Skip to content
WP Cloud
WP Cloud
    • For Hosts
    • For Agencies
    • For Registrars
    • For Native Hosting
    • Performance
    • Security
    • Real-Time Automated Failover
    • Vertical Scaling and Bursting
    • WordPress Management
    • PanelAlpha Integration: White-Label WordPress Control Panel for Hosts
    • EasyEngine Panel Integration: Visual WordPress Management for WP Cloud
    • FAQs
    • WP Cloud API
    • Partner Portal
    • Documentation
    • New Partner Guide
    • Pressable
    • Convesio
    • Porkbun
    • PanelAlpha
    • Ivapix
    • UNC Greensboro
    • Impressive Hosting
    • Blog
    • Performance Benchmarks
  • Connect With Us
  • Login ↗
Start Here ↗
  • Solutions

    • For Hosts
    • For Agencies
    • For Registrars
    • For Native Hosting
    • Featured Partners

    Features

    • Performance
    • Security
    • Real-Time Automated Failover
    • Vertical Scaling and Bursting
    • WordPress Management

    Integrations

    • PanelAlpha Integration
    • Easy Engine Panel Integration

    Resources

    • FAQs
    • WP Cloud API
    • Partner Portal
    • Documentation
    • New Partner Guide
  • Case Studies
    • PressableA case study about how WP Cloud supports Pressable to power millions of page views daily.
    • Convesio
    • Porkbun
    • PanelAlpha
    • Ivapix
    • UNC Greensboro
    • Newspack
    • Inverse Paradox
  • Insights
    • Podcast
    • BlogWP Cloud blog page with latest news and updates about the platform.
    • Performance Benchmarks
  • Connect With Us
  • Login ↗
Start Here ↗

Browse

    • WP Cloud platform overview
    • Onboard and launch with WP Cloud
    • WP Cloud Partner Portal
    • Get support from WP Cloud
    • WP Cloud glossary
    • Manage and secure API keys
    • Client SSH
    • WP Cloud API quick start
    • Webhooks
    • Run bulk tasks across sites
      • Manage site domains and aliases
      • Domain verification records
      • TLS certificates
      • Manage custom TLS certificates
      • Cloudflare and WP Cloud
    • Clone a site
    • Configure resources, site type, and billing with site meta
    • Delete a site
    • Persistent data
    • Staging sites
    • Migrate a site to WP Cloud
      • SSH and SFTP access models
      • Client SSH
      • User SSH and SFTP access
      • Database credentials
      • phpMyAdmin
      • ABSPATH
      • Default wp-config.php
      • Site constants
      • Configure redirects and headers with custom-redirects.php
      • Akismet and Jetpack
      • Blocked and unsupported plugins
      • PHP lifecycle and supported versions
      • Symlinks and managed software
      • WordPress versions
      • Install Composer and WP-CLI packages
      • Manage platform software with WP-CLI
      • Useful WP-CLI commands
    • Transactional email
    • WordPress multisite
    • Cron scheduling
    • Decoupled and headless WordPress
    • Repair Yoast indexables
      • Page Cache
      • Edge Cache
      • Object Cache
      • Image transformation
      • Offload image sub-sizes
    • Configure lightweight 404s for static files
      • DDoS protection
      • Defensive Mode
      • Rate limiting
      • Network and web application firewalls
      • Bot protection
      • Password protection
      • HTTP and security headers
      • PHP filesystem access permissions
      • Scan a site for malware
    • Backups overview
    • Create an on-demand backup
    • Restore a backup
    • Jetpack backups
      • Error logs
      • Web server logs
    • Metrics
    • Application performance monitoring
    • Automated failover
    • IP ranges
    • Origin and edge servers
    • Server specifications and settings
    • EasyEngine integration
    • PanelAlpha integration
      • White labelling and co-marketing WP Cloud
      • WP Cloud logos
      • Terms of Service & Compliance
      • Prohibited content
      • Copyright infringement and takedown notifications
    • WP Cloud billing
    • WP Cloud for agencies and site networks
    • WP Cloud partner support options
    • Troubleshoot Page and Edge Cache
    • Troubleshoot HTTP 429 and 599 errors
    • WP Cloud HTTP status codes
    • Troubleshoot site performance
    • Cache slow database queries
    • Troubleshoot duplicate core files, wp-config.php, and wp-admin 403 errors
    • Troubleshoot email delivery
    • Troubleshoot PDF thumbnail generation
    • Troubleshoot TLS certificate provisioning
Documentation/Security/Traffic protection/Defensive Mode

Defensive Mode

LAST UPDATED

3 months ago

    Defensive Mode adds an on-demand browser challenge when a site needs more protection from automated traffic. It works with WP Cloud’s platform-level DDoS protection and requires Edge Cache.

    How Defensive Mode works

    You can enable Defensive Mode for 30 minutes through seven days. It uses proof of work: a visitor briefly sees a page that says the browser is being checked, then the browser completes the challenge and redirects the visitor to the requested page. This may take up to five seconds.

    The challenge reduces spam and DDoS requests from clients that cannot complete the work. It also applies to legitimate visitors. Browser-based visitors normally continue automatically, but API clients, webhooks, uptime monitors, and other automated clients may be unable to complete it.

    When to use Defensive Mode

    Use Defensive Mode during a suspected bot or DDoS event when unwanted traffic is still reaching the site or using PHP resources. Check Metrics, web server logs, and the site’s normal traffic pattern before and after enabling it.

    Keep Defensive Mode active only as long as needed. Check important site, API, webhook, monitoring, and checkout workflows after enabling it.

    Manage Defensive Mode with WP-CLI

    The installed wp edge-cache command accepts durations in minutes, hours, or days. The supported range is 30 minutes through seven days.

    Enable Defensive Mode for a duration:

    wp edge-cache defensive-mode --time=<time>Code language: HTML, XML (xml)

    For example:

    wp edge-cache defensive-mode --time=35m
    wp edge-cache defensive-mode --time=2h
    wp edge-cache defensive-mode --time=3d

    End it early:

    wp edge-cache defensive-mode --end

    Check the current Edge Cache and Defensive Mode state:

    wp edge-cache status

    Run wp edge-cache without a subcommand to see the usage installed on the site. The current command uses defensive-mode; do not use the obsolete defensive_mode form.

    Manage Defensive Mode through the API

    Use the Configure Defensive Mode endpoint to set the state for a site. WP Cloud partners can use this endpoint to provide Defensive Mode controls in their own dashboards.

    Supply the expiration as a Unix timestamp at least 30 minutes and no more than seven days in the future. A value of 0 disables Defensive Mode. The site-level route uses the primary domain by default. Use the domain-specific route documented in the same API group when the setting should apply to another domain on the site.

    Use the Get Defensive Mode status endpoint to retrieve the current ddos_until value. A future timestamp records when the mode is set to end; 0 means it is not active.

    Automatic Defensive Mode

    WP Cloud may enable Defensive Mode automatically when a site uses too many resources. This reduces unwanted requests reaching WordPress and can help legitimate traffic continue to reach the site instead of receiving rate-limit responses.

    Automatic Defensive Mode runs for 60 seconds at a time. WP Cloud may enable it again or extend it if conditions do not improve. A legitimate visitor is challenged no more than once per hour while automatic Defensive Mode is active.

    Check the site after enabling Defensive Mode

    After enabling Defensive Mode:

    1. Check wp edge-cache status or the API status endpoint.
    2. Open the site in a logged-out browser and confirm that the challenge appears and then loads the requested page.
    3. Test important automated clients. A client without a browser may be unable to complete the challenge.
    4. Compare request volume, rate-limit metrics, PHP use, and visitor errors with the period before you enabled it.
    5. End Defensive Mode when the additional challenge is no longer needed, then repeat the checks.

    If legitimate traffic still receives HTTP 429 responses, or WP Cloud records HTTP 599 errors during the event, use Troubleshoot HTTP 429 and 599 errors.

    Previous DDoS protection
    Next Rate limiting

    Related Guides

    • DDoS protection

      Learn how WP Cloud routes, filters, and mitigates denial-of-service traffic before it reaches WordPress.

      1 Min.

      READ

    • Rate limiting

      Understand how WP Cloud classifies excessive requests, when HTTP 429 responses are expected, and when…

      3 Min.

      READ

    • Network and web application firewalls

      Understand WP Cloud inbound access, outbound firewall rules, and web application firewall responses.

      2 Min.

      READ

    On this page

      Contact support

      Contact us with Support issues and questions related to WP Cloud, the WP Cloud Atomic API, API-key IP allow list changes, Station, and more.

      Check the FAQs

      Have questions? Please visit our FAQ to learn more.

      An Automattic venture

      Work With Us

      Press

      Privacy Policy

      © 2021-2026 Automattic Inc.

      Notifications