assetnote/nowafpls
Burp Plugin to Bypass WAFs through the insertion of Junk Data observed · 2026-08-28
Health v2 · maintenance only
38/100
- Activity 31
- Release rhythm 35
- Longevity 60
Flags: no_releases no_license
How is this computed?
round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-02. Adoption (stars, forks) is never an input.
- gap_med: n/a
- age_days: 849
- days_rel: n/a
- days_push: 415
- n_releases_24m: 0
Adoption not part of the score
1502 stars · 147 forks observed · 2026-08-28
What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded
nowafpls is a Jython-based Burp Suite plugin that bypasses web application firewalls (WAFs) by inserting junk data into HTTP request bodies. It exploits the request body size limits of WAFs so that malicious payloads placed after the junk data are not inspected by the firewall.
Use cases
- bypass cloudflare waf
- bypass aws waf request body inspection
- insert junk data into http requests to evade waf
- burp suite plugin for waf bypass
- test waf request body size limits
- evade waf detection in penetration testing
- pad http post requests to skip waf inspection
When to choose
- you are performing authorized penetration testing against a WAF-protected application
- you need to test whether a WAF's request body inspection limit can be exploited
- you want a simple, lightweight Burp Suite extension for WAF evasion
- you need contextual junk data insertion for URLEncoded, XML, or JSON request bodies
When to avoid
- you are not authorized to test the target application
- you need a general-purpose web proxy or scanner rather than a WAF bypass tool
- you do not use Burp Suite or a compatible interception proxy
- the target WAF has no request body size inspection limit
Facets
plugin · maturity active
security penetration-testing plugin-system security penetration-testing web-development developer-tools python browser burp-suite waf-bypass jython web-security penetration-testing http-request-manipulation security-testing burp-extension waf request-padding
1 source
- readme: https://github.com/assetnote/nowafpls · fetched 2026-08-28 · 53997ea6b5ac
Member repositories
| Repository | Role | Health v2 |
|---|---|---|
| assetnote/nowafpls | main | 38 |
For agents
markdown · JSON · MCP: product_card(name="assetnote/nowafpls")
Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem