5 Best Free and Open Source WAF for 2025

This page summarizes the projects mentioned and recommended in the original post on dev.to

Judoscale - Save 47% on cloud hosting with autoscaling that just works
Judoscale integrates with Django, FastAPI, Celery, and RQ to make autoscaling easy and reliable. Save big, and say goodbye to request timeouts and backed-up task queues.
judoscale.com
featured
CodeRabbit: AI Code Reviews for Developers
Revolutionize your code reviews with AI. CodeRabbit offers PR summaries, code walkthroughs, 1-click suggestions, and AST-based analysis. Boost productivity and code quality across all major languages with each PR.
coderabbit.ai
featured
  1. SafeLine

    SafeLine is a self-hosted WAF(Web Application Firewall) / reverse proxy to protect your web apps from attacks and exploits.

    Link: SafeLine on GitHub

  2. Judoscale

    Save 47% on cloud hosting with autoscaling that just works. Judoscale integrates with Django, FastAPI, Celery, and RQ to make autoscaling easy and reliable. Save big, and say goodbye to request timeouts and backed-up task queues.

    Judoscale logo
  3. ModSecurity

    Discontinued ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. It has a robust event-based programming language which provides protection from a range of attacks against web applications and allows for HTTP traffic monitoring, logging and real-time analysis. [Moved to: https://github.com/owasp-modsecurity/ModSecurity] (by SpiderLabs)

    Link: ModSecurity on GitHub

  4. Awesome-WAF

    🔥 Web-application firewalls (WAFs) from security standpoint.

    Link: Awesome-WAF on GitHub

  5. BunkerWeb

    🛡️ Open-source and next-generation Web Application Firewall (WAF)

    Link: BunkerWeb on GitHub

  6. wafw00f

    WAFW00F allows one to identify and fingerprint Web Application Firewall (WAF) products protecting a website.

    Link: wafw00f on GitHub

  7. CodeRabbit

    CodeRabbit: AI Code Reviews for Developers. Revolutionize your code reviews with AI. CodeRabbit offers PR summaries, code walkthroughs, 1-click suggestions, and AST-based analysis. Boost productivity and code quality across all major languages with each PR.

    CodeRabbit logo
NOTE: The number of mentions on this list indicates mentions on common posts plus user suggested alternatives. Hence, a higher number means a more popular project.

Suggest a related project

Related posts

  • Comparison on Six Self-Hosted WAF

    3 projects | dev.to | 26 Aug 2024
  • Top Open-Source WAF Projects: Secure Your Website with the Best Tools

    6 projects | dev.to | 19 Aug 2024
  • A powerful free and open source WAF – UUSEC WAF

    4 projects | news.ycombinator.com | 16 Mar 2025
  • Battle of the WAFs: Testing Detection and Performance Across Open-Source Firewalls

    3 projects | dev.to | 27 Aug 2024
  • Recommended free and open-source WAF for 2024.

    6 projects | dev.to | 19 Jul 2024

Did you know that Python is
the 2nd most popular programming language
based on number of references?