WAFUnclaimed

Coraza

Also known as
coraza

What is Coraza?

A web application firewall that provides enterprise-grade threat protection for APIs, applications, and legacy systems, with minimal performance overhead and support for custom rules and integrations.

Independently observed

Coraza pricing

We don't have Coraza's full plan breakdown yet (its pricing page resisted automated reading). Here's what we could confirm. Always check live pricing for exact numbers.

Pricing as of verify at live pricing ↗Independently observed
Open sourceFree tier

Free and open source

Platform & deployment

Independently observed
Deployment
  • Self-hosted

Integrations (3)

Independently observed
  • NGINX
  • Envoy
  • Apache APISIX

Security & compliance

Known vulnerabilities: 2 (0 in the last 12 months), max severity HIGH sourcea count reflects scale & disclosure, not quality

Coraza alternatives

Other waf we track, ranked by the same independent score.

All Coraza alternatives, ranked →

Compare Coraza

Side by side against other waf, attribute by attribute, with a source on every value.

Independent · unbought · dated

The Vioscale score: one lens on the evidence

Not user reviews and not a paid placement: a confidence-weighted blend of the independent signals below (adoption, activity, security posture, and more), which you can sort and re-weight yourself. Vendors can correct their listing but can never move their rank, and stars are weighted low as a vanity metric. It is one way to read the evidence for Coraza, not the verdict.

Balanced composite 46 / 100
low · 32%updating
Signal contributions to the composite score
SignalScoreWeightContributionEvidence
Price level1000.055.2
Release cadence830.054.3
Security score930.043.9
Development activity340.093.2
Pricing transparency250.082.1
Stars670.031.8
Integrations170.091.6
Dependent projects210.061.3
Reliability00.070.0-
Capabilities00.080.0-
Security posture00.070.0-
Package downloads00.140.0-
Developer Q&A activity00.060.0-

Computed . Re-weight it by intent, or see the full method.

All data & sourcesshow ↓

Every value we hold, with its source, retrieval date, and confidence. This is the evidence behind the score: don't trust it, verify it.

Activity

AttributeValueEvidence
Commits last 30d11mediumsource · 2026-08-26 · 65%

Adoption

AttributeValueEvidence
Github stars3,761highsource · 2026-08-26 · 90%
Dependent repos16highsource · 2026-08-26 · 85%

Integrations

AttributeValueEvidence
Count3mediumsource · 2026-08-19 · 60%

Language

AttributeValueEvidence
PrimaryGohighsource · 2026-08-26 · 90%

License

AttributeValueEvidence
SpdxApache-2.0highsource · 2026-08-26 · 95%

Pricing

AttributeValueEvidence
Free tierYesmediumsource · 2026-08-19 · 60%
Price levelfreemediumsource · 2026-08-19 · 60%
Modelcommerciallowsource · 2026-08-26 · 40%

Release

AttributeValueEvidence
Cadence days31mediumsource · 2026-08-26 · 70%
History20 itemsmediumsource · 2026-08-26 · 70%

Security

AttributeValueEvidence
Scorecard9.3highsource · 2026-08-26 · 90%
VulnerabilitiesCount: 2 · Source: https://advisories.ecosyste.ms/api/v1/advisories?ecosystem=go&package_name=github.com%2Fcorazawaf%2Fcoraza%2Fv3&per_page=100 · Last 12m: 0 · Max severity: HIGHhighsource · 2026-08-26 · 90%