Self-hosted service
chaitin/SafeLine avatar
chaitin/SafeLine

SafeLine: A Self-Hosted WAF and Reverse Proxy for Web Application Security

SafeLine is a self-hosted WAF(Web Application Firewall) / reverse proxy to protect your web apps from attacks and exploits.

22,676 stars1,544 forksGoGPL-3.0

At a glance

What is it?
SafeLine is a self-hosted web application firewall and reverse proxy that filters HTTP traffic to block SQL injection, XSS, and other web attacks. It deploys via Docker Compose and is licensed under GPL-3.0.
Who is it for?
SafeLine is a practical choice for teams that need a self-hosted WAF without building custom Nginx rules or paying for a cloud firewall. The Docker Compose deployment is straightforward, and the Balance mode in the README's comparison table shows 71.65% detection with only 0.07% false positives across 33,669 test samples.
Can I use it commercially?
Yes, with conditions. GPL-3.0 is a copyleft licence: if you distribute software that includes it, you must release that software's source code under the same licence. Running it internally without distributing it does not trigger that obligation.
Is it still maintained?
Yes. The repository last received commits 7 days ago.
What is it written in?
Mainly Go, according to GitHub's language statistics.

Answers come from the project's GitHub data, last synced on September 26, 2026, and from our analysis. They are not legal advice.

DEEP OPEN-SOURCE ANALYSIS

What SafeLine protects against and who it is for

SafeLine acts as a reverse proxy sitting in front of web applications. Client requests arrive at SafeLine first; the WAF engine inspects and filters the traffic, and clean requests are forwarded to the application server. The README lists the attack types that SafeLine defends against: SQL injection, XSS, code injection, OS command injection, CRLF injection, LDAP injection, XPath injection, RCE (remote code execution), XXE, SSRF, path traversal, backdoor shells, brute force attempts, HTTP flood, and bot abuse.

The primary audience is web teams and system administrators who want a self-hosted firewall in front of applications that may not have been written with all these attack categories in mind. SafeLine is particularly relevant for teams running older web applications or PHP-based sites where input sanitization may be inconsistent. The README notes that the project has over 400,000 installations worldwide and protects more than 1,000,000 websites, handling over 30 billion HTTP requests daily.

SafeLine is the Community Edition of a product by Chaitin, a security company. The README links to a live demo at demo.waf.chaitin.com:9443, which lets potential users inspect the management interface before installation. The architecture positions SafeLine as a sidecar to any existing HTTP server; no changes to the application code are needed, since all traffic routing changes happen at the reverse proxy layer.

Core protection capabilities

SafeLine documents five main protection modes. Block Web Attacks covers the full list of injection and traversal attacks. Rate Limiting defends against DoS attacks and brute force by throttling traffic that exceeds configurable limits. Anti-Bot Challenge presents bot detection challenges to visitors; the README describes a mechanism where human users pass while crawlers and automated clients are blocked.

Authentication Challenge is a separate feature that requires visitors to enter a password before reaching the protected application. When this is turned on, unauthenticated visitors are blocked entirely, providing a simple but effective layer for internal tools exposed to the internet.

Dynamic Protection encrypts HTML and JavaScript code in the responses from the backend. According to the README, this encryption is applied dynamically on each request, which is intended to prevent DOM scraping and client-side code analysis. This is a non-standard WAF capability not present in most open-source alternatives.

The Web Access Control List (ACL) is a fifth capability mentioned in the core capability list. It allows operators to explicitly allow or block specific IP addresses or ranges, which complements the signature-based detection with explicit administrative controls. These five modes can be combined independently per protected application.

Installing SafeLine with Docker Compose

SafeLine is deployed with Docker Compose. The compose.yaml file in the repository defines four services: a PostgreSQL 15.2 database container (safeline-pg), a management service (safeline-mgt) that exposes the admin interface on port 9443 by default, a detector service, and a tengine (nginx-based) reverse proxy service.

The configuration requires two environment variables: SUBNET_PREFIX for the internal Docker network addressing and POSTGRES_PASSWORD for the database. The management service connects to PostgreSQL at startup using the MGT_PG variable.

The management container exposes a health check endpoint at https://localhost:1443/api/open/health. A data volume is mounted at ${SAFELINE_DIR}/resources for persistence. The README links to the official Install Guide at docs.waf.chaitin.com for the full step-by-step walkthrough, and notes that users in mainland China should use the Chinese installation guide to ensure proper connectivity to cloud services.

Detection accuracy compared to ModSecurity and Cloudflare

The README includes a detection comparison table across four configurations using 33,669 test samples. The results, as documented:

- ModSecurity Level 1: 69.74% detection, 17.58% false positive rate, 82.20% accuracy - Cloudflare Free: 10.70% detection, 0.07% false positive rate, 98.40% accuracy - SafeLine Balance: 71.65% detection, 0.07% false positive rate, 99.45% accuracy - SafeLine Strict: 76.17% detection, 0.22% false positive rate, 99.38% accuracy

The Balance mode result is notable: it achieves detection rates comparable to ModSecurity's rule-based approach while keeping the false positive rate as low as Cloudflare's free tier. ModSecurity at Level 1 blocks almost 18 in every 100 legitimate requests, which in production causes real friction for end users.

