ModSecurity logo

ModSecurity

Open source WAF for Nginx and Apache

4.0(250 reviews)free
free tieropen sourceself hostable

ModSecurity is the leading open source WAF. Runs as a module for Nginx (via libmodsecurity) and Apache. OWASP Core Rule Set included. Self-hosted on any server.

Pros

  • Free and open source
  • OWASP Core Rule Set included
  • Runs on any Nginx or Apache server

Cons

  • Complex to tune — many false positives by default
  • Requires WAF expertise

Best For

Security engineers who want a free self-hosted WAF they fully control on their Nginx or Apache servers

Pricing

Free Forever

Free
  • Core features included

Reviews (0)

No reviews yet. Be the first to share your experience!

Write a Review

Articles about ModSecurity

Alternatives to ModSecurity

Sucuri logo

Sucuri

Website firewall and malware cleanup service

Firewall & DDoS ProtectionFrom €20/mo
5.0 (261)
View Tool →
AWS WAF logo

AWS WAF

Amazon WAF integrated with CloudFront and ALB

Firewall & DDoS ProtectionFrom €5/mo
4.9 (8)
View Tool →
Hetzner DDoS Protection logo

Hetzner DDoS Protection

Hardware-backed DDoS mitigation for high-traffic infrastructure

Firewall & DDoS ProtectionFree
4.9 (245)
View Tool →
Gcore logo

Gcore

Global CDN with 150+ PoPs including Russia and CIS

Firewall & DDoS ProtectionFree tier
4.8 (275)
View Tool →
Radware logo

Radware

Behavioral DDoS mitigation with machine learning

Firewall & DDoS ProtectionFrom €2000/mo
4.7 (217)
View Tool →
F5 BIG-IP logo

F5 BIG-IP

Enterprise application delivery controller

Firewall & DDoS ProtectionFrom €1000/mo
4.4 (41)
View Tool →

Stay in the loop

Get weekly updates on the best new AI tools, deals, and comparisons.

No spam. Unsubscribe anytime.