Coraza WAF
Open-source enterprise-grade web application firewall
Coraza is an open-source, high-performance web application firewall library compatible with ModSecurity rules and the OWASP Core Rule Set. It is embedded into self-hosted proxies such as Caddy and Traefik.
Key features
- ModSecurity-compatible
- OWASP CRS support
- High performance
- Embeddable WAF
Strengths
- Released under the Apache-2.0 license
- Active community (3.7k GitHub stars)
- Written in Go
- Tiny footprint — runs in 128 MB RAM
Coraza WAF replaces
Compare Coraza WAF
13 head-to-head comparisons.
- Coraza WAF vs Caddy
- Coraza WAF vs Traefik
- Coraza WAF vs Pi-hole
- Coraza WAF vs acme.sh
- Coraza WAF vs mitmproxy
- Coraza WAF vs Kong Gateway
- Coraza WAF vs Istio
- Coraza WAF vs AdGuard Home
- Coraza WAF vs NPS
- Coraza WAF vs Nginx Proxy Manager
- Coraza WAF vs SafeLine
- Coraza WAF vs CrowdSec
- Coraza WAF vs Traefik Geoblock
Similar reverse proxy & gateways apps
Caddy
Reverse Proxy & GatewaysFast, multi-platform web server with automatic HTTPS
Replaces Nginx, Apache
Traefik
Reverse Proxy & GatewaysCloud-native reverse proxy and load balancer
Replaces HAProxy, AWS ELB
Pi-hole
Reverse Proxy & GatewaysBlackhole for Internet advertisements with a GUI for management and
acme.sh
Reverse Proxy & GatewaysPure shell ACME client for TLS certificates
Replaces Certbot
mitmproxy
Reverse Proxy & GatewaysInteractive HTTPS proxy for inspection and debugging
Replaces Charles Proxy, Fiddler
Kong Gateway
Reverse Proxy & GatewaysCloud-native, fast, scalable API gateway
Replaces AWS API Gateway, Apigee