
BunkerWeb
Open-source web application firewall and reverse proxy

BunkerWeb is a next-generation, open-source web application firewall (WAF) that runs as an NGINX-based reverse proxy in front of your web services. It aims to provide secure-by-default protection for websites, applications, and APIs while staying easy to integrate into common deployment environments.
Key Features
- Reverse proxy web server built on NGINX for fronting multiple web services
- Built-in web security hardening (TLS configuration, HTTP security headers)
- Automated HTTPS certificate management with ACME/Let’s Encrypt
- Integrated ModSecurity WAF with OWASP Core Rule Set support
- Rate limiting and request/connection limiting to reduce abuse
- Automatic banning based on suspicious behavior and HTTP status patterns
- Bot protection with challenge mechanisms (for example JavaScript, cookie, CAPTCHA)
- IP reputation blocking via external lists and DNSBL
- Extensible plugin system for adding or customizing security capabilities
- Optional web UI for managing instances and configuration
Use Cases
- Protecting self-hosted websites and web apps behind a hardened reverse proxy
- Shielding APIs from common web attacks, abusive clients, and automated bots
- Standardizing HTTPS/TLS and baseline security policies across environments
Limitations and Considerations
- Some advanced capabilities are reserved for the commercial PRO offering
- As with any WAF, effective protection requires careful tuning to minimize false positives
BunkerWeb is a strong fit when you want an auditable, configurable WAF that can be deployed across Linux, containers, and Kubernetes. Its secure-by-default approach, NGINX foundation, and plugin model make it suitable for both homelabs and production environments.
Categories:
Tags:
Tech Stack:
Similar Services

Pi-hole
Network-wide DNS sinkhole for ad and tracker blocking
Pi-hole is a network-wide DNS sinkhole that blocks ads and trackers for all devices on your network, with a web dashboard, query logs, and optional DHCP server.


Headscale
Self-hosted control server for Tailscale-based WireGuard networks
Headscale is an open source, self-hosted implementation of the Tailscale control server for managing a private tailnet, nodes, keys, IPs, and routes.

AdGuard Home
Network-wide DNS server that blocks ads, trackers, phishing and malware
Open-source DNS-based ad & tracker blocking server for networks. Offers per-device rules, parental controls, encrypted upstream DNS (DoH/DoT/DNSCrypt), web UI and API.

Web-Check
All-in-one OSINT tool for analyzing any website.
Comprehensive on-demand OSINT to analyze a website's security, architecture, and tech stack.

wg-easy
WireGuard VPN server with a web-based admin interface
Run a WireGuard VPN server with an easy web admin UI to manage clients, generate configs and QR codes, and monitor connections and traffic.

NetBird
WireGuard-based overlay network with SSO/MFA and granular access controls.
Open-source zero-trust networking platform delivering a WireGuard-based private network with centralized access control, SSO/MFA, and cross-platform clients.


