UUSEC WAF
An industrial-grade, free, high-performance web application firewall and API security gateway with AI, semantic engines, HIPS, and RASP protection.
At a Glance
About UUSEC WAF
UUSEC WAF is a web application firewall (WAF) and API security gateway (WAAP) developed by UUSEC Technology, available as open-source software under the BSD 2-Clause license. It operates as a cloud WAF reverse proxy and delivers three-layer defense covering the traffic layer, system layer, and application runtime layer. The project is hosted on GitHub and, according to the repository, reached v7.2.1 as of May 2026.
What It Is
UUSEC WAF is a self-hosted, reverse-proxy WAF that sits in front of web applications and APIs to detect and block attacks including SQL injection, XSS, RCE, LFI, HTTP flood, and zero-day exploits. It is built on nginx and LuaJIT, deployed via Docker, and managed through a browser-based admin interface. The product targets security administrators and website operators who need enterprise-grade protection without relying on a cloud SaaS vendor.
Three-Layer Defense Architecture
The product's headline differentiator is its three-layer defense model:
- Traffic layer: Semantic analysis engines for SQL, XSS, RCE, and LFI, combined with deep decoding (base64, JSON, form data) to resist WAF bypass techniques.
- System layer (HIPS): Host Intrusion Prevention System that intercepts low-level attacks at the kernel layer, including process network communication restrictions, file read/write controls, privilege escalation blocking, and overflow attack prevention.
- Runtime layer (RASP): Runtime Application Self-Protection inserted into Java JVM and PHP Zend engines to track runtime context and block web zero-day exploits from within the application.
AI and Semantic Detection Engines
UUSEC WAF applies machine learning anomaly detection to distinguish normal HTTP traffic from attack traffic. The system automatically learns parameter characteristics of normal traffic and builds whitelist rule libraries, enabling zero-day interception without manual rule updates. The vendor publishes an internal benchmark comparing detection rates across 33,669 samples, claiming the Pro edition achieves 98.97% detection with a 0.01% false positive rate, versus 69.74% detection and 17.58% false positives for ModSecurity Level 1.
Advanced Rule and Plugin Engine
Beyond built-in detection, UUSEC WAF exposes a Lua script rule engine that allows advanced administrators to write custom vulnerability protection rules and plugins. Rules published in the management backend take effect immediately without restarting the service. The vendor states this flexibility exceeds most free WAF products including ModSecurity. The CDN acceleration module includes a self-developed cache purge feature supporting regular expression URL path matching, which the vendor claims surpasses the commercial nginx proxy_cache_purge module.
Deployment and Setup
Installation requires Docker CE 20.10.14+ and Docker Compose 2.0.0+, and is completed via a single shell command. The WAF runs on Linux x86_64 and uses ports 80 and 443 by default in reverse proxy mode. The management interface is accessible at https://ip:4443. Setup involves adding sites, uploading SSL certificates (or requesting Let's Encrypt certificates automatically), and updating DNS A records to point to the WAF server.
Update: v7.2.1
The latest release is v7.2.1, published on May 16, 2026. The repository was last pushed on May 19, 2026, indicating active development. The project has accumulated over 1,600 GitHub stars and 163 forks since its creation in September 2022, with 81 open issues at the time of data collection.
Community Discussions
Be the first to start a conversation about UUSEC WAF
Share your experience with UUSEC WAF, ask questions, or help others learn from your insights.
Pricing
Community Edition
Free open-source edition with core WAF and API security features, up to 10 sites.
- Sites management (max 10 sites)
- Vulnerabilities protection
- HTTP flood protection
- Backdoor detection
- Business security
Professional Edition
Commercial edition with unlimited sites, machine learning, HIPS, RASP, enhanced rules, data masking, and technical support.
- Unlimited sites
- All Community Edition features
- Multi-tenant support
- Enhanced rules
- Data masking
- Technical support
- Machine learning
- HIPS
- RASP
Business Edition
Custom enterprise edition with all Professional features plus cluster management and customized development.
- All Professional Edition features
- Cluster management
- Customized development
Capabilities
Key Features
- Web Application Firewall (WAF)
- API Security Gateway (WAAP)
- AI-based anomaly detection for 0-day defense
- Semantic analysis engines for SQL, XSS, RCE, LFI
- HIPS (Host Intrusion Prevention System)
- RASP (Runtime Application Self-Protection) for Java JVM and PHP Zend
- HTTP flood protection
- CDN acceleration with regex-based cache purge
- Lua script rule engine for custom plugins
- Immediate rule deployment without restart
- Let's Encrypt free SSL certificate support with auto-renewal
- Multi-tenant support (commercial editions)
- Load balancing
- Data masking (commercial editions)
- Cluster management (commercial editions)
- Compliance audit logging
- Regional restrictions
- Backdoor detection
- Business security rules
- Browser-based management interface
Integrations
Demo Video

