compare
ModSecurity vs open-appsec
The same facts for both, read from GitHub every night, and the relation a person reviewed.
| Fact | ModSecurity | open-appsec |
|---|---|---|
| Language | C++ | C++ |
| Licence | Apache-2.0 | Apache-2.0 |
| Stars | 9.8k | 1.7k |
| Latest | v3.0.17 | 1.1.36 |
| Last push | 2026-10-03 | 2026-09-06 |
| Release cadence | about 33 days between releases | about 73 days between releases |
| Active contributors | 2 commit authors on the default branch in the last 90 days | not counted |
| Flags | none | none |
How they relate
Both replace Cloudflare WAF. Alternatives to Cloudflare WAF →
PartialModSecurityWAF engine for nginx, Apache and IIS on your own servers, used with a rule set such as the OWASP CRS.
Partialopen-appsecMachine-learning WAF for NGINX, Kubernetes ingress and API gateways, without a CDN.
ModSecurity
open-appsec
- 1.1.362026-08-24Support for new nginx & Linux distributions
- 1.1.352026-08-25Support for new nginx & Linux distributions
- 1.1.342026-04-20Support for new nginx & Linux distributions
- 1.1.332026-01-20Support for Debian Buster and Trixie #342
- 1.1.322025-11-26Prometheus support in declarative mode, read more here
ModSecurity
✓ signed The latest release, v3.0.17, carries a signature GitHub verified.
Loading the security report
open-appsec
✓ signed The latest release, 1.1.36, carries a signature GitHub verified.
Loading the security report