BunkerWeb
Open-source web application firewall built on NGINX that acts as a reverse proxy with a web UI and a plugin system.
- GitHub stars
- 11k
- Last commit
- today
- Latest release
- v1.6.15
- Licence
- AGPL-3.0
- Self-hosted
- Yes

BunkerWeb is an open-source web application firewall that protects web services and aims to make them secure by default. It is a complete web server based on NGINX that sits in front of your applications as a reverse proxy, filtering traffic before it reaches them.
It can be deployed in Linux, Docker, Swarm and Kubernetes environments and is configurable through a command line or a web user interface. Core security features ship in the box, and additional ones can be added with a plugin system. Related topics in the repository include ModSecurity, anti-bot protection, DNS blocklists and Let's Encrypt certificate handling.
The software is written mainly in Python and released under the AGPL-3.0 license. The project provides documentation, a demo, community templates, examples and a forum. Its goal is for administrators to get a reasonable level of protection with minimal configuration while keeping room to tune individual settings for their own use cases.
Key features
- NGINX-based reverse proxy and WAF
- Secure-by-default configuration
- Web UI for managing settings
- Plugin system for extra protections
- Deploys on Linux, Docker, Swarm and Kubernetes
- Anti-bot and DNS blocklist options
Pricing: A free open-source edition is available. Paid self-hosted plans are 49 euros (Shield) and 149 euros (Fortress) a month with a 30-day trial; managed Cloud starts from 639 euros a month and Sentinel is custom.



