Web Application Firewall
block OWASP Top 10 attacks

// screenshot of bunkerweb.io ↗
BunkerWeb is a Web Application Firewall (WAF) and reverse proxy — combines nginx with ModSecurity, custom security rules, anti-bot, rate limiting, and a beautiful admin UI. Open-source, drop-in replacement for nginx + manual ModSecurity wiring.
BunkerWeb is a Web Application Firewall (WAF) and reverse proxy — combines nginx with ModSecurity, custom security rules, anti-bot, rate limiting, and a beautiful admin UI. Open-source, drop-in replacement for nginx + manual ModSecurity wiring.
For self-hosters running public-facing apps and worried about attacks, BunkerWeb is the all-in-one defense layer.
Concrete scenarios where teams pick BunkerWeb over the SaaS alternative.
block OWASP Top 10 attacks
protected access to backend apps
rate limiting + bad-bot blocking
Let's Encrypt + secure cipher suites
CAPTCHA + behavior analysis
If your team profile matches one of these, BunkerWeb is a strong fit out of the box.
running public-facing apps with attack concerns
protecting customer-facing sites
wanting WAF without commercial vendors
rejecting Cloudflare's data handling
requiring documented WAF
When evaluating self-hosted options for this category, here are the dimensions on which BunkerWeb consistently lands above the alternatives.
The stack you'll plug BunkerWeb into — services, protocols, and adjacent apps in the BluixApps catalog.
bunkerity/bunkerweb:1.5 (release-tagged)Operational guidance from running this in production — what to do before you scale, what to lock down, what surprises people.
bunkerity/bunkerweb:1.6.9 · bunkerity/bunkerweb-scheduler:1.6.9