Ross ROSS = Recommend OSS · open-source software intelligence for agents

SpiderLabs/owasp-modsecurity-crs

OWASP ModSecurity Core Rule Set (CRS) Project (Official Repository) observed · 2026-08-28

github.com/SpiderLabs/owasp-modsecurity-crs · homepage · Perl · Apache-2.0 (permissive) · archived observed · 2026-08-28

Health v2 · maintenance only

10/100

  • Activity 0
  • Release rhythm 8
  • Longevity 100

Flags: archived

How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-02. Adoption (stars, forks) is never an input.

  • gap_med: n/a
  • age_days: 5144
  • days_rel: n/a
  • days_push: 2269
  • n_releases_24m: 0

Full methodology

Adoption not part of the score

2491 stars · 726 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded

The OWASP ModSecurity Core Rule Set (CRS) is a set of generic attack detection rules for use with ModSecurity or compatible web application firewalls, protecting against the OWASP Top Ten and other attacks with minimal false positives. This original SpiderLabs repository is archived; the project has moved to github.com/coreruleset/coreruleset.

Use cases

  • protect a web application from common attacks with a WAF
  • block OWASP Top Ten vulnerabilities using ModSecurity
  • get a free starting ruleset for a web application firewall
  • reduce false positives in WAF attack detection
  • harden an nginx or Apache server with ModSecurity rules

When to choose

  • you need battle-tested generic WAF rules for ModSecurity or a compatible engine
  • you want OWASP-endorsed protection against common web attacks
  • you need a community-maintained ruleset with tuning options

When to avoid

  • you want active development - use the successor at coreruleset/coreruleset instead
  • you need a WAF engine itself rather than a ruleset
  • you run a firewall incompatible with ModSecurity rule syntax

Facets

plugin · maturity abandoned

security middleware security web-development backend self-hosted waf modsecurity owasp web-application-firewall ruleset archived moved-to-coreruleset web-server linux

1 source

Member repositories

RepositoryRoleHealth v2
SpiderLabs/owasp-modsecurity-crsmain10

For agents

markdown · JSON · MCP: product_card(name="SpiderLabs/owasp-modsecurity-crs")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem