Ross ROSS = Recommend OSS · open-source software intelligence for agents

wallarm/gotestwaf

An open-source project in Golang to asess different API Security tools and WAF for detection logic and bypasses observed · 2026-08-28

github.com/wallarm/gotestwaf · homepage · Go · MIT (permissive) observed · 2026-08-28

Health v2 · maintenance only

41/100

  • Activity 34
  • Release rhythm 17
  • Longevity 100
How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.

  • gap_med: 141.0
  • age_days: 2409
  • days_rel: 398
  • days_push: 398
  • n_releases_24m: 3

Full methodology

Adoption not part of the score

1799 stars · 258 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded

GoTestWAF is a Go-based tool that simulates OWASP and API attacks (SQL injection, XSS, etc.) across REST, GraphQL, gRPC, SOAP, and XMLRPC protocols to evaluate WAFs, IPS, API gateways, and API security proxies. It generates encoded malicious payloads placed in various parts of HTTP requests and produces evaluation reports on detection coverage.

Use cases

  • test how well my WAF detects OWASP attacks
  • evaluate API security proxy detection coverage before deployment
  • find bypasses in a web application firewall
  • benchmark and compare different WAF solutions
  • run regression tests against OWASP Core Rule Set
  • generate a PDF report of WAF false negatives
  • test GraphQL and gRPC security filtering

When to choose

  • you need to assess detection logic and bypass resistance of a WAF, IPS, or API gateway
  • you want protocol-specific attack testing across REST, GraphQL, gRPC, SOAP, and XMLRPC
  • you need an automated, repeatable security evaluation with reports

When to avoid

  • you need a full dynamic application security testing (DAST) scanner for your application itself
  • you want continuous runtime protection rather than point-in-time testing
  • you need a managed cloud service instead of a self-run tool

Facets

cli-tool · maturity active

penetration-testing security testing http-client security penetration-testing apis web-development windows go cli waf-testing api-security owasp attack-simulation bypass-testing security-evaluation linux macos docker

2 sources

Member repositories

RepositoryRoleHealth v2
wallarm/gotestwafmain41

For agents

markdown · JSON · MCP: product_card(name="wallarm/gotestwaf")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem