SafeLine

SafeLine

Self-hosted WAF for protecting web apps and APIs

20kstars
1.3kforks
Last commit: 2mo ago
Repo age: 3y old
SafeLine screenshot

SafeLine is an open-source Web Application Firewall (WAF) by Chaitin Technology designed to protect web applications and APIs by inspecting HTTP(S) traffic and blocking malicious requests. It is typically deployed in front of your apps as a reverse proxy/gateway and provides a management UI for configuring protected sites and security policies.

Key Features

  • Reverse-proxy WAF deployment in front of web apps and APIs
  • Protection against common web attacks (e.g., SQL injection, XSS, path traversal, command injection)
  • Rule/policy-based request inspection and blocking for HTTP traffic
  • Web console for configuring sites, policies, and viewing security events
  • Access logs and security event visibility to aid investigation and tuning
  • Containerized deployment (commonly via Docker/Docker Compose)

Use Cases

  • Protect a self-hosted website or admin panel from automated scans and exploit attempts
  • Add a security layer in front of internal business apps exposed to the internet
  • Shield API endpoints from injection attacks and suspicious request patterns

Limitations and Considerations

  • As with most WAFs, tuning policies may be required to reduce false positives for complex applications
  • Advanced enterprise features (e.g., large-scale centralized management) may not be present depending on the edition

SafeLine fits teams that want a deployable, self-managed WAF to reduce exposure to common web threats. It is especially useful when placed at the edge in front of multiple services to standardize inbound traffic inspection and blocking.

Categories:

Tags:

Tech Stack:

Share:

Similar Services

Pi-hole

Pi-hole

Network-wide ad blocking via DNS sinkhole

55.2k
3k
Last commit: 1mo ago

DNS sinkhole that blocks ads, trackers, and malicious domains network-wide with a web dashboard, per-client controls, and optional DHCP/DNS features.

Alternative to:
NextDNS
NextDNS
+1
CyberChef

CyberChef

The Cyber Swiss Army Knife for data analysis and decoding

33.7k
3.8k
Last commit: 5mo ago

Browser-based tool for decoding, encoding, encryption, and data analysis using a drag-and-drop “recipe” workflow for security, DFIR, and engineering tasks.

Alternative to:
CrackStation (online hash cracking/lookup)
CrackStation (online hash cracking/lookup)
+4
AdGuard Home

AdGuard Home

Network-wide ads and tracker blocking via DNS

32k
2.2k
Last commit: 14d ago

Self-hosted DNS server with ad/tracker blocking, custom filtering, parental controls, encrypted DNS, and per-client statistics for home networks.

Alternative to:
NextDNS
NextDNS
+1
Nginx Proxy Manager

Nginx Proxy Manager

Web UI for Nginx reverse proxy with Let's Encrypt SSL

30.9k
3.5k
Last commit: 1mo ago

Web-based reverse proxy manager for Nginx with hosts, streams, access lists, and automatic Let's Encrypt certificates via an easy admin UI.

Alternative to:
NGINX Plus
NGINX Plus
+5
Teleport

Teleport

Identity-native infrastructure access for SSH, Kubernetes, RDP and DBs

19.6k
2k
Last commit: 1d ago

Open-source platform that provides unified, audited, identity-based access to servers, Kubernetes clusters, databases, and desktops without static credentials.

Alternative to:
Okta Advanced Server Access
Okta Advanced Server Access
+2
Pangolin

Pangolin

Self-hosted secure tunneling and access gateway

17.8k
529
Last commit: 4d ago

Pangolin provides a self-hosted access gateway for securely exposing internal apps via tunnels, with identity-aware access controls and a web UI.

Alternative to:
Cloudflare SSL/TLS and reverse proxy features
Cloudflare SSL/TLS and reverse proxy features
+3