While I trust the code is correct and secured to the best of our abilities, a Web Application Firewall (WAF) will provide an extra layer and account for things we forget (string sanitation for example) or things we cannot predict (zero day vulnerabilities). The WAF I recommend is Cloudflare pro due to Cloudflare's business reputation and the services low price ($20/month). Numerous alternatives also exist that would provide similar protection benefits (barracuda, radware, AWS).
While I trust the code is correct and secured to the best of our abilities, a Web Application Firewall (WAF) will provide an extra layer and account for things we forget (string sanitation for example) or things we cannot predict (zero day vulnerabilities). The WAF I recommend is Cloudflare pro due to Cloudflare's business reputation and the services low price ($20/month). Numerous alternatives also exist that would provide similar protection benefits (barracuda, radware, AWS).