Lia

GitHub is where WAF projects prove themselves in production. Stars, commits, releases, issue resolution — the public record tells you more than any vendor comparison page. Here are five self-hosted WAFs worth your time, ranked by what they actually deliver.

1. SafeLine — 17K+ Stars

The most-starred WAF on GitHub. Deployed as Docker containers with a clean web dashboard, SafeLine uses semantic analysis rather than signature matching — it parses the grammatical structure of HTTP requests to distinguish attacks from legitimate traffic.

Detection rate: 71.65% with 0.07% false positives (BlazeHTTP benchmark).

Install:

bash -c "$(curl -fsSLk https://waf.chaitin.com/release/latest/manager.sh)" -- --en

Enter fullscreen mode Exit fullscreen mode

Best for: Teams that want strong protection out of the box with minimal tuning. Community Edition is free for up to 10 applications.

2. BunkerWeb — NGINX-Based, Feature-Rich

Built on NGINX with ModSecurity + OWASP CRS integration. Includes a web UI, automatic Let's Encrypt, antibot challenges (Captcha, reCAPTCHA, hCaptcha), and Docker/K8s support.

Best for: Users who want the OWASP CRS ecosystem with a modern GUI and container-native deployment.

Weakness: Detection depends on ModSecurity rules, which generate a 17.58% false positive rate without extensive tuning.

3. Coraza — The Modern ModSecurity Replacement

An OWASP project written in Go. Drop-in compatible with ModSecurity SecLang rules and 100% compatible with OWASP CRS v4. Integrates with Caddy, Envoy, HAProxy, and Nginx.

Best for: Teams already invested in ModSecurity/CRS who want better performance without changing their rule sets.

Weakness: No built-in UI. You'll need separate tooling for dashboards and log analysis.

4. CrowdSec — Community-Powered Threat Intelligence

An IDS/IPS with a WAF component driven by community-sourced threat intelligence. Over 110,000 machines share IP reputation data, creating a continuously updated blocklist. The WAF uses virtual patching — blocks known-bad request patterns with near-zero false positives.

Best for: Teams that want crowd-sourced IP blocking alongside WAF capability. MIT-licensed and free.

Weakness: The WAF component is newer and less comprehensive than dedicated WAFs. Better paired with something like SafeLine or Coraza.

5. PRX-WAF — High-Performance on Pingora

Built on Cloudflare's Pingora proxy library in Rust. Supports HTTP/1.1, HTTP/2, HTTP/3 (QUIC), 644+ built-in rules, OWASP CRS, ModSecurity rule import, and a Vue 3 admin UI. Extremely fast — sub-millisecond latency on clean traffic.

Best for: Teams that need maximum throughput and want to stay in the Rust/Pingora ecosystem.

Weakness: Newer project with a smaller community. Documentation is still catching up to features.

Benchmark Comparison

WAF Detection False Positives Dashboard Setup
SafeLine 71.65% 0.07% Yes - Clean GUI One command
ModSecurity + CRS 69.74% 17.58% No - Third-party Hours of tuning
BunkerWeb ~65% ~10% Yes - Web UI Docker Compose
CrowdSec WAF Varies Near-zero No Module install
Coraza + CRS ~65% ~10% No Library/plugin

FAQ

Which has the easiest setup?

SafeLine. One command, no rule tuning required. BunkerWeb is second — Docker Compose with env vars.

Which is best for production?

SafeLine or Coraza. SafeLine if you want a GUI and low false positives out of the box. Coraza if you need CRS compatibility and are comfortable without a UI.

Is ModSecurity still worth using?

Only if you're already deeply invested in it and have your rules finely tuned. For new deployments, Coraza gives you CRS compatibility with better performance and a modern codebase.

Do I need to choose just one?

No. SafeLine for application-layer inspection, CrowdSec for IP reputation, and Cloudflare for CDN/DDoS — layered defense.


Which matters more when evaluating a WAF — detection rate, false positives, or ease of setup?


Try SafeLine WAF — self-hosted Community Edition, free for up to 10 apps.
Live Demo | GitHub | Deploy Guide | Discord