SafeLine logo

SafeLine

Website

Self-hosted WAF and reverse proxy for securing web apps

22.4k stars 1.5k forks last commit first released GPL-3.0

Actively maintained

Last commit 26 Aug 2026.

SafeLine screenshot

SafeLine is a self-hosted Web Application Firewall (WAF) that sits in front of web apps to filter and monitor HTTP/S traffic, protecting against common web attacks. It also functions as a reverse proxy with ML-powered threat detection and modular, policy-driven protection.

Key Features

  • Intelligent protection engine powered by machine learning with high detection rates and very low false positives
  • Bot protection with CAPTCHA challenges and anti-replay protection
  • HTTP Flood DDoS protection through intelligent traffic orchestration and rate limiting
  • Identity and Access Management for on-prem and cloud apps via standard protocols and flexible integration
  • Nginx-based reverse proxy architecture that shields web apps from the Internet

Use Cases

  • E-commerce & Payment Platforms: protects merchant sites with real-time bot detection and traffic analysis, aiming to maintain availability during peak periods
  • SaaS & Cloud Platforms: protects REST and GraphQL APIs from common web threats with ML-powered anomaly detection
  • Content & Media Services: guards against high-frequency attacks and content scraping, with geo-based access controls for copyright compliance

Conclusion

SafeLine is a production-ready, self-hosted WAF with a broad user base and open community. It provides enterprise-grade protection for web applications, APIs, and services through ML-powered threat detection and flexible deployment options.

Categories:

Tags:

Tech Stack:

Share:

Similar to SafeLine

Anubis

Web AI firewall utility that challenges and blocks scraper bots

21.7k
693
Last commit

Anubis is a lightweight web AI firewall that protects sites from AI crawlers and scraping bots using configurable request challenges and bot policies.

MITActively maintained
Alternative to:
Cloudflare Web Application Firewall (WAF) logo
Cloudflare Web Application Firewall (WAF)
+10
BunkerWeb logo

BunkerWeb

Open-source web application firewall and reverse proxy

10.9k
640
Last commit

BunkerWeb is an open-source WAF and NGINX-based reverse proxy to protect web apps and APIs with HTTPS automation, security policies, and extensible plugins.

AGPL-3.0Actively maintained
Alternative to:
Cloudflare Web Application Firewall (WAF) logo
Cloudflare Web Application Firewall (WAF)
+10
CrowdSec logo

CrowdSec

Crowdsourced IDS/IPS and WAF with shared malicious IP intelligence

14.7k
710
Last commit

CrowdSec is an open-source security engine that detects attacks from logs and blocks malicious IPs using bouncers and community-curated threat intelligence.

MITActively maintained
Alternative to:
Fail2Ban logo
Fail2Ban
+10
UUSEC WAF logo

UUSEC WAF

Web application firewall and API security gateway (WAAP)

1.7k
170
Last commit

High-performance web application firewall and API security gateway with semantic detection, rule management, and reverse-proxy deployment for protecting websites and APIs.

BSD-2-ClauseActively maintained
Alternative to:
Cloudflare Web Application Firewall (WAF) logo
Cloudflare Web Application Firewall (WAF)
+9
Cap logo

Cap

Privacy-first proof-of-work CAPTCHA alternative for web and APIs

7.6k
551
Last commit

Lightweight, self-hostable CAPTCHA alternative using SHA-256 proof-of-work challenges to protect forms and APIs from bots without tracking or visual puzzles.

Actively maintained
Alternative to:
Google reCAPTCHA logo
Google reCAPTCHA
+8
SWAG logo

SWAG

Nginx reverse proxy with automated TLS certificates and fail2ban

3.7k
276
Last commit

LinuxServer.io SWAG is a Docker image bundling Nginx reverse proxy, ACME certificate automation (Let’s Encrypt/ZeroSSL), optional PHP, and fail2ban intrusion prevention.

GPL-3.0Actively maintained
Alternative to:
Apache HTTP Server logo
Apache HTTP Server
+9