Anubis
Web AI firewall utility that challenges and blocks scraper bots
21.7k stars 693 forks last commit first released MIT
Actively maintained
Last commit 25 Aug 2026.

Anubis is a lightweight web AI firewall utility that protects upstream websites from high-volume scraper bots, especially AI crawlers. It sits in front of your origin and uses one or more challenges to decide whether to allow a request through.
Key Features
- Challenge-based request gating to deter automated scraping and crawler traffic
- Designed to be lightweight and affordable to run in front of community sites and small services
- Configurable bot policies for allowlisting or blocking specific clients (including “good bots”)
- Acts as a standalone alternative for environments where a hosted reverse-proxy security service is not desired
Use Cases
- Protecting personal sites, forums, and small communities from aggressive AI crawler traffic
- Adding an anti-scraping layer in front of an origin server to reduce load and bandwidth costs
- Enforcing access rules for known bots and automated clients via explicit allow/deny policies
Limitations and Considerations
- Can be a disruptive (“nuclear”) approach that may block smaller scrapers and potentially useful crawlers unless explicitly allowlisted
Anubis is best suited for operators who need a self-managed, challenge-based front door for HTTP traffic and want fine control over which automated clients are permitted. When tuned with sensible policies, it can help balance discoverability with uptime protection.
Categories:
Tags:
Tech Stack:
Similar to Anubis

BunkerWeb
Open-source web application firewall and reverse proxy
BunkerWeb is an open-source WAF and NGINX-based reverse proxy to protect web apps and APIs with HTTPS automation, security policies, and extensible plugins.

SafeLine
Self-hosted WAF and reverse proxy for securing web apps
SafeLine is a self-hosted Web Application Firewall (WAF) and reverse proxy that defends web apps from SQL injection, XSS, bot abuse, and DDoS using ML-powered threat detection and configurable policies.

UUSEC WAF
Web application firewall and API security gateway (WAAP)
High-performance web application firewall and API security gateway with semantic detection, rule management, and reverse-proxy deployment for protecting websites and APIs.
NetGoat
Self-hostable reverse proxy and traffic manager with WAF features
NetGoat is a self-hostable reverse proxy and traffic management platform offering Cloudflare-like features such as TLS termination, rate limiting, WAF-style filtering, and dashboards.
SWAG
Nginx reverse proxy with automated TLS certificates and fail2ban
LinuxServer.io SWAG is a Docker image bundling Nginx reverse proxy, ACME certificate automation (Let’s Encrypt/ZeroSSL), optional PHP, and fail2ban intrusion prevention.

Pangolin
Identity-aware VPN and reverse proxy for secure remote access
Open-source identity-based remote access platform combining WireGuard VPN and tunneled reverse proxy access with granular zero-trust controls.

