bunkerity/bunkerweb
🛡️ Open-source and cloud-native Web Application Firewall (WAF) observed · 2026-08-28
Health v2 · maintenance only
95/100
- Activity 99
- Release rhythm 86
- Longevity 100
How is this computed?
round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.
- gap_med: 35
- age_days: 2570
- days_rel: 12
- days_push: 7
- n_releases_24m: 18
Adoption not part of the score
10865 stars · 640 forks observed · 2026-08-28
What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-29, confidence not recorded
BunkerWeb is an open-source, cloud-native Web Application Firewall (WAF) built on NGINX that acts as a reverse proxy to protect web services, APIs, and applications. It ships 'secure by default' with bot blocking, DDoS mitigation, OWASP Top 10 protection, Let's Encrypt integration, and a web UI, deployable on Linux, Docker, Swarm, and Kubernetes.
Use cases
- protect web services behind a reverse proxy with a WAF
- block malicious bots and mitigate DDoS attacks
- secure APIs against OWASP Top 10 threats
- manage HTTPS certificates automatically with Let's Encrypt
- deploy a self-hosted web application firewall in Docker or Kubernetes
- harden NGINX-based hosting with security tuning and DNSBL filtering
When to choose
- you want an open-source, auditable WAF as a reverse proxy in front of existing services
- you deploy on Docker, Swarm, or Kubernetes and need secure-by-default configuration
- you need bot protection, rate limiting, and TLS management in a single entry point
- you prefer a web UI over hand-writing NGINX/ModSecurity configs
When to avoid
- you need a managed cloud WAF with an SLA and vendor support without self-hosting
- your stack is not HTTP/HTTPS-based (e.g., non-web protocols)
- you cannot comply with the AGPL-3.0 license in your product
- you need a lightweight edge proxy without WAF overhead
Facets
service · maturity active
security proxy http-server rate-limiting plugin-system security web-development self-hosted self-hosted python waf reverse-proxy modsecurity nginx antibot letsencrypt ddos-protection owasp devsecops web-application-firewall devops containers linux docker kubernetes web-server
4 sources
- readme: https://github.com/bunkerity/bunkerweb · fetched 2026-08-28 · 9cdde8db6886
- homepage: https://www.bunkerweb.io · fetched 2026-08-29 · 09136eb11f6d
- site_page: https://docs.bunkerweb.io/latest · fetched 2026-08-29 · 5721177a9a63
- site_page: https://www.bunkerweb.io/pricing-plan · fetched 2026-08-29 · 169dd0e3b96f
Member repositories
| Repository | Role | Health v2 |
|---|---|---|
| bunkerity/bunkerweb | main | 95 |
For agents
markdown · JSON · MCP: product_card(name="bunkerity/bunkerweb")
Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem