WAFW00F
Web application firewall fingerprinting tool that detects which WAF protects a given website.
External Tool
This open-source tool is maintained externally. View the source on GitHub to learn more or run it yourself.
Browse security tools →What's next with WAFW00F?
Choose how you want to get started.
Use it free
Open the official tool or demo — no account needed.
Self-host it
Run the open-source version on your own infrastructure.
What is WAFW00F?
WAFW00F is a free WAF detection used by professionals and enthusiasts.
How it works
How WAFW00F works — see the article below for details on this security tools tool.
How to use it
- 1Open the WAFW00F tool, enter your input, and get your result instantly.
What it can do
- WAF detection
Use cases
Assumptions and limitations
Assumptions
- source: https://github.com/EnableSecurity/wafw00f
- license: BSD-3-Clause — free to use
- privacy: Self-hosted — you control your data
Limitations
- Dual-use tool — use only with explicit authorization on systems you own or have permission to test.
Understanding the result
Web application firewall fingerprinting tool that detects which WAF protects a given website.
Tool details
- Clearly flagged when a network request is needed.
- No account, no sign-up, and no tracking of your content.
- Powered by (BSD-3-Clause).
- Built with
- (EnableSecurity/wafw00f)
- License
- BSD-3-Clause
- Runs locally
- No — requires a network request
- Verification
- Not yet verified
- Input
- Query
- Output
- Text
Built with EnableSecurity/wafw00f. OpenToolVault provides the discovery and browser interface while crediting the original project maintainers.
- Built with
- License
- BSD-3-Clause
Open-source project
OpenToolVault is an independent directory. We are not affiliated with or endorsed by this project.
References
- / — GitHub Repository
Upstream project · GitHub
- BSD-3-Clause License
Upstream project