{"id":633,"date":"2026-08-12T07:08:26","date_gmt":"2026-08-12T07:08:26","guid":{"rendered":"https:\/\/www.osto.one\/resources\/?p=633"},"modified":"2026-08-12T07:08:26","modified_gmt":"2026-08-12T07:08:26","slug":"waf","status":"publish","type":"post","link":"https:\/\/www.osto.one\/resources\/glossary\/waf\/","title":{"rendered":"WAF Explained: What a Web Application Firewall Blocks"},"content":{"rendered":"\n<!-- =========================================================================\n     OSTO GLOSSARY: WAF\n     Shared glossary design system. Paste into one Custom HTML block. No H1.\n     ========================================================================= -->\n\n<style>\n.og{\n  --navy:#1c267a; --text:#0f1538; --muted:#0f1538; --light:#0f1538;\n  --border:#e7e9f2; --divider:#eceef5; --white:#ffffff;\n\n  --peri-50:#f4f5fd;  --peri-100:#e9ecfa; --peri-200:#cfd5f2; --peri-700:#4a52a8;\n  --sage-50:#f2f8f5;  --sage-100:#e3f0e9; --sage-200:#c3ddce; --sage-700:#3a6f5d;\n  --apri-50:#fdf6f0;  --apri-100:#fbe9dc; --apri-200:#f2cdb2; --apri-700:#a2603a;\n  --plum-50:#f8f3f9;  --plum-100:#f0e6f3; --plum-200:#dcc6e2; --plum-700:#6b4576;\n  --sky-50:#f1f7fb;   --sky-100:#e2eff7;  --sky-200:#bfd9e9;  --sky-700:#2f6a89;\n\n  --shadow:0 6px 22px rgba(15,21,56,.05);\n  --font:'Inter',-apple-system,BlinkMacSystemFont,'Segoe UI',Roboto,sans-serif;\n  font-family:var(--font); font-size:17px; line-height:1.75; color:var(--text);\n}\n.og p{margin:0 0 22px}\n.og h2{font-family:var(--font);font-size:clamp(25px,3vw,31px);font-weight:700;line-height:1.25;letter-spacing:-.5px;color:var(--navy);margin:52px 0 8px;scroll-margin-top:92px}\n.og h2::after{content:\"\";display:block;width:46px;height:5px;border-radius:3px;margin:12px 0 18px;background:var(--peri-200)}\n.og h2.c-sage::after{background:var(--sage-200)}\n.og h2.c-apri::after{background:var(--apri-200)}\n.og h2.c-plum::after{background:var(--plum-200)}\n.og h2.c-sky::after{background:var(--sky-200)}\n.og ul,.og ol{padding-left:22px;margin:0 0 24px}\n.og li{margin-bottom:9px}\n.og strong{font-weight:600}\n\n.og .dek{font-size:20px;line-height:1.6;color:var(--muted);margin:0 0 18px}\n.og .tags{margin:0 0 30px;padding:0;list-style:none;display:flex;flex-wrap:wrap;gap:8px}\n.og .tags li{margin:0}\n.og .tag{display:inline-block;font-size:12px;font-weight:600;letter-spacing:.7px;text-transform:uppercase;padding:6px 13px;border-radius:20px}\n.og .t-peri{background:var(--peri-100);color:var(--peri-700)}\n.og .t-sage{background:var(--sage-100);color:var(--sage-700)}\n\n.og .short{background:linear-gradient(135deg,var(--peri-100) 0%,var(--sage-100) 100%);border-radius:22px;padding:28px 32px;margin:0 0 30px}\n.og .short .k{font-size:13px;font-weight:700;letter-spacing:1.4px;text-transform:uppercase;color:var(--peri-700);margin:0 0 10px}\n.og .short p{font-size:19px;line-height:1.65;margin:0;color:var(--text)}\n\n.og .toc{background:var(--peri-50);border-radius:20px;padding:24px 28px;margin:0 0 34px}\n.og .toc .k{font-size:12px;font-weight:700;letter-spacing:1.3px;text-transform:uppercase;color:var(--peri-700);margin:0 0 12px}\n.og .toc ol{margin:0;padding-left:20px;columns:2;column-gap:34px}\n.og .toc li{margin-bottom:8px;break-inside:avoid;font-size:16px}\n.og .toc a{color:var(--navy);text-decoration:none;border-bottom:1px solid rgba(28,38,122,.22)}\n\n.og .callout{border-radius:4px;padding:24px 28px;margin:0 0 30px;background:var(--white);border:2px solid var(--navy)}\n.og .callout .k{font-weight:700;font-size:17px;margin:0 0 8px;color:var(--navy)}\n.og .callout p:last-child{margin-bottom:0}\n.og .callout.c-plum{background:var(--plum-50);border:none;border-radius:20px}\n.og .callout.c-plum .k{color:var(--plum-700)}\n\n.og figure{margin:0 0 30px}\n.og .sx{overflow-x:auto;-webkit-overflow-scrolling:touch;border-radius:20px;background:var(--white);box-shadow:var(--shadow)}\n.og .sx svg{display:block;width:100%;height:auto;min-width:600px}\n.og figcaption{font-size:14px;line-height:1.6;color:var(--muted);margin-top:12px}\n.og .swipe{display:none}\n\n.og table{width:100%;border-collapse:collapse;margin:0 0 28px;font-size:15px;background:var(--white);border-radius:18px;overflow:hidden;box-shadow:var(--shadow)}\n.og th{text-align:left;padding:14px 16px;font-weight:700;font-size:12.5px;letter-spacing:.8px;text-transform:uppercase}\n.og td{border-bottom:1px solid var(--divider);padding:13px 16px;vertical-align:top;line-height:1.6}\n.og tr:last-child td{border-bottom:none}\n.og .h-peri th{background:var(--peri-100);color:var(--peri-700)}\n.og .h-sage th{background:var(--sage-100);color:var(--sage-700)}\n.og .h-plum th{background:var(--plum-100);color:var(--plum-700)}\n\n.og .trio{display:grid;grid-template-columns:repeat(3,1fr);gap:14px;margin:0 0 28px}\n.og .tcard{border-radius:18px;padding:20px 22px}\n.og .tcard .n{font-size:16px;font-weight:700;margin:0 0 4px}\n.og .tcard .g{font-size:13px;font-weight:600;margin:0 0 10px;opacity:.8}\n.og .tcard p{font-size:14px;line-height:1.55;margin:0;color:var(--muted)}\n.og .tcard.a{background:var(--sky-50)}   .og .tcard.a .n,.og .tcard.a .g{color:var(--sky-700)}\n.og .tcard.b{background:var(--sage-50)}  .og .tcard.b .n,.og .tcard.b .g{color:var(--sage-700)}\n.og .tcard.c{background:var(--plum-50)}  .og .tcard.c .n,.og .tcard.c .g{color:var(--plum-700)}\n\n.og .pill{display:inline-block;font-size:11px;font-weight:700;letter-spacing:.8px;text-transform:uppercase;padding:5px 11px;border-radius:20px;white-space:nowrap}\n.og .p-req{background:var(--plum-200);color:#4d2f57}\n.og .p-exp{background:var(--sky-100);color:var(--sky-700)}\n.og .p-imp{background:#eef0f4;color:var(--muted)}\n.og .p-ask{background:var(--apri-100);color:var(--apri-700)}\n.og .p-yes{background:var(--sage-100);color:var(--sage-700)}\n.og .p-no{background:#eef0f4;color:var(--muted)}\n\n.og details{background:var(--white);border-radius:14px;margin:0 0 10px;box-shadow:0 2px 10px rgba(15,21,56,.04)}\n.og summary{cursor:pointer;padding:16px 20px;font-weight:600;font-size:17px;color:var(--navy);list-style:none;display:flex;justify-content:space-between;gap:16px;align-items:flex-start}\n.og summary::-webkit-details-marker{display:none}\n.og summary::after{content:\"+\";font-size:22px;line-height:1;color:var(--peri-700);flex:0 0 auto}\n.og details[open] summary::after{content:\"\\2013\"}\n.og details p{padding:0 20px 18px;margin:0;font-size:16px;line-height:1.7}\n\n.og .related{font-size:15px;color:var(--muted);border-top:1px solid var(--divider);padding-top:22px;margin-top:40px}\n\n@media(max-width:700px){\n  .og{font-size:16px}\n  .og .dek{font-size:18px}\n  .og .short p{font-size:17px}\n  .og .short,.og .toc,.og .callout{padding:22px 20px}\n  .og .toc ol{columns:1}\n  .og .trio{grid-template-columns:1fr}\n  .og .swipe{display:inline;font-weight:600;color:var(--peri-700)}\n  .og table{font-size:14px}\n  .og th,.og td{padding:11px 12px}\n}\n<\/style>\n\n<div class=\"og\">\n\n<p class=\"dek\">A WAF sits in front of your application, inspects every incoming request, and blocks the ones carrying an attack before they reach your servers.<\/p>\n\n<ul class=\"tags\">\n  <li><span class=\"tag t-peri\">Glossary<\/span><\/li>\n  <li><span class=\"tag t-sage\">Application security<\/span><\/li>\n<\/ul>\n\n<div class=\"short\">\n  <p class=\"k\">The short answer<\/p>\n  <p>A web application firewall filters HTTP traffic at the application layer. It blocks SQL injection, cross-site scripting, bot traffic and the rest of the OWASP Top 10, along with volumetric attacks. A network firewall decides which ports are open; a WAF reads what is actually inside the request.<\/p>\n<\/div>\n\n<p>It is a control, not a fix. A WAF buys you time on a vulnerability you have not patched yet, and stops the automated traffic that makes up most attacks. It does not repair the underlying flaw.