
SafeLine
Self-hosted WAF and reverse proxy for securing web apps
22.4k stars 1.5k forks last commit first released GPL-3.0
Actively maintained
Last commit 26 Aug 2026.

SafeLine is a self-hosted Web Application Firewall (WAF) that sits in front of web apps to filter and monitor HTTP/S traffic, protecting against common web attacks. It also functions as a reverse proxy with ML-powered threat detection and modular, policy-driven protection.
Key Features
- Intelligent protection engine powered by machine learning with high detection rates and very low false positives
- Bot protection with CAPTCHA challenges and anti-replay protection
- HTTP Flood DDoS protection through intelligent traffic orchestration and rate limiting
- Identity and Access Management for on-prem and cloud apps via standard protocols and flexible integration
- Nginx-based reverse proxy architecture that shields web apps from the Internet
Use Cases
- E-commerce & Payment Platforms: protects merchant sites with real-time bot detection and traffic analysis, aiming to maintain availability during peak periods
- SaaS & Cloud Platforms: protects REST and GraphQL APIs from common web threats with ML-powered anomaly detection
- Content & Media Services: guards against high-frequency attacks and content scraping, with geo-based access controls for copyright compliance
Conclusion
SafeLine is a production-ready, self-hosted WAF with a broad user base and open community. It provides enterprise-grade protection for web applications, APIs, and services through ML-powered threat detection and flexible deployment options.
Categories:
Tags:
Tech Stack:
Similar to SafeLine
Anubis
Web AI firewall utility that challenges and blocks scraper bots
Anubis is a lightweight web AI firewall that protects sites from AI crawlers and scraping bots using configurable request challenges and bot policies.

BunkerWeb
Open-source web application firewall and reverse proxy
BunkerWeb is an open-source WAF and NGINX-based reverse proxy to protect web apps and APIs with HTTPS automation, security policies, and extensible plugins.
CrowdSec
Crowdsourced IDS/IPS and WAF with shared malicious IP intelligence
CrowdSec is an open-source security engine that detects attacks from logs and blocks malicious IPs using bouncers and community-curated threat intelligence.

UUSEC WAF
Web application firewall and API security gateway (WAAP)
High-performance web application firewall and API security gateway with semantic detection, rule management, and reverse-proxy deployment for protecting websites and APIs.

Cap
Privacy-first proof-of-work CAPTCHA alternative for web and APIs
Lightweight, self-hostable CAPTCHA alternative using SHA-256 proof-of-work challenges to protect forms and APIs from bots without tracking or visual puzzles.

SWAG
Nginx reverse proxy with automated TLS certificates and fail2ban
LinuxServer.io SWAG is a Docker image bundling Nginx reverse proxy, ACME certificate automation (Let’s Encrypt/ZeroSSL), optional PHP, and fail2ban intrusion prevention.
