Skip to content

Add WAFtester to Testing section#108

Open
Qandil wants to merge 1 commit intodevsecops:masterfrom
Qandil:add-waftester
Open

Add WAFtester to Testing section#108
Qandil wants to merge 1 commit intodevsecops:masterfrom
Qandil:add-waftester

Conversation

@Qandil
Copy link

@Qandil Qandil commented Mar 6, 2026

Adds WAFtester to the Testing section.

WAFtester is an open-source WAF security testing CLI that:

  • Tests WAF rule coverage with 2800+ attack payloads across 18 categories
  • Fingerprints 197+ WAF vendors
  • Automates bypass discovery with 70+ evasion techniques
  • Outputs SARIF, SonarQube, GitLab SAST, and JUnit for CI/CD integration
  • Quantitative scoring (F1, MCC, FPR) for WAF effectiveness measurement

It fits the DevSecOps pipeline as a testing tool that can run in CI/CD to validate WAF configurations before and after deployment.

GitHub: https://github.com/waftester/waftester

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant