Firewall & Security Suite
In-App Purchases
Subscriptions
Description
Highlights
Features
About the Extension
A firewall that lives inside Shopware and acts before the HTTP cache: it blocks malicious IPs, whole countries, brute-force, scanners and spam before they do any harm.
Every publicly reachable shop is probed by bots around the clock. The Firewall & Security Suite sits directly in Shopware - in front of the cache - and rejects known threat IPs, blocked countries, honeypot hits and rate abuse. Login, registration and forms get their own base protection. And because everything is built "observe first", you first see risk-free what a stricter mode would catch - then you switch it on with a single click.
The problem you know
Your shop is publicly reachable - and therefore a permanent target for automation:
- Scanners constantly probe admin paths and config files (/wp-login.php, /.env and the like).
- Brute-force and credential stuffing hammer the customer login.
- Bots create fake accounts and spam contact and newsletter forms.
- Scrapers pull prices and content by the second.
Shopware core offers little against this. The workarounds are unsatisfying: a WAF/CDN enterprise plan is expensive and complex, blocking IPs manually in the web server is reactive and tedious, and tools like fail2ban sit outside Shopware - with no relation to login, registration or checkout.
How "Firewall & Security Suite" solves it
Instead of patchwork, a layered protection that acts commerce-natively exactly where it counts:
- Pre-cache firewall. Known threat IPs are rejected very early - before the request triggers expensive processing. No external service required.
- Five protection layers, one control centre. IP reputation (threat blacklist), geo blocking, rate limiter, honeypots and base protection for login, registration and forms - all in one place.
- Observe first. Freshly installed, the firewall blocks nothing and only records. The "would-block preview" shows what a stricter mode would catch - you only switch it on once you are sure.
- Self-lockout protection built in. Your own IP is detected, private/reserved addresses are exempt, and verified crawlers (Google/Bing) can be waved through via an allow-list.
The benefits at a glance
- Less attack surface - bots, scanners and known threat IPs never even reach the shop.
- Built to minimise false positives against real customers - thanks to observe-first and self-lockout protection.
- No external infrastructure - runs inside Shopware, without an expensive WAF or CDN.
- Full traceability - dashboard, analysis and log show live what is happening.
Typical use cases
Constant scanner traffic: your server log is full of /wp-login.php and /.env requests. Honeypots recognise these trap paths as a conclusive scanner signal and ban the IP - immediately in protect mode.
Brute-force on the login: a script tries passwords by the minute. Base protection counts failed attempts per IP and bans once the threshold is crossed - known-suspicious IPs even earlier.
Traffic from unwanted regions: attacks cluster from certain countries you do not sell to anyway. Geo blocking blocks or observes whole countries - with a single click via presets.
Fake registrations and form spam: bots create accounts en masse and flood contact/newsletter forms. Base protection detects the waves and throttles the source.
Features in detail
Pre-cache firewall with IP reputation
A compiled firewall list built from continuously updated threat feeds (including FireHOL, Spamhaus DROP, Team Cymru bogons, AbuseIPDB) is checked on every request - before the HTTP cache. Despite millions of entries, the check stays in the sub-millisecond range thanks to indexed network matching. IPv4 and IPv6 are supported equally.
Geo blocking for whole countries
Block or observe individual countries via a clear country grid with flags. Presets (e.g. "Europe only", "known risk regions") set the selection with one click; each country can be switched between block, observe and off.
Rate limiter against frequency abuse
Throttles IPs that send too many requests per time window - counted separately per area such as account, checkout, catalog and 404 scans. Repeat offenders are banned for increasingly longer periods via an escalation ladder. The limiter only enforces when proxy detection is clean (protection against mass false bans behind a CDN/proxy).
Honeypots (trap URLs)
Configurable paths that no real visitor ever requests (e.g. /wp-login.php). A hit is a conclusive scanner signal and leads - in protect mode - to an immediate ban; in observe mode it is only recorded.
Base protection for login, registration and forms
Six guards at the sensitive endpoints of the shop, each individually switchable:
- Login brute-force - ban after too many failed attempts within the window.
- Registration spam - throttles mass account creation.
- Password reset abuse - protects the reset request.
- Form abuse - covers contact and newsletter forms.
- Honeypots - trap URLs as a scanner signal.
- Admin login - observes failed backend logins (the admin access is never banned automatically, as a self-protection measure).
Known-suspicious IPs get a lower threshold than unknown ones - a second signal is enough.
Observe first with protection-level presets
Two separate axes: the mode (off / observe / protect) decides WHETHER it enforces; the protection level (soft / medium / hard) sets dozens of values with one click - thresholds, ban durations, time windows. This lets you test "observe + hard" risk-free before you switch on enforcement.
Dashboard, analysis and log
A dashboard with live key figures (blocked / observed / active bans) and a 24-hour trend. The analysis condenses the events into top IPs, attack types, origin countries and the would-block preview. The log is the complete, filterable list of individual events - clearable at any time to start from zero.
Visible rules instead of a black box
Automatic bans land as regular, visible and editable rules in the rule list - with an expiry and a reason. Your own allow/block rules (a single IP or a whole CIDR range) complement them; an allow rule always wins and protects against self-lockout.
Privacy and operation
- GDPR-compliant IP anonymisation - visitor IPs stored truncated on request (IPv4 /24, IPv6 /48).
- Recording can be turned off - for data economy, without touching protection.
- Per sales channel and multilingual (German / English).
- Setup assistant walks you through the initial setup in a few steps.
What this plugin does - and what it doesn't
So you know exactly what you get:
- It is an application firewall inside Shopware, not a network scrubber. Volumetric DDoS attacks still belong at the edge/CDN layer - this suite complements an edge WAF rather than replacing it.
- Counting happens behind the cache, blocking in front of it. Pure scraping over fully cached pages is therefore not detected as rate abuse (a detection limit); enforcement of a detected IP, however, is total.
- Behind a proxy/CDN, trusted proxies must be configured correctly, otherwise the firewall sees the proxy IP instead of the visitor IP - in that case the rate limiter does not enforce, for safety.
- The admin login is never banned automatically (self-lockout protection) - it is only observed.
- Threat and geo lists are only as good as their sources; misclassifications are possible - which is exactly what observe-first and the allow-list are for.
Who it pays off for
Shopware merchants of any size who want to actively secure their shop against bots, brute-force, scanners, scraping and spam - without running an expensive WAF/CDN enterprise plan. Equally for agencies that need traceable protection with a dashboard, analysis and an audit log.
The result: less attack surface, minimal false positives against real customers, full traceability - right inside Shopware.
Details
- Available: English, German
- Latest update: 18 July 2026
- Publication date: 18 July 2026
- Version: 2.0.0
- Category: Administration
Resources
Reviews (0)
About the Extension Partner
digitvision
Partner Status
-
Shopware
Premium Extension Partner
Details
- Ø-Rating: 4.9
- Partner since: 2018
- Extensions: 104
Support
- Based in: Germany
- Speaks: German, English
- Response time: Very quickly