Skip to content

What it blocks

Database injection

Someone tries to slip database commands into your site.

What it is

Database commands typed into a search box, a form or an address, hoping your site passes them straight to its database.

  • ' OR '1'='1 in a login form
  • UNION SELECT in an address
  • A command to delete a table in a search box

Why it matters

When it works, the attacker can read or change everything the site stores: customers, orders, passwords.

If a real visitor is ever stopped

This can catch real text that happens to look like a database command, such as a note about SQL or a name with an apostrophe beside certain words. Mark the request as real and that one field is let through.