← back

category

Web application firewalls

Inspect HTTP traffic and block attacks, bots and abuse before they reach an application.

Side by side

Web application firewalls
ToolStarsLicenceTermsSelf-hostedLanguageLatestLast push
Anubis23kMITOpen sourceYesGov1.27.02026-10-05
SafeLine23kGPL-3.0Open sourceYesGov9.4.22026-09-28
ModSecurity9.8kApache-2.0Open sourceYesC++v3.0.172026-10-03
Coraza3.9kApache-2.0Open sourceYesGov3.8.12026-10-06
OWASP CRS3.3kApache-2.0Open sourceYesPythonv4.30.02026-10-06
open-appsec1.7kApache-2.0Open sourceYesC++1.1.362026-09-06

6 tools

Anubis

Weighs the soul of incoming HTTP requests to stop AI crawlers

Language
Go
Licence
MIT
Stars
23k
Latest
v1.27.0
Last push
2026-10-05
SafeLine

SafeLine is a self-hosted WAF(Web Application Firewall) / reverse proxy to protect your web apps from attacks and exploits.

Language
Go
Licence
GPL-3.0
Stars
23k
Latest
v9.4.2
Last push
2026-09-28
ModSecurity

ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. It has a robust event-based programming language which provides protection from a range of attacks against web applications and allows for HTTP traffic monitoring, logging and real-time analysis.

Language
C++
Licence
Apache-2.0
Stars
9.8k
Latest
v3.0.17
Last push
2026-10-03
Coraza

OWASP Coraza WAF is a golang modsecurity compatible web application firewall library

Language
Go
Licence
Apache-2.0
Stars
3.9k
Latest
v3.8.1
Last push
2026-10-06
open-appsec

open-appsec is a machine learning security engine that preemptively and automatically prevents threats against Web Application & APIs. This repo include the main code and logic.

Language
C++
Licence
Apache-2.0
Stars
1.7k
Latest
1.1.36
Last push
2026-09-06

What these tools replace