Ross ROSS = Recommend OSS · open-source software intelligence for agents

EnableSecurity/wafw00f

WAFW00F allows one to identify and fingerprint Web Application Firewall (WAF) products protecting a website. observed · 2026-08-28

github.com/EnableSecurity/wafw00f · homepage · Python · BSD-3-Clause (permissive) observed · 2026-08-28

Health v2 · maintenance only

79/100

  • Activity 78
  • Release rhythm 68
  • Longevity 100
How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.

  • gap_med: 7
  • age_days: 4494
  • days_rel: 219
  • days_push: 136
  • n_releases_24m: 6

Full methodology

Adoption not part of the score

6528 stars · 1055 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-29, confidence not recorded

WAFW00F is a Python command-line tool that identifies and fingerprints Web Application Firewall (WAF) products protecting a website. It sends normal and potentially malicious HTTP requests, then analyzes responses to deduce which WAF or security solution is in place.

Use cases

  • detect which WAF is protecting a website
  • fingerprint web application firewall products during a pentest
  • check if a site is behind Cloudflare or another security layer
  • enumerate supported WAFs before testing evasion techniques
  • identify security solutions responding to malicious HTTP requests
  • reconnaissance of a target's web defenses

When to choose

  • you need to identify a website's WAF from the command line
  • you are doing web application penetration testing reconnaissance
  • you want a mature, widely-used open-source WAF detection tool with a large signature list

When to avoid

  • you need to bypass or evade a WAF rather than detect it
  • you need a full vulnerability scanner rather than WAF fingerprinting
  • you need a GUI-based security scanning suite

Facets

cli-tool · maturity stable

security penetration-testing http-client cli security penetration-testing web-development python cli cross-platform windows waf-detection fingerprinting web-application-firewall reconnaissance pentesting command-line linux macos

6 sources

Member repositories

RepositoryRoleHealth v2
EnableSecurity/wafw00fmain79

For agents

markdown · JSON · MCP: product_card(name="EnableSecurity/wafw00f")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem