Application Security software protects web services and servers from malicious traffic and operational errors. These tools filter HTTP requests to block exploits, mitigate bot scrapers, and manage the rollout of new features through flags. This type of software serves developers and system administrators who need to secure their own infrastructure. By hosting these apps on private servers, you keep session replays, traffic logs, and experimentation data within your own environment. This approach ensures that security configurations and user behavior analytics remain private.
This page lists 15 open source tools in the Application Security category. The most popular are SafeLine, Anubis and Unleash. Most use the MIT or AGPL-3.0 license, and 14 offer an official Docker image.
A self-hosted web application firewall and reverse proxy that filters and monitors HTTP traffic to block exploits.
Filters incoming HTTP requests using challenges to protect upstream resources from AI crawlers and scraper bots.
Manage feature flags and gradual rollouts to control how and when new features reach end users.
A self-hosted session replay and product analytics suite for troubleshooting web application issues and monitoring performance.
A web application firewall and reverse proxy that provides secure by default protection for web services.
Manage feature flags and run A/B tests using a warehouse native approach to product analytics and experimentation.
A lightweight bot protection system using proof-of-work and instrumentation challenges to replace visual puzzles and tracking.
A feature flagging and remote configuration tool for managing software releases and conducting multivariate tests across environments.
Manage feature flags as code by storing configurations directly in Git repositories with version control.
A self-hosted spam protection system using proof-of-work mechanisms to replace traditional visual CAPTCHA puzzles.
A privacy respecting proof of work system that protects websites from bots without requiring image solving.
Blocks malicious IP addresses by detecting failed login attempts from event viewers and log files.
A self-hosted cloud native feature flag solution for managing feature toggles and A/B testing experiments.
Manage feature flags and conduct A/B testing to decouple code deployments from feature releases in production.
A web application firewall and API security gateway featuring AI and semantic analysis for threat detection.
Join our newsletter to get shiny new open source software delivered to your inbox. Unsubscribe anytime.