CO

Coraza WAF

Open-source enterprise-grade web application firewall

Reverse Proxy & Gateways ★ 3.7k stars Medium setup Apache-2.0

Coraza is an open-source, high-performance web application firewall library compatible with ModSecurity rules and the OWASP Core Rule Set. It is embedded into self-hosted proxies such as Caddy and Traefik.

Key features

  • ModSecurity-compatible
  • OWASP CRS support
  • High performance
  • Embeddable WAF

Strengths

  • Released under the Apache-2.0 license
  • Active community (3.7k GitHub stars)
  • Written in Go
  • Tiny footprint — runs in 128 MB RAM

Coraza WAF replaces

Compare Coraza WAF

13 head-to-head comparisons.

Similar reverse proxy & gateways apps