OWASP
ModSecurity
Project

A trusted, community-driven open-source WAF engine protecting real-world web applications. Built for today and actively maintained so you stay safe against emerging cybersecurity threats.

Latest release date:

ModSecurity inspects traffic in both directions. Valid requests from a browser HTTP client reach protected CMS, REST API, SaaS and database services; unsafe requests and responses containing sensitive data are blocked.

Open Source Web Application Firewall

ModSecurity is an open-source, cross-platform web application firewall (WAF) module. Known as the “Swiss Army Knife” of WAFs, it enables web application defenders to gain visibility into HTTP(S) traffic and provides a power rules language and API to implement advanced protections.

The Most Widespread Open-Source WAF

Used by businesses, government organizations, internet service providers, and commercial WAF vendors alike on millions of domains all over the world. The engine, coupled with OWASP CRS - the dominant WAF rule set, undeniably raises the level of protection against HTTP attacks to a higher level.

OWASP logo

ModSecurity under OWASP’s custodianship

OWASP® Foundation, the leading open community dedicated to application security, is already responsible for the Core Rule Set, the dominant WAF rule set on the market. By joining the ModSecurity WAF to their repertoire, OWASP can now steer ModSecurity’s development with a holistic view, fostering even tighter integration between the core rule set and the underlying framework.

Getting Started

Usage Scenarios

  • Real-time application security monitoring and access control
  • Full HTTP traffic logging
  • Continuous passive security assessment
  • Web application hardening

Download

Principles

  • Flexibility
  • Passiveness
  • Predictability
  • Quality over quantity

Learn more

Community

Be part of a vibrant and welcoming community.

Join us on Slack for discussions, see GitHub for our projects, or follow us on X (Twitter).

We are always looking for new contributors and developers.

Join the community

Latest Blog Posts

View all updates

Trusted by

Logos reflect publicly available information, not endorsements or partnerships. None of these companies fund the project.

Interested in backing ModSecurity and becoming an official supporter? Contact us for sponsorship options.