The comparison does not document what algorithm SafeLine uses to achieve this. The README does not describe the detection engine internals, so the detection accuracy figures should be treated as self-reported benchmark data.

Limitations and when SafeLine is not the right choice

SafeLine is GPL-3.0. Any product that distributes SafeLine as part of a larger system must also release the combined work under GPL-3.0. For companies that want to incorporate a WAF into a proprietary product, this licence is a constraint. The management UI and the engine are both covered by the licence; the MCP server and SDK integrations in the repository's sdk/ directory would need individual review.

The Docker Compose deployment model means SafeLine is a fixed installation rather than a cloud-native workload. There is an Ingress-NGINX plugin and a Kong Gateway plugin listed in the README's ecosystem section, but these are integrations, not a Kubernetes-native deployment. Teams that need a WAF implemented as a Kubernetes admission controller or sidecar will find SafeLine's architecture less natural than alternatives designed for that model.

The dynamic HTML and JS encryption feature, while distinctive, could cause issues with content security policies, browser extensions, or accessibility tools that expect unmodified page source. The README does not document known incompatibilities.

Because SafeLine manages traffic routing through the Tengine reverse proxy layer, debugging failed requests requires inspecting SafeLine's logs in addition to the application's logs. The compose.yaml mounts the Nginx log directory from the management container at ${SAFELINE_DIR}/logs/nginx, which gives operators access to raw access and error logs. Correlating a blocked request across the WAF logs and the application logs requires matching request IDs, and the README does not describe a log format or correlation approach in detail.

Ecosystem and maintenance

SafeLine's most recent release is v9.4.2, published on 2026-09-28, the same day as this article. The last push to the repository was on 2026-09-22, and the release history shows consistent cadence through the 9.x series. The release cadence has been consistent through the 9.x series, with v9.4.0 on 2026-08-17 and v9.4.1 on 2026-09-03.

The README documents several ecosystem integrations. A SafeLine MCP Server enables AI-assisted management and control of the WAF through the Model Context Protocol. The sdk/ directory contains an Ingress-NGINX plugin for protecting Kubernetes ingress traffic and a Kong Gateway plugin. The management interface is accessible at port 9443 over HTTPS by default, with a live demo available at the URL listed in the README.

For monitoring, the management service exposes metrics compatible with Prometheus, based on the golang prometheus/client_golang dependency visible in the management module. The compose.yaml defines resource limits and health checks for each container, which supports standard container monitoring infrastructure.

Compared to ModSecurity (the other widely used open-source WAF), SafeLine's advantage is the management UI and the lower false positive rate in the documented tests. ModSecurity is typically configured through Nginx or Apache modules with text-based rule files, while SafeLine provides a web dashboard for managing protected applications, viewing blocked requests, and reviewing traffic logs. The management dashboard also integrates with the MCP server for AI-assisted rule management.

Editorial conclusion

SafeLine is a practical choice for teams that need a self-hosted WAF without building custom Nginx rules or paying for a cloud firewall. The Docker Compose deployment is straightforward, and the Balance mode in the README's comparison table shows 71.65% detection with only 0.07% false positives across 33,669 test samples. It is not the right tool for environments that cannot run Docker or that require a fully open-source stack without GPL-licensed components, since SafeLine's WAF engine is GPL-3.0. Before deploying in production, verify that TCP port 9443 (the default management port) is restricted to trusted networks, as the management interface controls the entire WAF configuration.

Frequently asked questions

How do I install SafeLine WAF?

SafeLine is installed using Docker Compose. The compose.yaml file in the repository defines the full stack including PostgreSQL and the management interface. The official Install Guide at docs.waf.chaitin.com provides the step-by-step walkthrough. The management interface is available at port 9443 after installation.

What is SafeLine WAF?

SafeLine is a self-hosted web application firewall and reverse proxy that filters HTTP traffic to block SQL injection, XSS, code injection, path traversal, bot abuse, and other web attacks. It runs as a Docker Compose stack and provides a web management interface for configuring protected applications.

Is SafeLine WAF free?

The Community Edition of SafeLine is free and open-source under GPL-3.0. The README documents a comparison between the Community Edition's Balance and Strict modes and notes that the project has over 400,000 installations. Some cloud service features may require connectivity to Chaitin's cloud infrastructure.

Official sources

  1. Official documentation
  2. Official README
  3. Project repository
  4. Release notes
For maintainers

Add this badge to your README

If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.

Add this badge to your README

markdown
[![Hysen Labs](https://hysenlabs.com/badge/chaitin-safeline.svg)](https://hysenlabs.com/projects/chaitin-safeline)
Community notes

Community notes