Wafris – an Open Source Web Application Firewall that lives in your stack
wafris.org
wafris.org
To your questions: there's an OSS core in that you can use the firewall itself without a connection to Wafris Hub.
We're in a transition where we're moving from our v1 (which required Redis) to a v2 on all clients (which uses locally replicated SQLite) and the docs and clients are in different states.
Some what's driving this is:
1. Solutions like Fastly + Cloudflare are out there, but there's still way too many sites without any "default" type protection.
2. It remains a big issue to try and sync and scale these types of systems if implemented within a framework.
3. It's easy to find stuff to block (look in your logs and it's all sorts of dumb attacks, scrapers, bots, etc.) but much harder to close the loop on discovering what to block. This is really "Wafris Hub" (the web gui) that tries to close the loop on this.
Would love more feedback, either here or mike@wafris.org
Is my understanding correct?
I do think it must either be early or abandoned; the NodeJS installation instructions are just an empty page.
https://wafris.org/docs/installation/nodejs/ should work for you now.
Also is there a list of supported servers/software? I clicked on a few links from the home page and they took me to a page asking for an e-mail to be notified when they're available in the future.
Does the free plan even allow blocking anything? All the Pricing page says is "IP Investigation" for the free/oss plan, leading me to assume most features are behind a paywall?