Independent Web Application Firewall intelligence

Independent WAF directory and comparisons.

Compare open-source, self-hosted, managed, cloud, and Kubernetes WAF products by deployment model, features, sources, alternatives, and real-world selection criteria.

16vendor profiles
10comparison pages
10review pages
14tutorial guides
8best-of lists
8original labs

Latest tested evidence

ModSecurity vs Coraza: 20 of 20 expected HTTP results matched.

We ran the same OWASP CRS 4.25.0 request set through two pinned Docker stacks. The public evidence includes the full CSV, versioned JSON summary, JSON body results, clean-traffic warnings, and a local latency control.

  • 12 clean decisions returned HTTP 200.
  • 8 controlled SQLi/XSS decisions returned HTTP 403.
  • CRS 920350 exposed localhost Host-header alert noise without blocking clean traffic.
ModSecurity and Coraza twenty-request Docker result matrix

WAF fundamentals

New to Web Application Firewalls? Start with the traffic path.

Learn what a WAF is, how inspection and blocking work, which deployment model fits each architecture, what a WAF cannot replace, and how the technology evolved before comparing products.

Browse WAF fundamentals

Editorial research model

A neutral WAF research layer, not a vendor landing page.

WAFWiki is designed around repeatable data fields, official source links, comparison logic, and update notes. The first release intentionally favors verifiable structure over broad but shallow article volume.

Data cards

Each WAF profile tracks deployment model, pricing path, license, integrations, limitations, and sources.

Decision context

Pages frame practical questions such as reviews, alternatives, versus tradeoffs, and deployment guides.

Evidence trail

Official documentation, repositories, product pages, and last-checked dates are visible on profile pages.

Editorial separation

Commercial relationships are disclosed separately so they do not decide rankings, verdicts, or source standards.

Vendor directory

Start with structured WAF profiles.

Each profile is built from product data, official links, sources, alternatives, and last-checked metadata.

Open Source WAF

SafeLine

SafeLine is a self-hosted WAF and reverse proxy often evaluated by teams that want local enforcement, Docker-first deployment, and a free path before commercial expansion.

Pricing
Free / Paid
Deployment
Docker, Linux, Kubernetes
Checked
2026-05-30

Open Source WAF

Coraza

Coraza is a Go-based WAF engine commonly considered when teams want ModSecurity-compatible rule support in modern Go-native environments.

Pricing
Free
Deployment
Library, Reverse Proxy integrations, Custom gateways
Checked
2026-05-30

Open Source WAF

ModSecurity

ModSecurity is a widely known open-source WAF engine and a common baseline for rule-based web application firewall deployments.

Pricing
Free
Deployment
Nginx, Apache, IIS
Checked
2026-05-30

Managed WAF

Cloudflare WAF

Cloudflare WAF is a managed edge security service suited for teams that want CDN, DNS, DDoS, bot, and WAF controls in one global platform.

Pricing
Free / Paid plans
Deployment
Cloud edge, DNS proxy, Reverse proxy
Checked
2026-05-30

Managed WAF

AWS WAF

AWS WAF is a managed web application firewall for protecting AWS-hosted applications and APIs with rule groups, managed rules, and AWS-native integrations.

Pricing
Usage-based
Deployment
CloudFront, Application Load Balancer, API Gateway
Checked
2026-07-17

OWASP CRS is not a standalone WAF product, but it is a key rule set used with WAF engines such as ModSecurity and Coraza.

Pricing
Free
Deployment
ModSecurity, Coraza, Compatible WAF engines
Checked
2026-05-30

Cloud WAF field guides

Follow the architecture, pricing, rules, and deployment path.

These guides separate product profiles, independent reviews, infrastructure templates, and comparison decisions so each page answers one concrete research question.

Research pathways

Built for teams comparing reviews, alternatives, and WAF tradeoffs.

Start from common evaluation paths such as SafeLine WAF review, SafeLine alternatives, ModSecurity NGINX setup, AWS WAF vs Cloudflare, best self-hosted WAF, and Kubernetes WAF.

Independent reviews

Review pages for WAF selection and alternatives.

Each review frames deployment fit, risks, validation steps, and decision questions instead of writing vendor sales copy.

Install and validation guides

Tutorials designed for careful WAF rollout.

Guides cover prerequisites, staged deployment, validation, false-positive review, and rollback planning.

Original lab evidence

Hands-on notes and labeled WAF workflow diagrams.

WAFWiki now separates verified smoke tests from methodology diagrams, with visible node labels, reproducible commands, and evidence excerpts that readers can inspect.

Coraza Caddy Docker test evidence showing pinned component versions, image digest, six clean HTTP 200 results, four HTTP 403 results, and CRS rule IDs.
The fixed Coraza stack matched all ten expected outcomes in this localhost run: six clean requests returned 200 and four controlled SQLi/XSS requests returned 403.

    Completed hands-on test

    Coraza Caddy Docker Test: CRS 4.25.0 Results

    Hands-on Coraza and Caddy Docker test with pinned versions, OWASP CRS 4.25.0, ten clean and attack-like requests, HTTP results, logs, and build constraints.

    Twenty-request result matrix showing matching ModSecurity and Coraza HTTP 200 and 403 outcomes for clean, SQLi, XSS, query, and JSON cases.
    Both fixed stacks matched all 20 expected decisions. This is evidence of behavior on the selected matrix, not a universal accuracy ranking.

      Completed hands-on test

      ModSecurity vs Coraza Docker Test: 20 Request Results

      Original ModSecurity vs Coraza Docker comparison using the same OWASP CRS 4.25.0, upstream, and 20 HTTP decisions across clean, SQLi, XSS, query, and JSON cases.

      JSON body test evidence showing a clean JSON HTTP 200 result, SQLi-like and XSS-like HTTP 403 results, and OWASP CRS rule IDs.
      Across both stacks, the clean JSON body was allowed twice while the SQLi-like and XSS-like JSON fields were blocked four times.

        Completed hands-on test

        WAF JSON Body Test: ModSecurity vs Coraza

        Hands-on JSON request-body test showing how ModSecurity and Coraza handled one clean body plus controlled SQLi-like and XSS-like fields under OWASP CRS 4.25.0.