<\/p>\n\n<div class=\"toc\">\n  <p class=\"k\">On this page<\/p>\n  <ol>\n    <li><a href=\"#path\">Where a WAF sits<\/a><\/li>\n    <li><a href=\"#models\">Negative and positive security models<\/a><\/li>\n    <li><a href=\"#blocks\">What it blocks<\/a><\/li>\n    <li><a href=\"#osto\">How Osto runs its WAF<\/a><\/li>\n    <li><a href=\"#faq\">FAQ<\/a><\/li>\n  <\/ol>\n<\/div>\n\n<h2 id=\"path\">Where a WAF sits<\/h2>\n\n<figure>\n<div class=\"sx\">\n<svg viewBox=\"0 0 760 280\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" role=\"img\" aria-label=\"Traffic passes through the WAF, which forwards legitimate requests to the origin and blocks attacks.\">\n  <defs><marker id=\"wfA\" markerWidth=\"9\" markerHeight=\"9\" refX=\"7\" refY=\"4.5\" orient=\"auto\"><path d=\"M0,0 L9,4.5 L0,9 z\" fill=\"#3a6f5d\"\/><\/marker>\n  <marker id=\"wfB\" markerWidth=\"9\" markerHeight=\"9\" refX=\"7\" refY=\"4.5\" orient=\"auto\"><path d=\"M0,0 L9,4.5 L0,9 z\" fill=\"#a2603a\"\/><\/marker><\/defs>\n\n  <rect x=\"14\" y=\"52\" width=\"140\" height=\"44\" rx=\"12\" fill=\"#e3f0e9\"\/>\n  <text x=\"84\" y=\"80\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12.5\" font-weight=\"700\" fill=\"#3a6f5d\">Real visitors<\/text>\n  <rect x=\"14\" y=\"112\" width=\"140\" height=\"44\" rx=\"12\" fill=\"#fbe9dc\"\/>\n  <text x=\"84\" y=\"140\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12.5\" font-weight=\"700\" fill=\"#a2603a\">Bots and scanners<\/text>\n  <rect x=\"14\" y=\"172\" width=\"140\" height=\"44\" rx=\"12\" fill=\"#fbe9dc\"\/>\n  <text x=\"84\" y=\"200\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12.5\" font-weight=\"700\" fill=\"#a2603a\">Injection attempts<\/text>\n\n  <line x1=\"160\" y1=\"74\" x2=\"248\" y2=\"112\" stroke=\"#c3c9f0\" stroke-width=\"2\"\/>\n  <line x1=\"160\" y1=\"134\" x2=\"248\" y2=\"134\" stroke=\"#c3c9f0\" stroke-width=\"2\"\/>\n  <line x1=\"160\" y1=\"194\" x2=\"248\" y2=\"156\" stroke=\"#c3c9f0\" stroke-width=\"2\"\/>\n\n  <rect x=\"252\" y=\"76\" width=\"150\" height=\"116\" rx=\"16\" fill=\"#1c267a\"\/>\n  <text x=\"327\" y=\"122\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"15\" font-weight=\"700\" fill=\"#ffffff\">WAF<\/text>\n  <text x=\"327\" y=\"144\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11.5\" fill=\"#b9c1e6\">Inspects every<\/text>\n  <text x=\"327\" y=\"160\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11.5\" fill=\"#b9c1e6\">request in full<\/text>\n\n  <line x1=\"408\" y1=\"104\" x2=\"500\" y2=\"104\" stroke=\"#3a6f5d\" stroke-width=\"2.5\" marker-end=\"url(#wfA)\"\/>\n  <text x=\"454\" y=\"94\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11\" fill=\"#3a6f5d\">allowed<\/text>\n  <rect x=\"510\" y=\"80\" width=\"200\" height=\"52\" rx=\"12\" fill=\"#e3f0e9\"\/>\n  <text x=\"610\" y=\"104\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"13\" font-weight=\"700\" fill=\"#3a6f5d\">Your application<\/text>\n  <text x=\"610\" y=\"122\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11\" fill=\"#0f1538\">origin never exposed directly<\/text>\n\n  <line x1=\"408\" y1=\"164\" x2=\"500\" y2=\"164\" stroke=\"#a2603a\" stroke-width=\"2.5\" marker-end=\"url(#wfB)\"\/>\n  <text x=\"454\" y=\"154\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11\" fill=\"#a2603a\">blocked<\/text>\n  <rect x=\"510\" y=\"142\" width=\"200\" height=\"46\" rx=\"12\" fill=\"#fbe9dc\"\/>\n  <text x=\"610\" y=\"170\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12.5\" font-weight=\"700\" fill=\"#a2603a\">Dropped at the edge<\/text>\n\n  <text x=\"380\" y=\"238\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12.5\" fill=\"#0f1538\">Because traffic terminates at the WAF, the origin server is never addressed directly.