Open source modsecurity projects

Every project in the registry tagged modsecurity, ranked by real GitHub adoption.

projects 3 combined stars ★ 28K refresh nightly
01 crowdsec ★ 15K

Open-source IDS/IPS, WAF and bot detection for Linux, Windows, Docker and Kubernetes, with a crowdsourced blocklist of malicious IPs.

last push19 hours ago languageGo licenseMIT
02 bunkerweb ★ 11K

🛡️ Open-source and cloud-native Web Application Firewall (WAF)

last push17 hours ago languagePython licenseAGPL-3.0
03 uusec-waf ★ 1.7K

Industry-leading free, high-performance, AI and semantic technology Web Application Firewall and API Security Gateway (WAAP) - UUSEC WAF.

last push5 days ago languageShell licenseBSD-2-Clause

← all tags

Frequently asked questions

How many open source modsecurity projects are there?

This registry tracks 3 projects tagged modsecurity, with 27,668 GitHub stars between them. The most-adopted is crowdsec at 14,956 stars.

Are these modsecurity projects free to use?

Yes — 3 of the 3 carry an explicit open-source licence across 3 distinct licences, so there is no licence fee. Where a project also sells a hosted or enterprise version, the self-hosted path remains free.

Which modsecurity project should I choose?

The list above is ranked by GitHub stars, but stars measure attention rather than fit. Check three things on each card: the licence (permissive versus copyleft), the language it is written in, and the last-push date — a high-star project that has not been pushed in a year is a liability.

Are these modsecurity projects still maintained?

3 of the 3 were pushed in the last 90 days, and every card shows its exact last-push date so you can see the rest. Sort your shortlist by that date before committing to a migration.