BunkerWeb

BunkerWeb

Web application firewall and security reverse proxy

9.7kstars
555forks
Last commit: 1mo ago
Repo age: 7y old
BunkerWeb screenshot

BunkerWeb is a security-focused web server and reverse proxy designed to protect web applications with a built-in Web Application Firewall (WAF) and hardened defaults. It is typically deployed in front of one or more HTTP applications (as a reverse proxy) and can be managed via a web-based UI and configuration templates.

Key Features

  • NGINX-based reverse proxy/web server with security-first default configuration
  • Integrated WAF capabilities (commonly deployed with ModSecurity + OWASP Core Rule Set)
  • Web UI for configuration and operational management
  • Automated TLS certificate management (ACME/Let’s Encrypt) for HTTPS enablement
  • IP/geo-based access controls and request filtering features (e.g., allow/deny lists)
  • Rate limiting and protections targeting common OWASP Top 10 attack patterns
  • Container-friendly deployment options (Docker) for homelabs and production setups

Use Cases

  • Put a WAF in front of self-hosted services (e.g., dashboards, CMS, admin panels)
  • Centralize HTTPS and security controls for multiple internal web applications
  • Add request filtering, rate limiting, and hardened headers to legacy apps

Limitations and Considerations

  • Full protection depends on correct rule tuning (WAF rules can cause false positives)
  • Advanced scenarios may require NGINX/WAF knowledge for optimal configuration

BunkerWeb is a practical option for teams and self-hosters who want an NGINX-based reverse proxy with an integrated WAF and a management UI. It focuses on providing common web security controls in a deployable package while keeping compatibility with typical reverse-proxy architectures.

Categories:

Tags:

Tech Stack:

Share:

Similar Services

Pi-hole

Pi-hole

Network-wide ad blocking via DNS sinkhole

55.2k
3k
Last commit: 1mo ago

DNS sinkhole that blocks ads, trackers, and malicious domains network-wide with a web dashboard, per-client controls, and optional DHCP/DNS features.

Alternative to:
NextDNS
NextDNS
+1
CyberChef

CyberChef

The Cyber Swiss Army Knife for data analysis and decoding

33.7k
3.8k
Last commit: 5mo ago

Browser-based tool for decoding, encoding, encryption, and data analysis using a drag-and-drop “recipe” workflow for security, DFIR, and engineering tasks.

Alternative to:
CrackStation (online hash cracking/lookup)
CrackStation (online hash cracking/lookup)
+4
AdGuard Home

AdGuard Home

Network-wide ads and tracker blocking via DNS

32k
2.2k
Last commit: 13d ago

Self-hosted DNS server with ad/tracker blocking, custom filtering, parental controls, encrypted DNS, and per-client statistics for home networks.

Alternative to:
NextDNS
NextDNS
+1
Nginx Proxy Manager

Nginx Proxy Manager

Web UI for Nginx reverse proxy with Let's Encrypt SSL

30.9k
3.5k
Last commit: 1mo ago

Web-based reverse proxy manager for Nginx with hosts, streams, access lists, and automatic Let's Encrypt certificates via an easy admin UI.

Alternative to:
NGINX Plus
NGINX Plus
+5
SafeLine

SafeLine

Self-hosted WAF for protecting web apps and APIs

20k
1.3k
Last commit: 2mo ago

SafeLine is an open-source web application firewall (WAF) that protects web apps and APIs from common attacks using HTTP traffic inspection, rules, and management UI.

Alternative to:
Cloudflare WAF
Cloudflare WAF
+4
Teleport

Teleport

Identity-native infrastructure access for SSH, Kubernetes, RDP and DBs

19.6k
2k
Last commit: 16h ago

Open-source platform that provides unified, audited, identity-based access to servers, Kubernetes clusters, databases, and desktops without static credentials.

Alternative to:
Okta Advanced Server Access
Okta Advanced Server Access
+2