Ross ROSS = Recommend OSS · open-source software intelligence for agents

bunkerity/bunkerweb

🛡️ Open-source and cloud-native Web Application Firewall (WAF) observed · 2026-08-28

github.com/bunkerity/bunkerweb · homepage · Python · AGPL-3.0 (copyleft) observed · 2026-08-28

Health v2 · maintenance only

95/100

  • Activity 99
  • Release rhythm 86
  • Longevity 100
How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.

  • gap_med: 35
  • age_days: 2570
  • days_rel: 12
  • days_push: 7
  • n_releases_24m: 18

Full methodology

Adoption not part of the score

10865 stars · 640 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-29, confidence not recorded

BunkerWeb is an open-source, cloud-native Web Application Firewall (WAF) built on NGINX that acts as a reverse proxy to protect web services, APIs, and applications. It ships 'secure by default' with bot blocking, DDoS mitigation, OWASP Top 10 protection, Let's Encrypt integration, and a web UI, deployable on Linux, Docker, Swarm, and Kubernetes.

Use cases

  • protect web services behind a reverse proxy with a WAF
  • block malicious bots and mitigate DDoS attacks
  • secure APIs against OWASP Top 10 threats
  • manage HTTPS certificates automatically with Let's Encrypt
  • deploy a self-hosted web application firewall in Docker or Kubernetes
  • harden NGINX-based hosting with security tuning and DNSBL filtering

When to choose

  • you want an open-source, auditable WAF as a reverse proxy in front of existing services
  • you deploy on Docker, Swarm, or Kubernetes and need secure-by-default configuration
  • you need bot protection, rate limiting, and TLS management in a single entry point
  • you prefer a web UI over hand-writing NGINX/ModSecurity configs

When to avoid

  • you need a managed cloud WAF with an SLA and vendor support without self-hosting
  • your stack is not HTTP/HTTPS-based (e.g., non-web protocols)
  • you cannot comply with the AGPL-3.0 license in your product
  • you need a lightweight edge proxy without WAF overhead

Facets

service · maturity active

security proxy http-server rate-limiting plugin-system security web-development self-hosted self-hosted python waf reverse-proxy modsecurity nginx antibot letsencrypt ddos-protection owasp devsecops web-application-firewall devops containers linux docker kubernetes web-server

4 sources

Member repositories

RepositoryRoleHealth v2
bunkerity/bunkerwebmain95

For agents

markdown · JSON · MCP: product_card(name="bunkerity/bunkerweb")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem