WAF problem with Site Kit by Google

https://wordpress.org/support/topic/error-the-response-is-not-a-valid-json-response-3/#post-12706811

check this.

  • Adam
    • Support Gorilla

    Hi Edoardo

    I hope you’re well today!

    I’ve read that entire thread to get the idea of the case but I’m not quite sure what assistance/action do you require now.

    It’s about WAF (Web Application Firewall) blocking some communication and that’s basically what the WAF is for. I understand that it’s causing issues with SIte Kit but the idea of WAF is to have it as strict as possible and then let you, if needed, whitelist IPs and/or disable selected rules – rather than the other way around. This is the only way it can provide some reasonable level of security.

    I’ll be more than happy to discuss it with our developers so we could consider and possibly make some more “global’ changes but I’d like to ask first:

    – did you whitelist your IP and did it work for you or it still didn’t let you overcome the issue?
    – what exactly should I do in Site Kit to replicate that – just try to connect it to Google Analytics?

    – and what kind of solution on our end would you expect/would you want for this on our end?

    I’m asking this just to be able to fully test the case and to discuss it with our hosting team so we could see what could be done about that. I’d appreciate feedback :slight_smile:

    Best regards,
    Adam

  • Adam
    • Support Gorilla

    Hi Edoardo

    Thank you for response!

    I went through the process on my test site on our hosting – with WAF enabled – and I could replicate it. I see how this could possibly be “confusing” and problematic for site admins so I’ve reported it to our Hosting team for review and I’m awaiting their feedback on the case.

    I or one of my colleagues will update you here once we only get more information from our devops about that.

    Thank you for reporting the issue!

    Best regards,
    Adam

  • Aditya Shah
    • DevOps Team Lead

    Hi Edoardo

    Hope you are doing good. :slight_smile:

    We have whitelisted the rule for the plugin globally for all sites and so you can enable the WAF again and it should work all good for Site Kit by Google.

    Please let us know if you need any further help. :slight_smile:

    Best Regards,
    Aditya Shah