# Coraza vs Fastly Next-Gen WAF

| Attribute | Coraza | Fastly Next-Gen WAF |
|---|---|---|
| **Vioscale score** | 46.1 (32% (low)) | 66.7 (26% (low)) |
| activity.commits_last_30d | 11 | - |
| adoption.dependent_repos | 16 | - |
| adoption.github_stars | 3,761 | - |
| deployment.options | `{"self_hosted":true}` | `{"cloud":true,"hybrid":true,"on_prem":true,"self_hosted":true}` |
| description.long | A web application firewall that provides enterprise-grade threat protection for APIs, applications, and legacy systems, with minimal performance overhead and support for custom rules and integrations. | A hybrid SaaS web application firewall that protects APIs and web apps through lightweight edge agents paired with cloud-based threat intelligence, supporting on-premises, cloud, container, and serverless deployments with real-time attack visibility. |
| integrations.count | 3 | 5 |
| integrations.list | `[{"name":"NGINX"},{"name":"Envoy"},{"name":"Apache APISIX"}]` | `[{"name":"Slack"},{"name":"PagerDuty"},{"name":"Jira"},{"name":"Elastic"},{"name":"Palo Alto Networks Cortex XSOAR"}]` |
| language.primary | Go | - |
| license.spdx | Apache-2.0 | - |
| market.availability | - | `{"hqCountry":"US","primaryMarkets":[],"availabilityScope":"global","availableCountries":[],"notAvailableCountries":[]}` |
| platform.support | - | `{"web":true}` |
| pricing | `{"type":"open_source","summary":"Free and open source","freeTier":true,"sourceUrl":"https://coraza.io/","retrievedAt":"2026-08-19T22:25:47.555Z"}` | `{"type":"usage","plans":[{"free":true,"name":"Free Tier","summary":"Free tier with usage-based overage charges","features":["DDoS protection","API threat detection","Real-time attack visibility"],"components":[{"per":{"qty":1,"unit":"GB"},"kind":"metered","amount":0.28,"currency":"USD"},{"per":{"qty":10000,"unit":"requests"},"kind":"metered","amount":0.01,"currency":"USD"}],"description":"Experiment with core platform capabilities","contactSales":false,"includedLimits":{"secrets":"10","requests":"1 Million","bandwidth":"100 GB","kv_storage":"5 GB","image_requests":"100,000","compute_requests":"10 Million","tls_managed_domains":"5","ddos_blocked_requests":"500,000"}},{"free":false,"name":"Enterprise","summary":"Contact sales for quote","description":"Custom deployment and support for large-scale operations","contactSales":true}],"addOns":[{"name":"Gold Support"},{"name":"Enterprise Support"}],"summary":"Usage-based pricing with free tier; enterprise packages from $1,500/month","currency":"USD","freeTier":true,"sourceUrl":"https://www.fastly.com/pricing","retrievedAt":"2026-08-19T22:26:39.796Z","billingPeriods":["month"]}` |
| pricing.free_tier | yes | yes |
| pricing.model | commercial | freemium |
| pricing.price_level | free | low |
| pricing.transparent | - | yes |
| release.cadence_days | 31 | - |
| release.history | `[{"url":"https://github.com/corazawaf/coraza/releases/tag/v3.7.0","date":"2026-04-06T12:56:11Z","type":"stable","version":"v3.7.0"},{"url":"https://github.com/corazawaf/coraza/releases/tag/v3.6.0","date":"2026-03-31T13:08:21Z","type":"stable","version":"v3.6.0"},{"url":"https://github.com/corazawaf/coraza/releases/tag/v3.5.0","date":"2026-03-28T01:09:55Z","type":"stable","version":"v3.5.0"},{"url":"https://github.com/corazawaf/coraza/releases/tag/v3.4.0","date":"2026-03-11T23:28:22Z","type":"stable","version":"v3.4.0"},{"url":"https://github.com/corazawaf/coraza/releases/tag/v3.3.3","date":"2025-03-20T14:50:43Z","type":"stable","version":"v3.3.3"},{"url":"https://github.com/corazawaf/coraza/releases/tag/v3.3.2","date":"2025-01-09T12:34:21Z","type":"stable","version":"v3.3.2"},{"url":"https://github.com/corazawaf/coraza/releases/tag/v3.3.1","date":"2025-01-07T17:29:00Z","type":"stable","version":"v3.3.1"},{"url":"https://github.com/corazawaf/coraza/releases/tag/v3.3.0","date":"2025-01-03T08:58:16Z","type":"stable","version":"v3.3.0"},{"url":"https://github.com/corazawaf/coraza/releases/tag/v3.2.1","date":"2024-06-23T14:18:59Z","type":"stable","version":"v3.2.1"},{"url":"https://github.com/corazawaf/coraza/releases/tag/v3.2.0","date":"2024-06-20T21:34:34Z","type":"stable","version":"v3.2.0"},{"url":"https://github.com/corazawaf/coraza/releases/tag/v3.1.0","date":"2024-02-09T13:24:59Z","type":"stable","version":"v3.1.0"},{"url":"https://github.com/corazawaf/coraza/releases/tag/v3.0.4","date":"2023-09-26T10:17:47Z","type":"stable","version":"v3.0.4"},{"url":"https://github.com/corazawaf/coraza/releases/tag/v3.0.3","date":"2023-08-06T07:51:26Z","type":"stable","version":"v3.0.3"},{"url":"https://github.com/corazawaf/coraza/releases/tag/v3.0.2","date":"2023-06-27T08:29:31Z","type":"stable","version":"v3.0.2"},{"url":"https://github.com/corazawaf/coraza/releases/tag/v3.0.1","date":"2023-06-25T16:19:54Z","type":"stable","version":"v3.0.1"},{"url":"https://github.com/corazawaf/coraza/releases/tag/v3.0.0","date":"2023-05-31T12:01:20Z","type":"stable","version":"v3.0.0"},{"url":"https://github.com/corazawaf/coraza/releases/tag/v3.0.0-rc.3","date":"2023-05-27T04:54:00Z","type":"prerelease","version":"v3.0.0-rc.3"},{"url":"https://github.com/corazawaf/coraza/releases/tag/v3.0.0-rc.2","date":"2023-04-17T17:17:05Z","type":"prerelease","version":"v3.0.0-rc.2"},{"url":"https://github.com/corazawaf/coraza/releases/tag/v3.0.0-rc.1","date":"2023-03-17T14:29:46Z","type":"prerelease","version":"v3.0.0-rc.1"},{"url":"https://github.com/corazawaf/coraza/releases/tag/v2.0.1","date":"2022-07-25T14:48:47Z","type":"stable","version":"v2.0.1"}]` | - |
| security.gdpr | - | yes |
| security.scorecard | 9.3 | - |
| security.vulnerabilities | `{"count":2,"source":"https://advisories.ecosyste.ms/api/v1/advisories?ecosystem=go&package_name=github.com%2Fcorazawaf%2Fcoraza%2Fv3&per_page=100","last_12m":0,"max_severity":"HIGH"}` | - |

## Capabilities (WAF)

| Capability | Coraza | Fastly Next-Gen WAF |
|---|:--:|:--:|
| **Capabilities** |  |  |
| Deployment model | - | - |
| Owasp top 10 protection | - | - |
| Custom rules engine | - | - |
| Bot management | - | - |
| API discovery protection | - | - |
| Ddos l7 protection | - | - |
| Rate limiting | - | - |
| Threat intel feeds | - | - |
| SIEM logging integration | - | - |
| Kubernetes ingress support | - | - |
| SOC2 type ii | - | - |
| PCI DSS compliant | - | - |
| Fedramp authorized | - | - |
| Pricing model | - | - |

*Source: Vioscale. Generated 2026-09-01T15:15:30.654Z. "-" = undocumented, not absent.*
