Ross ROSS = Recommend OSS · open-source software intelligence for agents

openappsec/openappsec

open-appsec is a machine learning security engine that preemptively and automatically prevents threats against Web Application & APIs. This repo include the main code and logic. observed · 2026-08-28

github.com/openappsec/openappsec · homepage · C++ · Apache-2.0 (permissive) observed · 2026-08-28

Health v2 · maintenance only

99/100

  • Activity 99
  • Release rhythm 99
  • Longevity 100
How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-02. Adoption (stars, forks) is never an input.

  • gap_med: 30
  • age_days: 1407
  • days_rel: 8
  • days_push: 7
  • n_releases_24m: 18

Full methodology

Adoption not part of the score

1689 stars · 133 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded

open-appsec is an open-source machine learning security engine that provides preemptive web application and API threat protection against OWASP-Top-10 and zero-day attacks. It deploys as an add-on to Linux, Docker, or Kubernetes environments on NGINX, Kong, APISIX, or Envoy, using supervised and unsupervised ML models to score and block malicious HTTP requests.

Use cases

  • protect web applications from OWASP Top 10 attacks
  • prevent zero-day API attacks without signature updates
  • add a machine learning WAF to NGINX or Kong
  • secure Kubernetes ingress traffic
  • block malicious HTTP requests automatically based on learned traffic patterns
  • monitor and test web app security in monitor-only mode

When to choose

  • you need a modern ML-based WAF integrated into NGINX, Kong, APISIX, or Envoy
  • you want preemptive zero-day protection without maintaining signature rules
  • you run Linux, Docker, or Kubernetes and want declarative or Kubernetes CRD-based security configuration
  • you prefer an open-source alternative to commercial WAFs

When to avoid

  • you need a network-layer firewall or DDoS mitigation rather than HTTP-layer protection
  • you cannot rely on downloading the advanced production model from the vendor portal
  • your stack is not NGINX, Kong, APISIX, or Envoy based
  • you need a fully offline solution with no external model updates

Facets

library · maturity active

security machine-learning rate-limiting middleware http-server security web-development apis machine-learning self-hosted waf api-security owasp-top-ten zero-day-protection threat-prevention kong envoy apisix devsecops appsec devops linux docker kubernetes nginx

2 sources

Member repositories

RepositoryRoleHealth v2
openappsec/openappsecmain99

For agents

markdown · JSON · MCP: product_card(name="openappsec/openappsec")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem