OWASP Coraza WAF

Mac · Linux · Self-hosted · API

Freedom report

Two barsScore 6.4

  • Free tierA free tier is on its own pricing page
  • Open codeNo open-source code on record
  • Runs widely2 of 6 device platforms
  • DocumentedPlans, terms and facts published

OWASP Coraza WAF is a free, open-source firewall for web applications and APIs. It supports ModSecurity SecLang rulesets and is described as fully compatible with the OWASP Core Rule Set. The rule set covers attacks such as SQL injection, cross-site scripting, code injection, HTTPoxy, Shellshock, and scanner or bot activity. Coraza can run as a sidecar, proxy, or library in Go, C++, and WebAssembly. Official connectors are listed for NGINX, Envoy, Caddy, Apache APISIX, proxy-wasm, HAProxy, Traefik, and libcoraza. Extensions can use audit loggers, persistence engines, operators, actions, and plugins; examples include GeoIP support and a package embedding the Core Rule Set with recommended configuration. The Quick Start requires Go 1.24 or later. Coraza supports API, Linux, macOS, and self-hosted use. Its v3 documentation notes that persistent collections such as IP, SESSION, and RESOURCE are not currently supported. Coraza Playground provides a sandbox web interface for testing rules, and the documentation points users to GitHub Discussions and the OWASP Slack community.

Who it is for

Coraza suits teams protecting APIs or web applications that want an open-source, self-hosted firewall and compatibility with ModSecurity rulesets. It may fit deployments using one of its listed connectors or runtimes.

What is good

  • Free, open-source plan.
  • Compatible with the OWASP Core Rule Set.
  • Can run as a sidecar, proxy, or library.
  • Official connectors include NGINX and Envoy.
  • Provides a sandbox for testing rules.

What to know first

  • Requires Go 1.24 or later for the Quick Start.
  • Persistent collections are not supported in Coraza v3.

Verdict

Coraza offers several deployment forms, a broad connector list, and Core Rule Set compatibility for API and web application protection. Teams needing persistent collections such as IP, SESSION, or RESOURCE should account for their current lack of support in v3.

Get started with OWASP Coraza WAF

  1. Visit https://www.coraza.io/ and review the documentation
  2. Confirm that Go 1.24 or later is available if following the Quick Start
  3. Choose a deployment as a sidecar, proxy or library in Go, C++ or WebAssembly
  4. Select an official connector for your environment, if applicable
  5. Use Coraza Playground to test rules in its sandbox web interface

What the free plan stops at

The free Open source plan is listed at 0.00 USD per free. In Coraza v3, persistent collections such as IP, SESSION and RESOURCE are currently unsupported.

Questions about OWASP Coraza WAF

How much does Coraza cost?

The Open source plan is 0.00 USD per free. Coraza is described as free and open source.

What platforms and deployment options are listed?

The listed platforms are API, Linux, macOS and self-hosted. Coraza can run as a sidecar, proxy or library in Go, C++ and WebAssembly.

Which rule sets does Coraza support?

It supports ModSecurity SecLang rulesets and is 100% compatible with the OWASP Core Rule Set.

What integrations are available?

Official connectors are listed for NGINX, Envoy, Caddy, Apache APISIX, proxy-wasm, HAProxy, Traefik and libcoraza.

What runtime does the Quick Start require?

The Quick Start lists Go 1.24 or later as a requirement.

What is the v3 limitation for persistent collections?

The internals documentation says persistent collections such as IP, SESSION and RESOURCE are currently unsupported in Coraza v3.

OWASP Coraza WAF plans and pricing

All plans
Open source Free Apache-2.0 connectors · self-hosted deployment coraza.io · 4 Oct 2026

Compared on web application firewall software

Free plan
Yes
Managed rule sets
Yes
API protection
Yes
Bot management
Yes

Best OWASP Coraza WAF alternatives

See all 20