7,363 open-source and SaaS tools, with GitHub stats refreshed every day.

3 alternatives ranked by real activity

Open-source DataDome alternatives

A curated, ranked list of the 3 best open-source alternatives to DataDome.

The best open-source alternative to DataDome is SafeLine. If that doesn't suit you, other good options are CrowdSec and BunkerWeb.

DataDome alternatives are mainly security tools. 3 of them shipped code in the last 30 days, 3 can be self-hosted, and 1 uses a permissive licence.

Last updated October 3, 2026 · ranked by GitHub stars, growth and recent commits

SafeLine

Self-hosted web application firewall and reverse proxy that filters HTTP traffic to block attacks such as SQL injection, XSS, and bot abuse.

GitHub stars
23k
Last commit
4 days ago
Latest release
v9.4.2
Licence
GPL-3.0
Self-hosted
Yes
ly.safepoint.cloudSafeLine homepage screenshot

SafeLine is a self-hosted web application firewall (WAF) from Chaitin, released under the GPL-3.0 license. It sits in front of a web application as a reverse proxy, so visitors' requests pass through it first. It filters, monitors, and blocks malicious HTTP and HTTPS traffic before that traffic reaches the origin server, and it is also meant to stop unauthorized data from leaving the application.

The firewall targets common web attack classes, including SQL injection, cross-site scripting, command and code injection, server-side request forgery, path traversal, XXE, and remote code execution, as well as brute-force attempts, HTTP floods, and abusive bots. Beyond rule-based filtering, its documented core capabilities include IP-based rate limiting, a web access control list, bot defense, and encryption of the HTML and JavaScript code served to clients.

Security and operations teams that run their own websites or APIs can use it to add a protective layer in front of existing applications. The project is written in Go and hosted on GitHub, and the maintainers provide documentation, a live demo, and a Discord community. Because it is self-hosted, traffic inspection stays on infrastructure you control.

Key features

  • Reverse-proxy WAF filtering HTTP and HTTPS traffic
  • Blocks SQL injection, XSS, and RCE attempts
  • Defense against bot abuse and brute force
  • IP-based rate limiting
  • Web access control list rules
  • HTML and JavaScript code encryption
  • Self-hosted deployment on your own infrastructure

Pricing: Personal is free forever for up to 10 apps. Lite costs $10 per month ($100 per year) and Pro $100 per month ($1000 per year); Ultimate is custom. A 7-day trial is offered.

CrowdSec

CrowdSec is an open-source IDS/IPS, WAF and bot detection engine that blocks malicious IPs using a crowdsourced community blocklist.

GitHub stars
15k
Last commit
today
Latest release
v1.8.1
Licence
MIT
Self-hosted
Yes
docs.crowdsec.netCrowdSec homepage screenshot

CrowdSec is an open-source and participative security solution that detects and blocks malicious behavior on servers. Its Security Engine acts as an all-in-one intrusion detection and prevention system and web application firewall, analyzing log sources and HTTP requests and enforcing decisions through separate remediation components. It runs on Linux, Windows, Docker and Kubernetes.

A Community Blocklist of IP addresses identified as malicious is shared among users, so an address that attacks one participant can be blocked for others before it arrives. Detection and remediation are decoupled, which means logs can be parsed on one machine while blocking happens at a firewall, reverse proxy or CDN elsewhere. A web console supports monitoring and automation.

The README compares it with fail2ban, which reads similar logs, and with ModSecurity, Coraza and naxsi, since the AppSec component is a WAF built on Coraza that loads SecLang rules and the OWASP Core Rule Set. It can also answer suspicious requests with a JavaScript proof-of-work challenge to stop headless scrapers. CrowdSec is written in Go and licensed under MIT.

Key features

  • Log and HTTP request analysis for attack detection
  • Crowdsourced community blocklist of malicious IPs
  • WAF component built on Coraza
  • Remediation at firewall, proxy or CDN
  • Bot detection with proof-of-work challenges
  • Linux, Windows, Docker and Kubernetes support

Pricing: The Security Engine is free and open source under the MIT license.

BunkerWeb

Open-source web application firewall built on NGINX that acts as a reverse proxy with a web UI and a plugin system.

GitHub stars
11k
Last commit
today
Latest release
v1.6.15
Licence
AGPL-3.0
Self-hosted
Yes
bunkerweb.ioBunkerWeb homepage screenshot

BunkerWeb is an open-source web application firewall that protects web services and aims to make them secure by default. It is a complete web server based on NGINX that sits in front of your applications as a reverse proxy, filtering traffic before it reaches them.

It can be deployed in Linux, Docker, Swarm and Kubernetes environments and is configurable through a command line or a web user interface. Core security features ship in the box, and additional ones can be added with a plugin system. Related topics in the repository include ModSecurity, anti-bot protection, DNS blocklists and Let's Encrypt certificate handling.

The software is written mainly in Python and released under the AGPL-3.0 license. The project provides documentation, a demo, community templates, examples and a forum. Its goal is for administrators to get a reasonable level of protection with minimal configuration while keeping room to tune individual settings for their own use cases.

Key features

  • NGINX-based reverse proxy and WAF
  • Secure-by-default configuration
  • Web UI for managing settings
  • Plugin system for extra protections
  • Deploys on Linux, Docker, Swarm and Kubernetes
  • Anti-bot and DNS blocklist options

Pricing: A free open-source edition is available. Paid self-hosted plans are 49 euros (Shield) and 149 euros (Fortress) a month with a 30-day trial; managed Cloud starts from 639 euros a month and Sentinel is custom.

DataDome alternatives: questions

What is the best open-source alternative to DataDome?
SafeLine is the top-ranked open-source alternative to DataDome on Enlisted: Self-hosted web application firewall and reverse proxy that filters HTTP traffic to block attacks such as SQL injection, XSS, and bot abuse. Other strong options are CrowdSec and BunkerWeb.
Are these DataDome alternatives free?
All 3 are open source, so the code is free to use under its licence, and all of them can be self-hosted on your own server or computer.
How is this list of DataDome alternatives ranked?
By a score built from GitHub stars, star growth over the last 30 days and how recently the code changed. 3 of these projects shipped code in the last 30 days. Data is refreshed daily, and nobody can pay to move up.

People also look for alternatives to…

View all