Open Source WAF

SafeLine

SafeLine is a self-hosted WAF and reverse proxy often evaluated by teams that want local enforcement, Docker-first deployment, and a free path before commercial expansion.

Pricing
Free / Paid
Deployment
Docker, Linux, Kubernetes
Checked
2026-05-30

Open Source WAF

Coraza

Coraza is a Go-based WAF engine commonly considered when teams want ModSecurity-compatible rule support in modern Go-native environments.

Pricing
Free
Deployment
Library, Reverse Proxy integrations, Custom gateways
Checked
2026-05-30

Open Source WAF

ModSecurity

ModSecurity is a widely known open-source WAF engine and a common baseline for rule-based web application firewall deployments.

Pricing
Free
Deployment
Nginx, Apache, IIS
Checked
2026-05-30

Managed WAF

Cloudflare WAF

Cloudflare WAF is a managed edge security service suited for teams that want CDN, DNS, DDoS, bot, and WAF controls in one global platform.

Pricing
Free / Paid plans
Deployment
Cloud edge, DNS proxy, Reverse proxy
Checked
2026-05-30

Managed WAF

AWS WAF

AWS WAF is a managed web application firewall for protecting AWS-hosted applications and APIs with rule groups, managed rules, and AWS-native integrations.

Pricing
Usage-based
Deployment
CloudFront, Application Load Balancer, API Gateway
Checked
2026-05-30

Rule Set

OWASP Core Rule Set

OWASP CRS is not a standalone WAF product, but it is a key rule set used with WAF engines such as ModSecurity and Coraza.

Pricing
Free
Deployment
ModSecurity, Coraza, Compatible WAF engines
Checked
2026-05-30

Open Source WAF

open-appsec

open-appsec positions around modern WAF and API security with open-source deployment options and integrations for cloud-native entry points.

Pricing
Free / Paid
Deployment
Kubernetes, Nginx, Reverse Proxy
Checked
2026-05-30

Open Source WAF

BunkerWeb

BunkerWeb combines web serving and security controls, making it relevant for teams comparing open-source WAF-like protection for self-hosted workloads.

Pricing
Free / Paid
Deployment
Docker, Linux, Kubernetes
Checked
2026-05-30

Managed WAF

Akamai App & API Protector

Akamai App & API Protector is an enterprise WAAP option commonly evaluated by teams that want WAF, API protection, bot controls, and DDoS mitigation close to an edge delivery network.

Pricing
Quote-based
Deployment
Akamai edge, Hybrid apps, Multicloud traffic paths
Checked
2026-05-30

Enterprise WAF

F5 BIG-IP Advanced WAF

F5 BIG-IP Advanced WAF is an enterprise WAF commonly considered by teams that already use BIG-IP application delivery, need detailed policy controls, or operate hybrid infrastructure.

Pricing
Quote-based
Deployment
BIG-IP platform, Virtual edition, Hybrid infrastructure
Checked
2026-05-30

Nginx WAF

F5 WAF for NGINX

F5 WAF for NGINX is relevant when teams want WAF controls close to NGINX-based delivery, ingress, or reverse proxy patterns without relying only on open-source rule engines.

Pricing
Quote-based
Deployment
NGINX, Kubernetes ingress, Reverse proxy
Checked
2026-05-30

Managed WAF

Fastly Next-Gen WAF

Fastly Next-Gen WAF is a managed application security option often evaluated by teams that want WAF and API protection with edge delivery and security operations workflows.

Pricing
Quote-based
Deployment
Fastly edge, Cloud apps, API traffic paths
Checked
2026-05-30

Managed WAF

Imperva WAF

Imperva WAF is an enterprise application security product commonly evaluated for managed WAF, bot, DDoS, and compliance-oriented web application protection needs.

Pricing
Quote-based
Deployment
Cloud service, Hybrid environments, Enterprise web apps
Checked
2026-05-30

Cloud WAF

Azure Web Application Firewall

Azure Web Application Firewall is a managed WAF option for Azure-hosted and Azure-fronted applications, especially when teams already use Application Gateway or Azure Front Door.

Pricing
Usage-based
Deployment
Azure Application Gateway, Azure Front Door, Azure workloads
Checked
2026-05-30

Cloud WAF

Google Cloud Armor

Google Cloud Armor is a Google Cloud security service for protecting internet-facing applications with WAF rules, DDoS controls, and policy enforcement at Google's edge.

Pricing
Usage-based
Deployment
Google Cloud edge, Cloud Load Balancing, GCP workloads
Checked
2026-05-30

Open Source WAF

NAXSI

NAXSI is an open-source WAF project historically used with NGINX-style deployments and still relevant for teams researching lightweight rule-based WAF options.

Pricing
Free
Deployment
NGINX module, Reverse proxy, Self-hosted apps
Checked
2026-05-30