awesome-repositories.com
Blog
MCP
awesome-repositories.com

Discover the best open-source repositories with AI-powered search.

ExploreCurated searchesOpen-source alternativesSelf-hosted softwareBlogSitemap
ProjectMCP serverAboutHow we rankPress
LegalPrivacyTerms
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
EnableSecurity avatar

EnableSecurity/wafw00f

0
View on GitHub↗
6,414 stars·1,048 forks·Python·BSD-3-Clause·15 viewswww.enablesecurity.com↗

Wafw00f

WAFW00F allows one to identify and fingerprint Web Application Firewall (WAF) products protecting a website.

Features

  • WAF Presence Verifiers - Detects WAF presence by analyzing responses to normal and malicious HTTP requests.
  • WAF Response Fingerprinters - Examines server responses to fingerprint the specific WAF technology protecting a site.
  • WAF Signature Databases - Matches request-response patterns against a library of over 200 WAF vendor signatures.
  • HTTP Baseline Comparators - Compares benign and malicious request responses to detect WAF interference.
  • WAF Block Page Matchers - Matches default WAF block page content to identify the specific firewall product.
  • WAF Header Fingerprinters - Analyzes HTTP response headers to fingerprint the specific WAF technology in use.
  • Firewall Detection Tools - Detects whether a website is protected by a WAF using normal and malicious request patterns.
  • WAF Presence Detectors - Identifies whether a website is protected by a WAF through HTTP response analysis.
  • WAF Enumeration Tools - Enumerates WAF products from a database of over 200 known vendors for security assessments.
  • WAF Reconnaissance Tools - Gathers information about web application security infrastructure during penetration testing.
  • WAF Brand Identifiers - Identifies the brand and model of WAF protecting a website through HTTP response analysis.
  • WAF Probing Payloads - Sends malicious payloads to trigger WAF-specific responses for vendor identification.
  • WAF Status Code Analyzers - Analyzes HTTP status code differences between normal and malicious requests to detect WAFs.
  • Open Source Intelligence - Fingerprinting tool for identifying web application firewall products.
  • Fingerprinting Tools - Tool for detecting and identifying WAF products.
  • Technology Fingerprinting - Identifies and fingerprints Web Application Firewalls.
  • Network and Web Reconnaissance - Fingerprints web application firewalls.
  • WAF Fingerprinting - Comprehensive tool for identifying WAF vendors and configurations.

Star history

Star history chart for enablesecurity/wafw00fStar history chart for enablesecurity/wafw00f

How this analysis was created: This summary and feature list were written by an AI model that read the project's README and public documentation pages. Each feature links to the documentation it came from; stars, license and language come straight from the GitHub API. The model does not read the source code, and the analysis is refreshed when the project is re-analysed. Learn more on our About page.

AI search

Explore more awesome repositories

Describe what you need in plain English — the AI ranks thousands of curated open-source projects by relevance.

Start searching with AI

Frequently asked questions

What does enablesecurity/wafw00f do?

WAFW00F allows one to identify and fingerprint Web Application Firewall (WAF) products protecting a website.

What are the main features of enablesecurity/wafw00f?

The main features of enablesecurity/wafw00f are: WAF Presence Verifiers, WAF Response Fingerprinters, WAF Signature Databases, HTTP Baseline Comparators, WAF Block Page Matchers, WAF Header Fingerprinters, Firewall Detection Tools, WAF Presence Detectors.

What are some open-source alternatives to enablesecurity/wafw00f?

Open-source alternatives to enablesecurity/wafw00f include: urbanadventurer/whatweb — WhatWeb is a web application fingerprinting tool that identifies the technology stack powering a website by scanning… stamparm/identywaf — Blind WAF identification tool. ekultek/whatwaf — Detect and bypass web application firewalls and protection systems. tidesec/tidefinger — TideFinger,一个开源的指纹识别小工具,使用了传统和现代检测技术相结合的指纹检测方法,让指纹检测更快捷、准确。. ultimatehackers/xsstrike — XSStrike is a security tool designed to detect cross-site scripting vulnerabilities through parameter fuzzing and web… yogeshojha/rengine — Rengine is an automated reconnaissance framework and vulnerability management platform designed for attack surface…

Open-source alternatives to Wafw00f

Similar open-source projects, ranked by how many features they share with Wafw00f.
  • urbanadventurer/whatweburbanadventurer avatar

    urbanadventurer/WhatWeb

    6,424View on GitHub↗

    WhatWeb is a web application fingerprinting tool that identifies the technology stack powering a website by scanning HTTP responses and page content. It matches responses against a library of over 1800 signatures to detect CMS platforms, JavaScript libraries, web servers, embedded devices, and third-party addons, while also extracting technical metadata such as software versions, user accounts, and module names. The tool operates through a plugin-based detection framework that supports both passive and aggressive scanning modes. Passive plugins analyze existing HTTP headers and page content w

    Rubyapplication-securityappsechacking
    View on GitHub↗6,424
  • stamparm/identywafstamparm avatar

    stamparm/identywaf

    738View on GitHub↗

    Blind WAF identification tool

    Python
    View on GitHub↗738
  • ekultek/whatwafEkultek avatar

    Ekultek/WhatWaf

    2,901View on GitHub↗

    Detect and bypass web application firewalls and protection systems

    Python
    View on GitHub↗2,901
  • tidesec/tidefingerTideSec avatar

    TideSec/TideFinger

    2,074View on GitHub↗

    TideFinger,一个开源的指纹识别小工具,使用了传统和现代检测技术相结合的指纹检测方法,让指纹检测更快捷、准确。

    Python
    View on GitHub↗2,074
See all 30 alternatives to Wafw00f→