What is Coraza?
A web application firewall that provides enterprise-grade threat protection for APIs, applications, and legacy systems, with minimal performance overhead and support for custom rules and integrations.
Coraza pricing
We don't have Coraza's full plan breakdown yet (its pricing page resisted automated reading). Here's what we could confirm. Always check live pricing for exact numbers.
Free and open source
Platform & deployment
Independently observed- Self-hosted
Integrations (3)
Independently observed- NGINX
- Envoy
- Apache APISIX
Security & compliance
Known vulnerabilities: 2 (0 in the last 12 months), max severity HIGH sourcea count reflects scale & disclosure, not quality
Coraza alternatives
Other waf we track, ranked by the same independent score.
- Fastly Next-Gen WAFDistributed web application and API security platform deployable anywhere your infrastructure liveslow · 26%
- AWS WAFA cloud-native web application firewall that protects web applications and APIs from web-based attacksmedium · 61%
- Cloudflare WAFAn edge-deployed security layer that inspects incoming web traffic and prevents attacks before they reach your applicationsmedium · 53%
- ModSecuritylow · 20%
- Imperva WAFlow · 3%
- Barracuda Web Application FirewallDefend applications and APIs against cyber threats with intelligent attack detection and preventionlow · 30%
Compare Coraza
Side by side against other waf, attribute by attribute, with a source on every value.
The Vioscale score: one lens on the evidence
Not user reviews and not a paid placement: a confidence-weighted blend of the independent signals below (adoption, activity, security posture, and more), which you can sort and re-weight yourself. Vendors can correct their listing but can never move their rank, and stars are weighted low as a vanity metric. It is one way to read the evidence for Coraza, not the verdict.
| Signal | Score | Weight | Contribution | Evidence |
|---|---|---|---|---|
| Price level | 100 | 0.05 | 5.2 | ✓ |
| Release cadence | 83 | 0.05 | 4.3 | ✓ |
| Security score | 93 | 0.04 | 3.9 | ✓ |
| Development activity | 34 | 0.09 | 3.2 | ✓ |
| Pricing transparency | 25 | 0.08 | 2.1 | ✓ |
| Stars | 67 | 0.03 | 1.8 | ✓ |
| Integrations | 17 | 0.09 | 1.6 | ✓ |
| Dependent projects | 21 | 0.06 | 1.3 | ✓ |
| Reliability | 0 | 0.07 | 0.0 | - |
| Capabilities | 0 | 0.08 | 0.0 | - |
| Security posture | 0 | 0.07 | 0.0 | - |
| Package downloads | 0 | 0.14 | 0.0 | - |
| Developer Q&A activity | 0 | 0.06 | 0.0 | - |
Computed . Re-weight it by intent, or see the full method.
All data & sourcesshow ↓
Every value we hold, with its source, retrieval date, and confidence. This is the evidence behind the score: don't trust it, verify it.
Activity
| Attribute | Value | Evidence |
|---|---|---|
| Commits last 30d | 11 | mediumsource · 2026-08-26 · 65% |
Adoption
Integrations
| Attribute | Value | Evidence |
|---|---|---|
| Count | 3 | mediumsource · 2026-08-19 · 60% |
Language
| Attribute | Value | Evidence |
|---|---|---|
| Primary | Go | highsource · 2026-08-26 · 90% |
License
| Attribute | Value | Evidence |
|---|---|---|
| Spdx | Apache-2.0 | highsource · 2026-08-26 · 95% |