7,363 open-source and SaaS tools, with GitHub stats refreshed every day.

SafeLine

Open source

Self-hosted web application firewall and reverse proxy that filters HTTP traffic to block attacks such as SQL injection, XSS, and bot abuse.

ly.safepoint.cloud
SafeLine homepage screenshot
GitHub stars
23k
Last commit
5 days ago
Repository age
3 years
Version
v9.4.2
Licence
GPL-3.0
Self-hosted
Yes

About SafeLine

SafeLine is a self-hosted web application firewall (WAF) from Chaitin, released under the GPL-3.0 license. It sits in front of a web application as a reverse proxy, so visitors' requests pass through it first. It filters, monitors, and blocks malicious HTTP and HTTPS traffic before that traffic reaches the origin server, and it is also meant to stop unauthorized data from leaving the application.

The firewall targets common web attack classes, including SQL injection, cross-site scripting, command and code injection, server-side request forgery, path traversal, XXE, and remote code execution, as well as brute-force attempts, HTTP floods, and abusive bots. Beyond rule-based filtering, its documented core capabilities include IP-based rate limiting, a web access control list, bot defense, and encryption of the HTML and JavaScript code served to clients.

Security and operations teams that run their own websites or APIs can use it to add a protective layer in front of existing applications. The project is written in Go and hosted on GitHub, and the maintainers provide documentation, a live demo, and a Discord community. Because it is self-hosted, traffic inspection stays on infrastructure you control.

Key features

  • Reverse-proxy WAF filtering HTTP and HTTPS traffic
  • Blocks SQL injection, XSS, and RCE attempts
  • Defense against bot abuse and brute force
  • IP-based rate limiting
  • Web access control list rules
  • HTML and JavaScript code encryption
  • Self-hosted deployment on your own infrastructure

Good fit for

  • →Shielding public web apps from common attacks
  • →Rate limiting abusive clients and bots
  • →Adding a WAF layer in front of APIs
Built with
Go
Tags
waf
web-application-firewall
reverse-proxy
security
self-hosted
sql-injection
xss
bot-protection
rate-limiting

SafeLine: questions and answers

What is SafeLine used for?
SafeLine is a self-hosted web application firewall and reverse proxy that filters HTTP traffic to block attacks such as SQL injection, XSS, and bot abuse. It is a good fit for shielding public web apps from common attacks, rate limiting abusive clients and bots, and adding a WAF layer in front of APIs.
Is SafeLine open source?
Yes. SafeLine is open source under the GPL-3.0 licence. Its source code is on GitHub at chaitin/SafeLine and is written mainly in Go.
Is SafeLine free?
Yes. SafeLine is open source, so the software itself is free to use. Paid plans are also available, starting at $10 per month.
Can I self-host SafeLine?
Yes. SafeLine can be self-hosted on your own server or infrastructure.
What is SafeLine an alternative to?
SafeLine is an open-source alternative to Cloudflare, Fastly, Akamai and Barracuda Networks. Other open-source alternatives to Cloudflare include BunkerWeb, CrowdSec and ModSecurity.
Is SafeLine actively maintained?
Yes. The most recent commit to SafeLine was on 28 September 2026, and the latest release is v9.4.2, published on 28 September 2026. The project has 23k stars on GitHub.

Open-source alternatives to SafeLine

See all

SaaS alternatives to SafeLine

See all