7,363 open-source and SaaS tools, with GitHub stats refreshed every day.

ModSecurity

Open source

Cross-platform web application firewall engine for Apache, IIS and Nginx that inspects HTTP traffic with SecRules-based rule sets.

modsecurity.org
ModSecurity homepage screenshot
GitHub stars
9.8k
Last commit
2 days ago
Repository age
15 years
Version
v3.0.17
Licence
Apache-2.0
Self-hosted
Yes

About ModSecurity

ModSecurity is an open-source, cross-platform web application firewall engine. It started as an Apache module and now serves Apache, IIS and Nginx, protecting web applications from a range of attacks while also allowing HTTP traffic monitoring, logging and real-time analysis through an event-based rule language.

This repository contains libmodsecurity, the ModSecurity v3 library. It acts as an interface to connectors that pass web traffic in, loads and interprets rules written in the SecRules format, and applies them to HTTP content from your application. Version 3 is a full rewrite that removes the Apache dependencies, aims for higher performance and a new architecture, and plans native JSON audit logs.

The older ModSecurity v2.x for Apache is still maintained in its own repository. The code is written in C++ and released under the Apache-2.0 license, under the OWASP organization. Rule sets such as the OWASP Core Rule Set are typically used alongside it.

Key features

  • WAF engine for Apache, IIS and Nginx
  • SecRules rule language
  • HTTP traffic monitoring and logging
  • Connector-based architecture in v3
  • Rewrite without Apache dependencies

Good fit for

  • โ†’Protecting web apps behind Nginx
  • โ†’Logging and analyzing attack attempts
Built with
C++
Tags
waf
web-security
nginx
apache
owasp
firewall
secrules
cpp

ModSecurity: questions and answers

What is ModSecurity used for?
ModSecurity is a cross-platform web application firewall engine for Apache, IIS and Nginx that inspects HTTP traffic with SecRules-based rule sets. It is a good fit for protecting web apps behind Nginx, and logging and analyzing attack attempts.
Is ModSecurity open source?
Yes. ModSecurity is open source under the Apache-2.0 licence. Its source code is on GitHub at owasp-modsecurity/ModSecurity and is written mainly in C++.
Is ModSecurity free?
Yes. ModSecurity is open source, so the software itself is free to use.
Can I self-host ModSecurity?
Yes. ModSecurity can be self-hosted on your own server or infrastructure; there is no official hosted version.
What is ModSecurity an alternative to?
ModSecurity is an open-source alternative to Cloudflare, Akamai, Fortinet and Fastly. Other open-source alternatives to Cloudflare include BunkerWeb, SafeLine and CrowdSec.
Is ModSecurity actively maintained?
Yes. The most recent commit to ModSecurity was on 30 September 2026, and the latest release is v3.0.17, published on 29 September 2026. The project has 9.8k stars on GitHub.

Open-source alternatives to ModSecurity

See all

SaaS alternatives to ModSecurity

See all