# nemesida-waf/waf-bypass

Check your WAF before an attacker does

Repository: https://github.com/nemesida-waf/waf-bypass
Canonical: https://ross.abutalabs.com/products/waf-bypass
Homepage: https://nemesida-waf.com
Language: Python
License: MIT
License Family: permissive
Topics: waf, python3, bypass, python, rce, xss, waf-bypass-tool, api-security-testing, lfi, nosql-injection, path-traversal, rfi, sqli-injection, graphql-injection, ssti, waf-testing
Last push: 2026-07-20T20:29:28+00:00

## Health v2 (maintenance only)
Score: 83/100 (v2, computed 2026-09-03T02:20:16.233290+00:00)
- activity 93, release rhythm 61, longevity 100
- inputs: {"age_days": 2265, "days_push": 44, "days_rel": 44, "gap_med": 322.5, "n_releases_24m": 3}
- flags: none
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 1520, forks 185 (observed 2026-08-28T04:04:57.694726+00:00)

## What it is
WAF Bypass Tool is an open-source Python CLI tool that tests web application firewalls for false positives and false negatives using predefined and customizable attack payloads. It is developed by the Nemesida WAF team and can be run via Docker, pipx, or directly from source.

## Use cases
- test my WAF for bypass vulnerabilities before attackers find them
- check if my WAF blocks SQL injection payloads
- verify WAF detection of XSS, SSTI, and path traversal attacks
- run automated false positive and false negative tests against a firewall
- integrate WAF security testing into a CI pipeline with JSON output
- scan a web application behind a WAF for NoSQL and GraphQL injection gaps

## When to choose
- you operate a WAF and want to validate its detection coverage
- you need automated, repeatable WAF testing with customizable payloads
- you want JSON-formatted results for integration with security platforms

## When to avoid
- you need a full vulnerability scanner for the application itself rather than the WAF
- you require exploitation capabilities beyond detection testing
- you lack authorization to test the target host

## Facets
- artifact type: cli-tool
- maturity: active
- function: penetration-testing, security, testing, http-client
- domain: security, penetration-testing, apis, developer-tools
- platform: python, cli, cross-platform
- tags: waf-testing, waf-bypass, payload-testing, api-security, false-positive-detection, false-negative-detection, docker

## Member repositories
- nemesida-waf/waf-bypass (main) score 83

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:04:57.694726+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T04:31:55.166143+00:00, confidence not recorded.
  - readme: https://github.com/nemesida-waf/waf-bypass (fetched 2026-08-28T04:04:57.694726+00:00, sha f432fa037df5)
- Data as of 2026-08-30T08:39:29.467469+00:00.
