EnableSecurity/wafw00f
WAFW00F allows one to identify and fingerprint Web Application Firewall (WAF) products protecting a website. observed · 2026-08-28
Health v2 · maintenance only
79/100
- Activity 78
- Release rhythm 68
- Longevity 100
How is this computed?
round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.
- gap_med: 7
- age_days: 4494
- days_rel: 219
- days_push: 136
- n_releases_24m: 6
Adoption not part of the score
6528 stars · 1055 forks observed · 2026-08-28
What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-29, confidence not recorded
WAFW00F is a Python command-line tool that identifies and fingerprints Web Application Firewall (WAF) products protecting a website. It sends normal and potentially malicious HTTP requests, then analyzes responses to deduce which WAF or security solution is in place.
Use cases
- detect which WAF is protecting a website
- fingerprint web application firewall products during a pentest
- check if a site is behind Cloudflare or another security layer
- enumerate supported WAFs before testing evasion techniques
- identify security solutions responding to malicious HTTP requests
- reconnaissance of a target's web defenses
When to choose
- you need to identify a website's WAF from the command line
- you are doing web application penetration testing reconnaissance
- you want a mature, widely-used open-source WAF detection tool with a large signature list
When to avoid
- you need to bypass or evade a WAF rather than detect it
- you need a full vulnerability scanner rather than WAF fingerprinting
- you need a GUI-based security scanning suite
Facets
cli-tool · maturity stable
security penetration-testing http-client cli security penetration-testing web-development python cli cross-platform windows waf-detection fingerprinting web-application-firewall reconnaissance pentesting command-line linux macos
6 sources
- readme: https://github.com/EnableSecurity/wafw00f · fetched 2026-08-28 · 2f9255e0e14e
- homepage: https://www.enablesecurity.com/ · fetched 2026-08-29 · 2644e4c149e7
- site_page: https://www.enablesecurity.com/about · fetched 2026-08-29 · 7df63bd5a452
- registry_pypi: https://pypi.org/pypi/wafw00f/json · fetched 2026-08-29 · 06e2c99fd9f1
- site_page: https://www.enablesecurity.com/sipvicious · fetched 2026-08-29 · 041876013773
- site_page: https://www.enablesecurity.com/consultancy · fetched 2026-08-29 · 2b0e78873c70
Member repositories
| Repository | Role | Health v2 |
|---|---|---|
| EnableSecurity/wafw00f | main | 79 |
For agents
markdown · JSON · MCP: product_card(name="EnableSecurity/wafw00f")
Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem