# SpiderLabs/owasp-modsecurity-crs

OWASP ModSecurity Core Rule Set (CRS) Project (Official Repository)

Repository: https://github.com/SpiderLabs/owasp-modsecurity-crs
Canonical: https://ross.abutalabs.com/products/owasp-modsecurity-crs
Homepage: https://modsecurity.org/crs
Language: Perl
License: Apache-2.0
License Family: permissive
Archived: true
Last push: 2020-06-16T12:32:12+00:00

## Health v2 (maintenance only)
Score: 10/100 (v2, computed 2026-09-02T17:46:02.011165+00:00)
- activity 0, release rhythm 8, longevity 100
- inputs: {"age_days": 5144, "days_push": 2269, "days_rel": null, "gap_med": null, "n_releases_24m": 0}
- flags: archived
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 2491, forks 726 (observed 2026-08-28T04:06:56.391190+00:00)

## What it is
The OWASP ModSecurity Core Rule Set (CRS) is a set of generic attack detection rules for use with ModSecurity or compatible web application firewalls, protecting against the OWASP Top Ten and other attacks with minimal false positives. This original SpiderLabs repository is archived; the project has moved to github.com/coreruleset/coreruleset.

## Use cases
- protect a web application from common attacks with a WAF
- block OWASP Top Ten vulnerabilities using ModSecurity
- get a free starting ruleset for a web application firewall
- reduce false positives in WAF attack detection
- harden an nginx or Apache server with ModSecurity rules

## When to choose
- you need battle-tested generic WAF rules for ModSecurity or a compatible engine
- you want OWASP-endorsed protection against common web attacks
- you need a community-maintained ruleset with tuning options

## When to avoid
- you want active development - use the successor at coreruleset/coreruleset instead
- you need a WAF engine itself rather than a ruleset
- you run a firewall incompatible with ModSecurity rule syntax

## Facets
- artifact type: plugin
- maturity: abandoned
- function: security, middleware
- domain: security, web-development, backend
- platform: self-hosted
- tags: waf, modsecurity, owasp, web-application-firewall, ruleset, archived, moved-to-coreruleset, web-server, linux

## Member repositories
- SpiderLabs/owasp-modsecurity-crs (main) score 10

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:06:56.391190+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T02:27:47.023773+00:00, confidence not recorded.
  - readme: https://github.com/SpiderLabs/owasp-modsecurity-crs (fetched 2026-08-28T04:06:56.391190+00:00, sha 8bdabe8d8377)
- Data as of 2026-08-30T08:39:29.467469+00:00.
