About ModSecurity
ModSecurity is an open-source, cross-platform web application firewall engine. It started as an Apache module and now serves Apache, IIS and Nginx, protecting web applications from a range of attacks while also allowing HTTP traffic monitoring, logging and real-time analysis through an event-based rule language.
This repository contains libmodsecurity, the ModSecurity v3 library. It acts as an interface to connectors that pass web traffic in, loads and interprets rules written in the SecRules format, and applies them to HTTP content from your application. Version 3 is a full rewrite that removes the Apache dependencies, aims for higher performance and a new architecture, and plans native JSON audit logs.
The older ModSecurity v2.x for Apache is still maintained in its own repository. The code is written in C++ and released under the Apache-2.0 license, under the OWASP organization. Rule sets such as the OWASP Core Rule Set are typically used alongside it.
Key features
- WAF engine for Apache, IIS and Nginx
- SecRules rule language
- HTTP traffic monitoring and logging
- Connector-based architecture in v3
- Rewrite without Apache dependencies
Good fit for
- โProtecting web apps behind Nginx
- โLogging and analyzing attack attempts
- Built with
- C++
- Tags
- waf
- web-security
- nginx
- apache
- owasp
- firewall
- secrules
- cpp
ModSecurity: questions and answers
- What is ModSecurity used for?
- ModSecurity is a cross-platform web application firewall engine for Apache, IIS and Nginx that inspects HTTP traffic with SecRules-based rule sets. It is a good fit for protecting web apps behind Nginx, and logging and analyzing attack attempts.
- Is ModSecurity open source?
- Yes. ModSecurity is open source under the Apache-2.0 licence. Its source code is on GitHub at owasp-modsecurity/ModSecurity and is written mainly in C++.
- Is ModSecurity free?
- Yes. ModSecurity is open source, so the software itself is free to use.
- Can I self-host ModSecurity?
- Yes. ModSecurity can be self-hosted on your own server or infrastructure; there is no official hosted version.
- What is ModSecurity an alternative to?
- ModSecurity is an open-source alternative to Cloudflare, Akamai, Fortinet and Fastly. Other open-source alternatives to Cloudflare include BunkerWeb, SafeLine and CrowdSec.
- Is ModSecurity actively maintained?
- Yes. The most recent commit to ModSecurity was on 30 September 2026, and the latest release is v3.0.17, published on 29 September 2026. The project has 9.8k stars on GitHub.
Open-source alternatives to ModSecurity
See all
BunkerWeb
Security
๐ก๏ธ Open-source and cloud-native Web Application Firewall (WAF)
AGPL-3.0vs Cloudflareโ 11k
SafeLine
Security
CyberServal open-source WAF is a self-hosted WAF with 20.9K GitHub stars. Block SQL inject
GPL-3.0vs Cloudflareโ 23k
CrowdSec
Security
Open-source IDS/IPS, WAF and bot detection for Linux, Windows, Docker and Kubernetes, with
MITvs Cloudflareโ 15k
NGINX
Networking & VPN
The official NGINX Open Source repository.
BSD-2-Clausevs Cloudflareโ 32k
OPNsense
Security
OPNsense GUI, API and systems backend
BSD-2-Clausevs Fortinetโ 4.7k
pfSense
Security
Main repository for pfSense
Apache-2.0vs Fortinetโ 5.7k
SaaS alternatives to ModSecurity
See all
Cloudflare
Networking & VPN
CDN, DNS, DDoS protection and edge computing platform
SaaS
Akamai
Networking & VPN
CDN, security and edge compute platform for enterprise web delivery
SaaS
Fortinet
Security
FortiGate firewalls and a broad security fabric for network, cloud and endpoints
SaaS
Fastly
Networking & VPN
Edge cloud platform for CDN, security and serverless compute
SaaS
Barracuda Networks
Security
Email, network and application security products
SaaS
Imperva
Security
Web application, API and data security platform
SaaS

