# Imperva WAF vs ModSecurity

| Attribute | Imperva WAF | ModSecurity |
|---|---|---|
| **Vioscale score** | 22.4 (3% (low)) | 32.3 (20% (low)) |
| activity.commits_last_30d | - | 0 |
| adoption.dependent_repos | - | 0 |
| adoption.github_stars | - | 9,753 |
| deployment.options | `{"cloud":true,"hybrid":true,"self_hosted":true}` | `{"self_hosted":true}` |
| description.long | Imperva WAF delivers automated security policy management and attack protection with API discovery capabilities. It supports deployment as a managed cloud service or self-hosted solution using Kubernetes, allowing organizations to integrate protection with existing infrastructure without architectural changes. | A flexible firewall module that monitors HTTP traffic and enforces security policies through a customizable rules engine. |
| integrations.count | 5 | - |
| integrations.list | `[{"name":"AWS"},{"name":"Azure"},{"name":"GCP"},{"name":"Kong"},{"name":"Imperva WAF Gateway"}]` | - |
| language.primary | - | C++ |
| license.spdx | - | Apache-2.0 |
| platform.support | `{"web":true}` | - |
| pricing | - | `{"type":"open_source","freeTier":true,"sourceUrl":"https://modsecurity.org/","retrievedAt":"2026-08-19T22:22:16.598Z"}` |
| pricing.free_tier | - | yes |
| pricing.model | - | commercial |
| pricing.price_level | - | free |
| release.cadence_days | - | 85 |
| release.history | - | `[{"url":"https://github.com/owasp-modsecurity/ModSecurity/releases/tag/v2.9.14","date":"2026-07-02T18:56:26Z","type":"stable","version":"v2.9.14"},{"url":"https://github.com/owasp-modsecurity/ModSecurity/releases/tag/v3.0.16","date":"2026-06-29T16:40:53Z","type":"stable","version":"v3.0.16"},{"url":"https://github.com/owasp-modsecurity/ModSecurity/releases/tag/v3.0.15","date":"2026-04-28T17:48:05Z","type":"stable","version":"v3.0.15"},{"url":"https://github.com/owasp-modsecurity/ModSecurity/releases/tag/v2.9.13","date":"2026-04-28T18:09:37Z","type":"stable","version":"v2.9.13"},{"url":"https://github.com/owasp-modsecurity/ModSecurity/releases/tag/v2.9.12","date":"2025-08-05T19:21:09Z","type":"stable","version":"v2.9.12"},{"url":"https://github.com/owasp-modsecurity/ModSecurity/releases/tag/v2.9.11","date":"2025-07-01T20:07:12Z","type":"stable","version":"v2.9.11"},{"url":"https://github.com/owasp-modsecurity/ModSecurity/releases/tag/v2.9.10","date":"2025-06-02T15:07:24Z","type":"stable","version":"v2.9.10"},{"url":"https://github.com/owasp-modsecurity/ModSecurity/releases/tag/v2.9.9","date":"2025-05-21T19:49:37Z","type":"stable","version":"v2.9.9"},{"url":"https://github.com/owasp-modsecurity/ModSecurity/releases/tag/v3.0.14","date":"2025-02-25T14:32:53Z","type":"stable","version":"v3.0.14"},{"url":"https://github.com/owasp-modsecurity/ModSecurity/releases/tag/v3.0.13","date":"2024-09-03T13:56:15Z","type":"stable","version":"v3.0.13"},{"url":"https://github.com/owasp-modsecurity/ModSecurity/releases/tag/v2.9.8","date":"2024-09-03T13:07:38Z","type":"stable","version":"v2.9.8"},{"url":"https://github.com/owasp-modsecurity/ModSecurity/releases/tag/v3.0.12","date":"2024-01-30T15:52:56Z","type":"stable","version":"v3.0.12"},{"url":"https://github.com/owasp-modsecurity/ModSecurity/releases/tag/v3.0.11","date":"2023-12-06T20:01:25Z","type":"stable","version":"v3.0.11"},{"url":"https://github.com/owasp-modsecurity/ModSecurity/releases/tag/v3.0.10","date":"2023-07-25T16:38:18Z","type":"stable","version":"v3.0.10"},{"url":"https://github.com/owasp-modsecurity/ModSecurity/releases/tag/v3.0.9","date":"2023-04-13T03:22:09Z","type":"stable","version":"v3.0.9"},{"url":"https://github.com/owasp-modsecurity/ModSecurity/releases/tag/v2.9.7","date":"2023-01-05T01:45:19Z","type":"stable","version":"v2.9.7"},{"url":"https://github.com/owasp-modsecurity/ModSecurity/releases/tag/v3.0.8","date":"2022-09-07T20:16:11Z","type":"stable","version":"v3.0.8"},{"url":"https://github.com/owasp-modsecurity/ModSecurity/releases/tag/v2.9.6","date":"2022-09-08T00:23:08Z","type":"stable","version":"v2.9.6"},{"url":"https://github.com/owasp-modsecurity/ModSecurity/releases/tag/v3.0.7","date":"2022-05-30T20:08:15Z","type":"stable","version":"v3.0.7"},{"url":"https://github.com/owasp-modsecurity/ModSecurity/releases/tag/v2.9.5","date":"2021-11-22T23:59:04Z","type":"stable","version":"v2.9.5"}]` |
| security.gdpr | yes | yes |
| security.vulnerabilities | - | `{"count":0,"source":"https://advisories.ecosyste.ms/api/v1/advisories?ecosystem=nixpkgs&package_name=libmodsecurity&per_page=100","last_12m":0,"max_severity":null}` |

## Capabilities (WAF)

| Capability | Imperva WAF | ModSecurity |
|---|:--:|:--:|
| **Capabilities** |  |  |
| Deployment model | - | - |
| Owasp top 10 protection | - | - |
| Custom rules engine | - | - |
| Bot management | - | - |
| API discovery protection | - | - |
| Ddos l7 protection | - | - |
| Rate limiting | - | - |
| Threat intel feeds | - | - |
| SIEM logging integration | - | - |
| Kubernetes ingress support | - | - |
| SOC2 type ii | - | - |
| PCI DSS compliant | - | - |
| Fedramp authorized | - | - |
| Pricing model | - | - |

*Source: Vioscale. Generated 2026-09-01T14:29:36.825Z. "-" = undocumented, not absent.*
