{"adoption": {"forks": 185, "observed_at": "2026-08-28T04:04:57.694726+00:00", "stars": 1520}, "canonical_url": "https://ross.abutalabs.com/products/waf-bypass", "card": {"archived": false, "artifact_type": "cli-tool", "description": "Check your WAF before an attacker does", "domain": ["security", "penetration-testing", "apis", "developer-tools"], "enriched": true, "function": ["penetration-testing", "security", "testing", "http-client"], "health_score": 96, "homepage": "https://nemesida-waf.com", "language": "Python", "license": "MIT", "license_family": "permissive", "maturity": "active", "member_repos": ["nemesida-waf/waf-bypass"], "name": "nemesida-waf/waf-bypass", "platform": ["python", "cli", "cross-platform"], "pushed_at": "2026-07-20T20:29:28+00:00", "repo": "nemesida-waf/waf-bypass", "stars": 1520, "tags": ["waf-testing", "waf-bypass", "payload-testing", "api-security", "false-positive-detection", "false-negative-detection", "docker"], "topics": ["waf", "python3", "bypass", "python", "rce", "xss", "waf-bypass-tool", "api-security-testing", "lfi", "nosql-injection", "path-traversal", "rfi", "sqli-injection", "graphql-injection", "ssti", "waf-testing"], "urls": [], "use_cases": ["test my WAF for bypass vulnerabilities before attackers find them", "check if my WAF blocks SQL injection payloads", "verify WAF detection of XSS, SSTI, and path traversal attacks", "run automated false positive and false negative tests against a firewall", "integrate WAF security testing into a CI pipeline with JSON output", "scan a web application behind a WAF for NoSQL and GraphQL injection gaps"], "what_it_is": "WAF Bypass Tool is an open-source Python CLI tool that tests web application firewalls for false positives and false negatives using predefined and customizable attack payloads. It is developed by the Nemesida WAF team and can be run via Docker, pipx, or directly from source.", "when_to_avoid": ["you need a full vulnerability scanner for the application itself rather than the WAF", "you require exploitation capabilities beyond detection testing", "you lack authorization to test the target host"], "when_to_choose": ["you operate a WAF and want to validate its detection coverage", "you need automated, repeatable WAF testing with customizable payloads", "you want JSON-formatted results for integration with security platforms"]}, "data_as_of": "2026-08-30T08:39:29.467469+00:00", "members": [{"path": "/products/waf-bypass", "repo": "nemesida-waf/waf-bypass", "role": "main", "score": 83}], "provenance": {"archived": {"kind": "observed", "observed_at": "2026-08-28T04:04:57.694726+00:00", "source": "github"}, "artifact_type": {"confidence": null, "enriched_at": "2026-08-30T04:31:55.166143+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "f432fa037df5d298da456b369523e0e0d4d493c2dbeacf682183b8fc361dab07", "fetched_at": "2026-08-28T04:04:57.694726+00:00", "kind": "readme", "missing": false, "url": "https://github.com/nemesida-waf/waf-bypass"}], "taxonomy_version": 1}, "description": {"kind": "observed", "observed_at": "2026-08-28T04:04:57.694726+00:00", "source": "github"}, "domain": {"confidence": null, "enriched_at": "2026-08-30T04:31:55.166143+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "f432fa037df5d298da456b369523e0e0d4d493c2dbeacf682183b8fc361dab07", "fetched_at": "2026-08-28T04:04:57.694726+00:00", "kind": "readme", "missing": false, "url": "https://github.com/nemesida-waf/waf-bypass"}], "taxonomy_version": 1}, "enriched": {"inputs": [], "kind": "computed", "method": "enrichment_status"}, "function": {"confidence": null, "enriched_at": "2026-08-30T04:31:55.166143+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "f432fa037df5d298da456b369523e0e0d4d493c2dbeacf682183b8fc361dab07", "fetched_at": "2026-08-28T04:04:57.694726+00:00", "kind": "readme", "missing": false, "url": "https://github.com/nemesida-waf/waf-bypass"}], "taxonomy_version": 1}, "health_score": {"inputs": ["days_since_push", "days_since_release", "archived"], "kind": "computed", "method": "health_v1"}, "homepage": {"kind": "observed", "observed_at": "2026-08-28T04:04:57.694726+00:00", "source": "github"}, "language": {"kind": "observed", "observed_at": "2026-08-28T04:04:57.694726+00:00", "source": "github"}, "license": {"kind": "observed", "observed_at": "2026-08-28T04:04:57.694726+00:00", "source": "github"}, "license_family": {"inputs": ["license"], "kind": "computed", "method": "license_family"}, "maturity": {"confidence": null, "enriched_at": "2026-08-30T04:31:55.166143+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "f432fa037df5d298da456b369523e0e0d4d493c2dbeacf682183b8fc361dab07", "fetched_at": "2026-08-28T04:04:57.694726+00:00", "kind": "readme", "missing": false, "url": "https://github.com/nemesida-waf/waf-bypass"}], "taxonomy_version": 1}, "member_repos": {"kind": "observed", "observed_at": "2026-08-28T04:04:57.694726+00:00", "source": "github"}, "name": {"kind": "observed", "observed_at": "2026-08-28T04:04:57.694726+00:00", "source": "github"}, "platform": {"confidence": null, "enriched_at": "2026-08-30T04:31:55.166143+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "f432fa037df5d298da456b369523e0e0d4d493c2dbeacf682183b8fc361dab07", "fetched_at": "2026-08-28T04:04:57.694726+00:00", "kind": "readme", "missing": false, "url": "https://github.com/nemesida-waf/waf-bypass"}], "taxonomy_version": 1}, "pushed_at": {"kind": "observed", "observed_at": "2026-08-28T04:04:57.694726+00:00", "source": "github"}, "repo": {"kind": "observed", "observed_at": "2026-08-28T04:04:57.694726+00:00", "source": "github"}, "stars": {"kind": "observed", "observed_at": "2026-08-28T04:04:57.694726+00:00", "source": "github"}, "tags": {"confidence": null, "enriched_at": "2026-08-30T04:31:55.166143+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "f432fa037df5d298da456b369523e0e0d4d493c2dbeacf682183b8fc361dab07", "fetched_at": "2026-08-28T04:04:57.694726+00:00", "kind": "readme", "missing": false, "url": "https://github.com/nemesida-waf/waf-bypass"}], "taxonomy_version": 1}, "topics": {"kind": "observed", "observed_at": "2026-08-28T04:04:57.694726+00:00", "source": "github"}, "urls": {"kind": "observed", "observed_at": "2026-08-28T04:04:57.694726+00:00", "source": "github"}, "use_cases": {"confidence": null, "enriched_at": "2026-08-30T04:31:55.166143+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "f432fa037df5d298da456b369523e0e0d4d493c2dbeacf682183b8fc361dab07", "fetched_at": "2026-08-28T04:04:57.694726+00:00", "kind": "readme", "missing": false, "url": "https://github.com/nemesida-waf/waf-bypass"}], "taxonomy_version": 1}, "what_it_is": {"confidence": null, "enriched_at": "2026-08-30T04:31:55.166143+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "f432fa037df5d298da456b369523e0e0d4d493c2dbeacf682183b8fc361dab07", "fetched_at": "2026-08-28T04:04:57.694726+00:00", "kind": "readme", "missing": false, "url": "https://github.com/nemesida-waf/waf-bypass"}], "taxonomy_version": 1}, "when_to_avoid": {"confidence": null, "enriched_at": "2026-08-30T04:31:55.166143+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "f432fa037df5d298da456b369523e0e0d4d493c2dbeacf682183b8fc361dab07", "fetched_at": "2026-08-28T04:04:57.694726+00:00", "kind": "readme", "missing": false, "url": "https://github.com/nemesida-waf/waf-bypass"}], "taxonomy_version": 1}, "when_to_choose": {"confidence": null, "enriched_at": "2026-08-30T04:31:55.166143+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "f432fa037df5d298da456b369523e0e0d4d493c2dbeacf682183b8fc361dab07", "fetched_at": "2026-08-28T04:04:57.694726+00:00", "kind": "readme", "missing": false, "url": "https://github.com/nemesida-waf/waf-bypass"}], "taxonomy_version": 1}}, "score": {"components": {"activity": 93, "longevity": 100, "rhythm": 61}, "computed_at": "2026-09-03T02:20:16.233290+00:00", "flags": [], "formula": "round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)", "inputs": {"age_days": 2265, "days_push": 44, "days_rel": 44, "gap_med": 322.5, "n_releases_24m": 3}, "score": 83, "version": 2}, "staleness": {"enrichment_outdated": false, "low_confidence": false, "scrape_days": 9, "stale_scrape": false}}