Ross ROSS = Recommend OSS · open-source software intelligence for agents

nemesida-waf/waf-bypass

Check your WAF before an attacker does observed · 2026-08-28

github.com/nemesida-waf/waf-bypass · homepage · Python · MIT (permissive) observed · 2026-08-28

Health v2 · maintenance only

83/100

  • Activity 93
  • Release rhythm 61
  • Longevity 100
How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.

  • gap_med: 322.5
  • age_days: 2265
  • days_rel: 44
  • days_push: 44
  • n_releases_24m: 3

Full methodology

Adoption not part of the score

1520 stars · 185 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded

WAF Bypass Tool is an open-source Python CLI tool that tests web application firewalls for false positives and false negatives using predefined and customizable attack payloads. It is developed by the Nemesida WAF team and can be run via Docker, pipx, or directly from source.

Use cases

  • test my WAF for bypass vulnerabilities before attackers find them
  • check if my WAF blocks SQL injection payloads
  • verify WAF detection of XSS, SSTI, and path traversal attacks
  • run automated false positive and false negative tests against a firewall
  • integrate WAF security testing into a CI pipeline with JSON output
  • scan a web application behind a WAF for NoSQL and GraphQL injection gaps

When to choose

  • you operate a WAF and want to validate its detection coverage
  • you need automated, repeatable WAF testing with customizable payloads
  • you want JSON-formatted results for integration with security platforms

When to avoid

  • you need a full vulnerability scanner for the application itself rather than the WAF
  • you require exploitation capabilities beyond detection testing
  • you lack authorization to test the target host

Facets

cli-tool · maturity active

penetration-testing security testing http-client security penetration-testing apis developer-tools python cli cross-platform waf-testing waf-bypass payload-testing api-security false-positive-detection false-negative-detection docker

1 source

Member repositories

RepositoryRoleHealth v2
nemesida-waf/waf-bypassmain83

For agents

markdown · JSON · MCP: product_card(name="nemesida-waf/waf-bypass")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem