# Fastly Next-Gen WAF vs ModSecurity

| Attribute | Fastly Next-Gen WAF | ModSecurity |
|---|---|---|
| **Vioscale score** | 66.7 (26% (low)) | 32.3 (20% (low)) |
| activity.commits_last_30d | - | 0 |
| adoption.dependent_repos | - | 0 |
| adoption.github_stars | - | 9,753 |
| deployment.options | `{"cloud":true,"hybrid":true,"on_prem":true,"self_hosted":true}` | `{"self_hosted":true}` |
| description.long | A hybrid SaaS web application firewall that protects APIs and web apps through lightweight edge agents paired with cloud-based threat intelligence, supporting on-premises, cloud, container, and serverless deployments with real-time attack visibility. | A flexible firewall module that monitors HTTP traffic and enforces security policies through a customizable rules engine. |
| integrations.count | 5 | - |
| integrations.list | `[{"name":"Slack"},{"name":"PagerDuty"},{"name":"Jira"},{"name":"Elastic"},{"name":"Palo Alto Networks Cortex XSOAR"}]` | - |
| language.primary | - | C++ |
| license.spdx | - | Apache-2.0 |
| market.availability | `{"hqCountry":"US","primaryMarkets":[],"availabilityScope":"global","availableCountries":[],"notAvailableCountries":[]}` | - |
| platform.support | `{"web":true}` | - |
| pricing | `{"type":"usage","plans":[{"free":true,"name":"Free Tier","summary":"Free tier with usage-based overage charges","features":["DDoS protection","API threat detection","Real-time attack visibility"],"components":[{"per":{"qty":1,"unit":"GB"},"kind":"metered","amount":0.28,"currency":"USD"},{"per":{"qty":10000,"unit":"requests"},"kind":"metered","amount":0.01,"currency":"USD"}],"description":"Experiment with core platform capabilities","contactSales":false,"includedLimits":{"secrets":"10","requests":"1 Million","bandwidth":"100 GB","kv_storage":"5 GB","image_requests":"100,000","compute_requests":"10 Million","tls_managed_domains":"5","ddos_blocked_requests":"500,000"}},{"free":false,"name":"Enterprise","summary":"Contact sales for quote","description":"Custom deployment and support for large-scale operations","contactSales":true}],"addOns":[{"name":"Gold Support"},{"name":"Enterprise Support"}],"summary":"Usage-based pricing with free tier; enterprise packages from $1,500/month","currency":"USD","freeTier":true,"sourceUrl":"https://www.fastly.com/pricing","retrievedAt":"2026-08-19T22:26:39.796Z","billingPeriods":["month"]}` | `{"type":"open_source","freeTier":true,"sourceUrl":"https://modsecurity.org/","retrievedAt":"2026-08-19T22:22:16.598Z"}` |
| pricing.free_tier | yes | yes |
| pricing.model | freemium | commercial |
| pricing.price_level | low | free |
| pricing.transparent | yes | - |
| release.cadence_days | - | 85 |
| release.history | - | `[{"url":"https://github.com/owasp-modsecurity/ModSecurity/releases/tag/v2.9.14","date":"2026-07-02T18:56:26Z","type":"stable","version":"v2.9.14"},{"url":"https://github.com/owasp-modsecurity/ModSecurity/releases/tag/v3.0.16","date":"2026-06-29T16:40:53Z","type":"stable","version":"v3.0.16"},{"url":"https://github.com/owasp-modsecurity/ModSecurity/releases/tag/v3.0.15","date":"2026-04-28T17:48:05Z","type":"stable","version":"v3.0.15"},{"url":"https://github.com/owasp-modsecurity/ModSecurity/releases/tag/v2.9.13","date":"2026-04-28T18:09:37Z","type":"stable","version":"v2.9.13"},{"url":"https://github.com/owasp-modsecurity/ModSecurity/releases/tag/v2.9.12","date":"2025-08-05T19:21:09Z","type":"stable","version":"v2.9.12"},{"url":"https://github.com/owasp-modsecurity/ModSecurity/releases/tag/v2.9.11","date":"2025-07-01T20:07:12Z","type":"stable","version":"v2.9.11"},{"url":"https://github.com/owasp-modsecurity/ModSecurity/releases/tag/v2.9.10","date":"2025-06-02T15:07:24Z","type":"stable","version":"v2.9.10"},{"url":"https://github.com/owasp-modsecurity/ModSecurity/releases/tag/v2.9.9","date":"2025-05-21T19:49:37Z","type":"stable","version":"v2.9.9"},{"url":"https://github.com/owasp-modsecurity/ModSecurity/releases/tag/v3.0.14","date":"2025-02-25T14:32:53Z","type":"stable","version":"v3.0.14"},{"url":"https://github.com/owasp-modsecurity/ModSecurity/releases/tag/v3.0.13","date":"2024-09-03T13:56:15Z","type":"stable","version":"v3.0.13"},{"url":"https://github.com/owasp-modsecurity/ModSecurity/releases/tag/v2.9.8","date":"2024-09-03T13:07:38Z","type":"stable","version":"v2.9.8"},{"url":"https://github.com/owasp-modsecurity/ModSecurity/releases/tag/v3.0.12","date":"2024-01-30T15:52:56Z","type":"stable","version":"v3.0.12"},{"url":"https://github.com/owasp-modsecurity/ModSecurity/releases/tag/v3.0.11","date":"2023-12-06T20:01:25Z","type":"stable","version":"v3.0.11"},{"url":"https://github.com/owasp-modsecurity/ModSecurity/releases/tag/v3.0.10","date":"2023-07-25T16:38:18Z","type":"stable","version":"v3.0.10"},{"url":"https://github.com/owasp-modsecurity/ModSecurity/releases/tag/v3.0.9","date":"2023-04-13T03:22:09Z","type":"stable","version":"v3.0.9"},{"url":"https://github.com/owasp-modsecurity/ModSecurity/releases/tag/v2.9.7","date":"2023-01-05T01:45:19Z","type":"stable","version":"v2.9.7"},{"url":"https://github.com/owasp-modsecurity/ModSecurity/releases/tag/v3.0.8","date":"2022-09-07T20:16:11Z","type":"stable","version":"v3.0.8"},{"url":"https://github.com/owasp-modsecurity/ModSecurity/releases/tag/v2.9.6","date":"2022-09-08T00:23:08Z","type":"stable","version":"v2.9.6"},{"url":"https://github.com/owasp-modsecurity/ModSecurity/releases/tag/v3.0.7","date":"2022-05-30T20:08:15Z","type":"stable","version":"v3.0.7"},{"url":"https://github.com/owasp-modsecurity/ModSecurity/releases/tag/v2.9.5","date":"2021-11-22T23:59:04Z","type":"stable","version":"v2.9.5"}]` |
| security.gdpr | yes | yes |
| security.vulnerabilities | - | `{"count":0,"source":"https://advisories.ecosyste.ms/api/v1/advisories?ecosystem=nixpkgs&package_name=libmodsecurity&per_page=100","last_12m":0,"max_severity":null}` |

## Capabilities (WAF)

| Capability | Fastly Next-Gen WAF | ModSecurity |
|---|:--:|:--:|
| **Capabilities** |  |  |
| Deployment model | - | - |
| Owasp top 10 protection | - | - |
| Custom rules engine | - | - |
| Bot management | - | - |
| API discovery protection | - | - |
| Ddos l7 protection | - | - |
| Rate limiting | - | - |
| Threat intel feeds | - | - |
| SIEM logging integration | - | - |
| Kubernetes ingress support | - | - |
| SOC2 type ii | - | - |
| PCI DSS compliant | - | - |
| Fedramp authorized | - | - |
| Pricing model | - | - |

*Source: Vioscale. Generated 2026-09-01T15:18:55.471Z. "-" = undocumented, not absent.*
