Ross ROSS = Recommend OSS · open-source software intelligence for agents

Ekultek/WhatWaf

Detect and bypass web application firewalls and protection systems observed · 2026-08-28

github.com/Ekultek/WhatWaf · Python · NOASSERTION (other) observed · 2026-08-28

Health v2 · maintenance only

23/100

  • Activity 0
  • Release rhythm 8
  • Longevity 100

Flags: no_license

How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.

  • gap_med: n/a
  • age_days: 3183
  • days_rel: n/a
  • days_push: 753
  • n_releases_24m: 0

Full methodology

Adoption not part of the score

2924 stars · 468 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-29, confidence not recorded

WhatWaf is a Python command-line tool that detects web application firewalls (WAFs) protecting a target web application and attempts to find bypasses for them. It fingerprints dozens of known WAF products such as Cloudflare, Akamai, F5, and Barracuda.

Use cases

  • detect which WAF is protecting a website
  • find bypasses for a web application firewall
  • fingerprint firewall protection on a target URL
  • test whether my site's WAF can be evaded
  • identify WAF vendor from HTTP responses
  • penetration testing of web application protections

When to choose

  • you need to identify or fingerprint a WAF on a target web application
  • you are doing authorized penetration testing and want to test WAF evasion
  • you want a scriptable CLI for firewall detection across many known WAF products

When to avoid

  • you need a actively maintained tool with fast updates - the maintainer states updates are slow
  • you need a GUI or automated continuous WAF monitoring
  • you lack authorization to test the target - this is an offensive security tool

Facets

cli-tool · maturity maintenance

security penetration-testing http-client cli security penetration-testing web-development windows python cli waf-detection waf-bypass fingerprinting web-application-firewall offensive-security command-line linux macos

1 source

Member repositories

RepositoryRoleHealth v2
Ekultek/WhatWafmain23

For agents

markdown · JSON · MCP: product_card(name="Ekultek/WhatWaf")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem