What happened
The website you scanned is protected by a firewall, CDN, or bot-protection system, and that system blocked or challenged some of the requests the CookieInspector scanner made. Instead of the real page, the scanner received an access-denied page, a challenge, a rate-limit response, or nothing at all.
CookieInspector does not try to bypass these controls. It records what it could observe and marks the scan as limited.
The block can come from many places, not only a traditional Web Application Firewall: a CDN, bot protection, a managed challenge, IP reputation, rate limiting, firewall rules, or automated-traffic detection. The report uses the label WAF Limited Report for all of them.