Paranoia levels

Per-site levels 0–5. Default is 3. Level 4 can rise to 5 for a timed window.

Set sites[].waf.paranoia_level per site. Legal values are 0–5. The default is 3.

The engine looks at one decoded parameter value at a time. Path and parameter names stay visible.

LevelNameIsolatedEmbeddedTimed rise
0Record onlyLog, allowLog, allowNo
1Low monitorLog, allowLog, allowNo
2Low-mediumBlockAllow, review laterNo
3StandardBlockAllow, review laterNo
4Medium-highBlockAllow, review laterYes (rise to 5)
5StrictBlockBlock, then reviewAlready max

Temporary rise

At level 4, an embedded hit can raise the site to level 5 for promote_seconds (for example 300 seconds). The deadline is stored in SQLite. A process restart does not clear it.

Level 5 review

A sample blocked at level 5 still enters the review queue with a blocked mark. You cannot flip it to allow. You can save a lasting deny rule (feature, URL, IP, or fingerprint).