<\/text>\n  <text x=\"380\" y=\"258\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12.5\" fill=\"#0f1538\">Attackers cannot bypass it by connecting straight to your servers.<\/text>\n<\/svg>\n<\/div>\n<\/figure>\n\n<h2 id=\"models\" class=\"c-sage\">Negative and positive security models<\/h2>\n\n<p>This is the difference that decides how much manual work a WAF creates.<\/p>\n\n<table class=\"h-sage\">\n  <thead>\n    <tr><th><\/th><th>Negative model<\/th><th>Positive model<\/th><\/tr>\n  <\/thead>\n  <tbody>\n    <tr><td><strong>Rule<\/strong><\/td><td>Block anything matching a known attack pattern<\/td><td>Allow only what the application legitimately expects<\/td><\/tr>\n    <tr><td><strong>Catches<\/strong><\/td><td>Known attacks with a signature<\/td><td>Anything outside normal behaviour, including novel attacks<\/td><\/tr>\n    <tr><td><strong>Effort<\/strong><\/td><td>Rules maintained as attacks evolve<\/td><td>Requires learning the application&#8217;s real behaviour first<\/td><\/tr>\n    <tr><td><strong>False positives<\/strong><\/td><td>Higher on unusual but valid traffic<\/td><td>Lower once the profile is accurate<\/td><\/tr>\n  <\/tbody>\n<\/table>\n\n<h2 id=\"blocks\" class=\"c-apri\">What it blocks<\/h2>\n\n<div class=\"trio\">\n  <div class=\"tcard a\">\n    <p class=\"n\">Injection and scripting<\/p>\n    <p>SQL injection, cross-site scripting, command injection and the rest of the OWASP Top 10.<\/p>\n  <\/div>\n  <div class=\"tcard b\">\n    <p class=\"n\">Automated traffic<\/p>\n    <p>Credential stuffing, scraping, vulnerability scanners and volumetric floods.<\/p>\n  <\/div>\n  <div class=\"tcard c\">\n    <p class=\"n\">Abuse of your own logic<\/p>\n    <p>Forced browsing, parameter tampering, cookie manipulation and unauthorised endpoints.<\/p>\n  <\/div>\n<\/div>\n\n<h2 id=\"osto\">How Osto runs its WAF<\/h2>\n\n<p>Osto&#8217;s reverse-proxy WAF learns each application&#8217;s behaviour and generates a positive security policy automatically, so protection stands up without hand-written rules and with fewer false positives. It discovers applications and APIs and applies protection to them, enforces URL, parameter and method validation, checks cookie security and file uploads, and keeps recommending policy changes as the application evolves. Because it runs in the same platform as <a href=\"https:\/\/www.osto.one\/resources\/glossary\/cspm\/\">CSPM<\/a>, endpoint and the <a href=\"https:\/\/www.osto.one\/resources\/glossary\/siem\/\">SIEM<\/a>, a blocked request can be correlated with what else that source has been doing.<\/p>\n\n<p class=\"related\"><strong>Product documentation:<\/strong> Setup guides and technical reference are available in the <a href=\"https:\/\/docs.osto.one\/\" target=\"_blank\" rel=\"noopener\">Osto documentation<\/a>.<\/p>\n\n<!-- ============ CTA ============ -->\n<div style=\"background:linear-gradient(135deg,#1c267a 0%,#3f4796 48%,#6b4576 100%);border-radius:22px;padding:38px 34px;margin:40px 0 12px;box-shadow:0 10px 26px rgba(28,38,122,.2);text-align:center;\">\n  <p style=\"display:inline-block;background:rgba(255,255,255,.16);color:#ffffff;font-family:'Inter',-apple-system,sans-serif;font-size:11px;font-weight:700;letter-spacing:1.2px;text-transform:uppercase;padding:6px 14px;border-radius:20px;margin:0 0 16px;\">Free security assessment<\/p>\n  <p style=\"color:#ffffff;font-family:'Inter',-apple-system,sans-serif;font-size:26px;line-height:1.3;font-weight:700;letter-spacing:-.4px;margin:0 0 12px;\">A WAF that configures itself<\/p>\n  <p style=\"color:#cfd3ea;font-family:'Inter',-apple-system,sans-serif;font-size:16px;line-height:1.65;margin:0 auto 26px;max-width:520px;\">Osto learns each application and generates a positive security policy automatically, so protection stands up without hand-written rules.