Data cards
Each WAF profile tracks deployment model, pricing path, license, integrations, limitations, and sources.
Independent Web Application Firewall intelligence
Compare open-source, self-hosted, managed, cloud, and Kubernetes WAF products by deployment model, features, sources, alternatives, and real-world selection criteria.
Latest tested evidence
We ran the same OWASP CRS 4.25.0 request set through two pinned Docker stacks. The public evidence includes the full CSV, versioned JSON summary, JSON body results, clean-traffic warnings, and a local latency control.

WAF fundamentals
Learn what a WAF is, how inspection and blocking work, which deployment model fits each architecture, what a WAF cannot replace, and how the technology evolved before comparing products.
Browse WAF fundamentalsEditorial research model
WAFWiki is designed around repeatable data fields, official source links, comparison logic, and update notes. The first release intentionally favors verifiable structure over broad but shallow article volume.
Each WAF profile tracks deployment model, pricing path, license, integrations, limitations, and sources.
Pages frame practical questions such as reviews, alternatives, versus tradeoffs, and deployment guides.
Official documentation, repositories, product pages, and last-checked dates are visible on profile pages.
Commercial relationships are disclosed separately so they do not decide rankings, verdicts, or source standards.
Vendor directory
Each profile is built from product data, official links, sources, alternatives, and last-checked metadata.
Open Source WAF
SafeLine is a self-hosted WAF and reverse proxy often evaluated by teams that want local enforcement, Docker-first deployment, and a free path before commercial expansion.
Open Source WAF
Coraza is a Go-based WAF engine commonly considered when teams want ModSecurity-compatible rule support in modern Go-native environments.
Open Source WAF
ModSecurity is a widely known open-source WAF engine and a common baseline for rule-based web application firewall deployments.
Managed WAF
Cloudflare WAF is a managed edge security service suited for teams that want CDN, DNS, DDoS, bot, and WAF controls in one global platform.
Managed WAF
AWS WAF is a managed web application firewall for protecting AWS-hosted applications and APIs with rule groups, managed rules, and AWS-native integrations.
Rule Set
OWASP CRS is not a standalone WAF product, but it is a key rule set used with WAF engines such as ModSecurity and Coraza.
Cloud WAF field guides
These guides separate product profiles, independent reviews, infrastructure templates, and comparison decisions so each page answers one concrete research question.
Research pathways
Start from common evaluation paths such as SafeLine WAF review, SafeLine alternatives, ModSecurity NGINX setup, AWS WAF vs Cloudflare, best self-hosted WAF, and Kubernetes WAF.
Independent reviews
Each review frames deployment fit, risks, validation steps, and decision questions instead of writing vendor sales copy.
Install and validation guides
Guides cover prerequisites, staged deployment, validation, false-positive review, and rollback planning.
Original lab evidence
WAFWiki now separates verified smoke tests from methodology diagrams, with visible node labels, reproducible commands, and evidence excerpts that readers can inspect.

Completed hands-on test
Hands-on Coraza and Caddy Docker test with pinned versions, OWASP CRS 4.25.0, ten clean and attack-like requests, HTTP results, logs, and build constraints.

Completed hands-on test
Original ModSecurity vs Coraza Docker comparison using the same OWASP CRS 4.25.0, upstream, and 20 HTTP decisions across clean, SQLi, XSS, query, and JSON cases.

Completed hands-on test
Hands-on JSON request-body test showing how ModSecurity and Coraza handled one clean body plus controlled SQLi-like and XSS-like fields under OWASP CRS 4.25.0.