API abuse, contrib exploit probes, and XSS-class noise hit the shield first. (2) Origin sees less junk CPU and fewer mysterious admin lockouts. (3) No Drupal module to conflict with custom themes, Layout Builder, or a vendor-managed train. (4) No extra PHP hooks on every anonymous hit or Webform POST.
The pitch is not “delete every hardening module forever.” It is: stop treating an in-app module as your edge. Managed path: DNS → observe → promote — not another Composer package every departmental site must keep updated.
Why campus and agency Drupal is the hard case
Contrib lag is structural. A lab site on an old menu, media, or Webform module is a staffing gap. Virtual-patching at the edge buys time while the owning team ships the update.
Editors are not WAF operators. Faculty and agency staff paste HTML, upload PDFs, and save Layout Builder drafts. Deny-on-day-one packs punish them.
Auth and SSO paths are shared. /user/login and IdP callbacks attract credential stuffing a single departmental host cannot absorb alone.
Inventory is incomplete. Forgotten event, FOIA, and benefits forms still accept POSTs.
That is why higher education, government, and Drupal are the same operator problem: many sites, one thin team, zero appetite for false positives on institutional forms.
Drupal virtual patch WAF — Monster Menus XSS and contrib lag
In September 2026, Drupal published SA-CONTRIB-2026-116 for Monster Menus: stored XSS when HTML in page names isn’t sanitized in the tree browser (CVE-2026-81201; fixed in monster_menus 9.5.3). Not remote anonymous RCE — but on a campus estate that’s still session theft and admin phishing territory.
Operator checklist: /blog/waf-watch-2026-09-08. Durable lessons: Path-only rules are not enough. Count before block. Virtual patch buys time; it does not replace the update. Link /guides/virtual-patching-websites, /guides/waf-count-mode, /guides/whats-safe-to-block.
Multi-site Drupal estate protection — forms that must keep working
Multi-site Drupal estate protection means main site, departmental CMS, and agency microsites share one operator story — not one deny-first rule pack. Forms that must work: admissions, FOIA and benefits intake, event RSVPs, donations, ticket uploads.
Abuse looks like credential stuffing on /user/login, scripted Webform POSTs, malicious uploads, and probe strings in long registration bodies. Count-first: (1) rules start in count (2) ~24 hours real traffic (3) dashboard shows what’s safe — one click (4) Promote Copilot recommends Promote/Hold/Needs allowlist — does not auto-block. Link /guides/waf-false-positives-forms.
How ProtectMyWebsite runs Drupal protection
Pricing: $150/site/month, 14-day trial. Larger estates: Talk to sales — no Estate dollar amounts.
Keep origin IPs off the public internet.
| Step | What happens |
|---|---|
| Onboard | One DNS change or concierge DNS; no security module. |
| Observe | managed rules all start in count. |
| Promote | after ~24h Copilot explains; human promotes. |
| Operate | no Drupal module to update inside CMS. |
FAQ
What is a managed WAF for Drupal without a module? An edge web application firewall in front of your Drupal site that you do not install as a Drupal module. ProtectMyWebsite sits on DNS; Drupal, themes, and hosting stay as they are. Rules start in count; you promote what’s safe to block.
How does a Drupal edge WAF help campuses with multi-site estates? Campus Drupal is often dozens of properties with uneven contrib discipline. A Drupal edge WAF for campuses shields main and departmental hosts, virtual-patches while owners catch up, and uses count → promote so admissions forms are not day-one casualties. See higher education and government.
Can I virtual-patch Drupal before every contrib update lands? Yes — that is why operators use a Drupal virtual patch WAF during weeks like Monster Menus XSS (SA-CONTRIB-2026-116). Deploy content-aware rules in count, promote when hits look like abuse, and still schedule the Composer update. Virtual patch buys time; it does not replace patching.
Will a managed WAF break Drupal Webforms or Layout Builder? It can, if you block-first. ProtectMyWebsite starts rules in count, surfaces promote candidates after ~24 hours, and Promote Copilot flags Hold or Needs allowlist when hits look like editors or legitimate POSTs. You promote when evidence says it is safe.
Does Promote Copilot auto-block Drupal traffic? No. Copilot explains Promote / Hold / Needs allowlist from count-window evidence. The human still clicks. If AI is unavailable, the non-AI suggest UI remains.
Start here
ProtectMyWebsite is the managed WAF for Drupal operators who need edge protection without a module — and a clear answer to what’s safe to block on the next contrib XSS week.
Related
- All guides
- A managed WAF for your Drupal site
- Virtual patching websites with a managed WAF
- WAF Watch: Magento zero-day, school-year outages, and Drupal XSS
- What is WAF count mode? (and why you start there)
- What's safe to block on a WAF?
- WAF false positives on forms: stop blocking legitimate POSTs
- Managed WAF for university and college websites
- Managed WAF for government and public-sector websites
- Solutions & guides
- Free security scan
- Start a 14-day trial
- Pricing