<\/p>\n  <a href=\"https:\/\/osto.one\/contact\/\" style=\"display:inline-block;background:#ffffff;color:#1c267a;font-family:&#039;Inter&#039;,-apple-system,sans-serif;font-weight:700;font-size:16px;text-decoration:none;border-bottom:none;padding:14px 30px;border-radius:12px;margin:0 6px 10px;\" target=\"_blank\" rel=\"noopener\"><span style=\"color:#1c267a;\">Get a free security assessment<\/span><\/a>\n  <a href=\"https:\/\/osto.one\/book-demo\/\" style=\"display:inline-block;background:transparent;color:#ffffff;font-family:&#039;Inter&#039;,-apple-system,sans-serif;font-weight:600;font-size:16px;text-decoration:none;border:1.5px solid rgba(255,255,255,.5);border-radius:12px;padding:13px 28px;margin:0 6px 10px;\" target=\"_blank\" rel=\"noopener\"><span style=\"color:#ffffff;\">Book a platform walkthrough<\/span><\/a>\n  <p style=\"color:#b3b8d8;font-family:'Inter',-apple-system,sans-serif;font-size:13px;margin:14px 0 0;\">Auto app and API discovery &middot; Low false positives &middot; One platform, everything<\/p>\n<\/div>\n\n\n<h2 id=\"faq\">Frequently asked questions<\/h2>\n\n<details>\n  <summary>What does WAF stand for?<\/summary>\n  <p>Web application firewall. It inspects HTTP traffic at the application layer and blocks requests carrying attacks before they reach the application.<\/p>\n<\/details>\n\n<details>\n  <summary>How is a WAF different from a network firewall?<\/summary>\n  <p>A network firewall controls which ports and addresses can connect. A WAF reads the content of the request itself, which is the only way to see that a legitimate request to port 443 contains a SQL injection payload.<\/p>\n<\/details>\n\n<details>\n  <summary>Does a WAF replace fixing the vulnerability?<\/summary>\n  <p>No. It reduces exposure while a fix is developed and tested, which is genuinely valuable, but the flaw is still there. Treat WAF blocking as buying time rather than closing the issue.<\/p>\n<\/details>\n\n<details>\n  <summary>Do frameworks require a WAF?<\/summary>\n  <p>PCI DSS requires public-facing web applications to be protected, and names an automated technical solution such as a WAF as one way to meet it. <a href=\"https:\/\/www.osto.one\/resources\/glossary\/iso-27001\/\">ISO 27001<\/a> and <a href=\"https:\/\/www.osto.one\/resources\/blog\/soc-2-controls-cc1-cc9\/\">SOC 2<\/a> do not name the technology, but expect the underlying protection to exist.<\/p>\n<\/details>\n\n<p class=\"related\"><strong>Related glossary terms:<\/strong> <a href=\"https:\/\/www.osto.one\/resources\/glossary\/api-security\/\">API Security<\/a> &middot; DDoS &middot; OWASP Top 10 &middot; DAST &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/cspm\/\">CSPM<\/a> &middot; SIEM<\/p>\n\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>A WAF sits in front of your application, inspects every incoming request, and blocks the ones carrying an attack before\u2026<\/p>\n","protected":false},"author":8,"featured_media":634,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[180],"tags":[222,133,221,223],"class_list":["post-633","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-glossary","tag-negative-and-positive-security-models","tag-waf","tag-what-is-waf","tag-what-waf-does"],"_links":{"self":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/633","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/comments?post=633"}],"version-history":[{"count":1,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/633\/revisions"}],"predecessor-version":[{"id":635,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/633\/revisions\/635"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/media\/634"}],"wp:attachment":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/media?parent=633"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/categories?post=633"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/tags?post=633"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}