SafeLine
Self-hosted web application firewall and reverse proxy that filters HTTP traffic to block attacks such as SQL injection, XSS, and bot abuse.
- GitHub stars
- 23k
- Last commit
- 4 days ago
- Latest release
- v9.4.2
- Licence
- GPL-3.0
- Self-hosted
- Yes

SafeLine is a self-hosted web application firewall (WAF) from Chaitin, released under the GPL-3.0 license. It sits in front of a web application as a reverse proxy, so visitors' requests pass through it first. It filters, monitors, and blocks malicious HTTP and HTTPS traffic before that traffic reaches the origin server, and it is also meant to stop unauthorized data from leaving the application.
The firewall targets common web attack classes, including SQL injection, cross-site scripting, command and code injection, server-side request forgery, path traversal, XXE, and remote code execution, as well as brute-force attempts, HTTP floods, and abusive bots. Beyond rule-based filtering, its documented core capabilities include IP-based rate limiting, a web access control list, bot defense, and encryption of the HTML and JavaScript code served to clients.
Security and operations teams that run their own websites or APIs can use it to add a protective layer in front of existing applications. The project is written in Go and hosted on GitHub, and the maintainers provide documentation, a live demo, and a Discord community. Because it is self-hosted, traffic inspection stays on infrastructure you control.
Key features
- Reverse-proxy WAF filtering HTTP and HTTPS traffic
- Blocks SQL injection, XSS, and RCE attempts
- Defense against bot abuse and brute force
- IP-based rate limiting
- Web access control list rules
- HTML and JavaScript code encryption
- Self-hosted deployment on your own infrastructure
Pricing: Personal is free forever for up to 10 apps. Lite costs $10 per month ($100 per year) and Pro $100 per month ($1000 per year); Ultimate is custom. A 7-day trial is offered.


