Ross ROSS = Recommend OSS · open-source software intelligence for agents

assetnote/nowafpls

Burp Plugin to Bypass WAFs through the insertion of Junk Data observed · 2026-08-28

github.com/assetnote/nowafpls · Python observed · 2026-08-28

Health v2 · maintenance only

38/100

  • Activity 31
  • Release rhythm 35
  • Longevity 60

Flags: no_releases no_license

How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-02. Adoption (stars, forks) is never an input.

  • gap_med: n/a
  • age_days: 849
  • days_rel: n/a
  • days_push: 415
  • n_releases_24m: 0

Full methodology

Adoption not part of the score

1502 stars · 147 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded

nowafpls is a Jython-based Burp Suite plugin that bypasses web application firewalls (WAFs) by inserting junk data into HTTP request bodies. It exploits the request body size limits of WAFs so that malicious payloads placed after the junk data are not inspected by the firewall.

Use cases

  • bypass cloudflare waf
  • bypass aws waf request body inspection
  • insert junk data into http requests to evade waf
  • burp suite plugin for waf bypass
  • test waf request body size limits
  • evade waf detection in penetration testing
  • pad http post requests to skip waf inspection

When to choose

  • you are performing authorized penetration testing against a WAF-protected application
  • you need to test whether a WAF's request body inspection limit can be exploited
  • you want a simple, lightweight Burp Suite extension for WAF evasion
  • you need contextual junk data insertion for URLEncoded, XML, or JSON request bodies

When to avoid

  • you are not authorized to test the target application
  • you need a general-purpose web proxy or scanner rather than a WAF bypass tool
  • you do not use Burp Suite or a compatible interception proxy
  • the target WAF has no request body size inspection limit

Facets

plugin · maturity active

security penetration-testing plugin-system security penetration-testing web-development developer-tools python browser burp-suite waf-bypass jython web-security penetration-testing http-request-manipulation security-testing burp-extension waf request-padding

1 source

Member repositories

RepositoryRoleHealth v2
assetnote/nowafplsmain38

For agents

markdown · JSON · MCP: product_card(name="assetnote/nowafpls")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem