# Best practices voor securing (Weweb) websites?

**URL:** https://community.weweb.io/t/best-practices-voor-securing-weweb-websites/16187
**Category:** How do I?
**Created:** [January 30, 2025, 1:08pm UTC](https://community.weweb.io/t/best-practices-voor-securing-weweb-websites/16187 "2025-01-30T13:08:32Z")
**Posts on this page:** 6
**Page:** 1

<div class="post-metadata">

### Author: ![thijs](https://sea2.discourse-cdn.com/flex016/user_avatar/community.weweb.io/thijs/32/13651_2.png) [@thijs](https://community.weweb.io/u/thijs)
#### Post date: [January 30, 2025, 1:08pm UTC](https://community.weweb.io/t/best-practices-voor-securing-weweb-websites/16187/1 "2025-01-30T13:08:32Z")

</div>

Hi,

Does the service of Weweb (and Xano) by itself have sufficient security hygene?  
Or is it recommended to use addditional services, such as Cloudflare’s Pro plan or something else?

What have I tried so far:

- make sense of securing my website, but most information I find seems promoting services (and it sounds like I really need all of them).
- checked out [Weweb’s security docentation/recommendations](https://docs.weweb.io/pages/private-pages.html#security), but that seems limited to the extent that security is controlled within the webapp/database.

Best regards,  
Thijs

---

<div class="post-metadata">

### Author: ![Micah](https://sea2.discourse-cdn.com/flex016/user_avatar/community.weweb.io/micah/32/9102_2.png) [@Micah](https://community.weweb.io/u/Micah)
#### Post date: [January 30, 2025, 2:15pm UTC](https://community.weweb.io/t/best-practices-voor-securing-weweb-websites/16187/2 "2025-01-30T14:15:57Z")

</div>

In terms of purely security, Xano and WeWeb give you the power to make everything secure. Is there anything specific that makes you question security?

---

<div class="post-metadata">

### Author: ![Joyce](https://sea2.discourse-cdn.com/flex016/user_avatar/community.weweb.io/joyce/32/13232_2.png) [@Joyce](https://community.weweb.io/u/Joyce)
#### Post date: [January 30, 2025, 3:55pm UTC](https://community.weweb.io/t/best-practices-voor-securing-weweb-websites/16187/3 "2025-01-30T15:55:55Z")

</div>

> [@thijs](#):
>
> most information I find seems promoting services (and it sounds like I really need all of them)

Welcome to the big bright world of marketing @thijs 😄

All jokes aside, I second what @Micah said – Xano and WeWeb have the features you need to keep things secure – and would also love to know more about what specific concerns you have. Knowing what you’re worried about will help us explain how to address those concerns.

---

<div class="post-metadata">

### Author: ![thijs](https://sea2.discourse-cdn.com/flex016/user_avatar/community.weweb.io/thijs/32/13651_2.png) [@thijs](https://community.weweb.io/u/thijs)
#### Post date: [January 30, 2025, 8:54pm UTC](https://community.weweb.io/t/best-practices-voor-securing-weweb-websites/16187/4 "2025-01-30T20:54:51Z")

</div>

> [@Joyce](#):
>
> ano and WeWeb have the features you need to keep things secure – and would also love to know more about what specific concerns you have. Knowing what you’re worried about will help us explain how to address those concerns.

Hi @Joyce and @Micah ,

First off all: your responses are what I was hoping for!

Perhaps my question already revealed that I have no IT background at all, so after learning Weweb/Xano for a year I want to make sure that I’m not overseeing something obvious related to security that could be considered as negligence. That’s why I’m happy with your response as it puts things into perspective.

One specific concern that I can think of is lacking responsiveness of the webapp due to inappropriate use/pinging of the webapp (perhaps by anyone else than clients). But I suppose its okay to accept this risk and take action whenever it may occur.

Thanks!  
Thijs

---

<div class="post-metadata">

### Author: ![WeeeeeWeb](https://sea2.discourse-cdn.com/flex016/user_avatar/community.weweb.io/weeeeeweb/32/9689_2.png) [@WeeeeeWeb](https://community.weweb.io/u/WeeeeeWeb)
#### Post date: [January 30, 2025, 10:57pm UTC](https://community.weweb.io/t/best-practices-voor-securing-weweb-websites/16187/5 "2025-01-30T22:57:50Z")

</div>

You can also make usage of the xano feature “ **Middleware** ” to secure the xano API requests. This will allow you to for example, create roles and validate permissions to the databases before running the actual API request.

---

<div class="post-metadata">

### Author: ![mosinjack](https://avatars.discourse-cdn.com/v4/letter/m/eada6e/32.png) [@mosinjack](https://community.weweb.io/u/mosinjack)
#### Post date: [May 12, 2025, 1:04pm UTC](https://community.weweb.io/t/best-practices-voor-securing-weweb-websites/16187/6 "2025-05-12T13:04:03Z")

</div>

Great question, Thijs. Weweb and Xano offer solid starting points when it comes to security, but it’s definitely recommended to layer on additional services like Cloudflare’s Pro plan—especially for DDoS protection, performance optimization, and extra control over your traffic. It’s kind of like website security in layers: the more you add, the more resilient you become.

I’ve been digging into this myself and totally agree—so much info out there is tied to upselling a service. It would be nice to have a straight-up guide that breaks things down clearly… maybe even with a few funny jokes[-](https://allfunnyjokes.com/) thrown in to make security feel less intimidating!
