nemesida-waf/waf-bypass
Check your WAF before an attacker does observed · 2026-08-28
Health v2 · maintenance only
83/100
- Activity 93
- Release rhythm 61
- Longevity 100
How is this computed?
round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.
- gap_med: 322.5
- age_days: 2265
- days_rel: 44
- days_push: 44
- n_releases_24m: 3
Adoption not part of the score
1520 stars · 185 forks observed · 2026-08-28
What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded
WAF Bypass Tool is an open-source Python CLI tool that tests web application firewalls for false positives and false negatives using predefined and customizable attack payloads. It is developed by the Nemesida WAF team and can be run via Docker, pipx, or directly from source.
Use cases
- test my WAF for bypass vulnerabilities before attackers find them
- check if my WAF blocks SQL injection payloads
- verify WAF detection of XSS, SSTI, and path traversal attacks
- run automated false positive and false negative tests against a firewall
- integrate WAF security testing into a CI pipeline with JSON output
- scan a web application behind a WAF for NoSQL and GraphQL injection gaps
When to choose
- you operate a WAF and want to validate its detection coverage
- you need automated, repeatable WAF testing with customizable payloads
- you want JSON-formatted results for integration with security platforms
When to avoid
- you need a full vulnerability scanner for the application itself rather than the WAF
- you require exploitation capabilities beyond detection testing
- you lack authorization to test the target host
Facets
cli-tool · maturity active
penetration-testing security testing http-client security penetration-testing apis developer-tools python cli cross-platform waf-testing waf-bypass payload-testing api-security false-positive-detection false-negative-detection docker
1 source
- readme: https://github.com/nemesida-waf/waf-bypass · fetched 2026-08-28 · f432fa037df5
Member repositories
| Repository | Role | Health v2 |
|---|---|---|
| nemesida-waf/waf-bypass | main | 83 |
For agents
markdown · JSON · MCP: product_card(name="nemesida-waf/waf-bypass")
Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem