OWASP CRS
OWASP CRS is an open-source Web Application Firewall rule set that detects common attacks such as SQL injection, XSS, and remote code execution for ModSecurity and Coraza engines, maintained by a global volunteer community under the OWASP Foundation and distributed free under Apache 2.0.
- Company typePrivate
- Founded2001
- Headquarters—
- Headcount1–10
- GTM typeB2B
- OfferingSoftware
What OWASP CRS does
OWASP CRS (Core Rule Set) is an open-source Web Application Firewall rule set that provides generic attack detection for ModSecurity and compatible WAF engines. Distributed under the Apache 2.0 license and operated as a project of the OWASP Foundation, a US 501(c)(3) non-profit, CRS delivers protection against the OWASP Top Ten and a broad catalog of attack categories including SQL injection, XSS, LFI/RFI, PHP and Java code injection, SSTI, HTTPoxy, Shellshock, Unix/Windows shell injection, session fixation, scanner/bot detection, and metadata/error leakages. Detection uses SecLang rule syntax with configurable paranoia levels (PL1–PL4), anomaly scoring, and per-application exclusion packages for platforms such as WordPress, Drupal, Nextcloud, phpBB, phpMyAdmin, cPanel, DokuWiki and XenForo.
The rule set officially supports ModSecurity v2 (Apache, the reference engine), ModSecurity v3 (libmodsecurity) with Nginx, and Coraza, a Go-based engine recommended for new and Kubernetes/cloud-native deployments. CRS 4 introduced a plug-in architecture, an early-blocking option, RE2/Hyperscan regex compatibility, HTTP/3 support, and improved multi-byte UTF-8 handling. The project ships official Docker images for Apache, Nginx and Caddy variants, an Envoy Gateway connector via Coraza, and integration with the Kubernetes NGINX Ingress Controller. Supporting tooling includes the crs-toolchain (regex assembly CLI), a public CRS Sandbox, go-ftw (WAF testing framework), and msc_pyparser. CRS 4.25.0 is the first Long-Term Support release (supported until Q3 2027), while legacy CRS 3.3.x support ends Q3 2026.
CRS does not generate software revenue. Its operating model is community-driven, maintained by a global pool of volunteer developers with sponsor-financed dev-on-duty support, annual developer retreats, and a Gold/Silver corporate sponsorship program. Disclosed sponsors include Google (Gold) and Swiss Post (Silver). Distribution is self-serve via GitHub releases, Docker Hub, and GitHub Container Registry; community engagement runs through OWASP Slack, GitHub, the coreruleset.org documentation site, conferences, and a YouTube channel.
OWASP CRS firmographics
Firmographics- Name
- OWASP CRS
- Legal name
- OWASP Foundation
- Website
- https://coreruleset.org
- Company type
- Private
- Founded year
- 2001
- Operating status
- Operating
- Headcount range
- 1–10 employees
- Short description
- OWASP CRS is an open-source Web Application Firewall rule set that detects common attacks such as SQL injection, XSS, and remote code execution for ModSecurity and Coraza engines, maintained by a global volunteer community under the OWASP Foundation and distributed free under Apache 2.0.
- Ownership category
- akta.pro rank
OWASP CRS industry classification
Industry- Product category
- Web Application Firewall Rules
- SIC
- Services-Computer Programming, Data Processing, Etc. (7370), Services-Computer Programming Services (7371)
- akta.pro primary industry
- Web Application Security (WAF, RASP) (HDADACAA)
- akta.pro secondary industry
- Runtime Application Self-Protection & In-App Detection (HDADACAI)
Keywords
OWASP CRS business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Personnel, Technology or R&D, Marketing or Sales, Operations
Revenue model
- Open Source Distribution: CRS is distributed freely as open-source software under the Apache 2.0 license. No direct revenue is generated from software sales.
- Sponsorship and Donations: The project operates a sponsorship program with Gold and Silver tiers. Organizations sponsor to support ongoing development and maintenance of the project.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Freemium | Pay-as-you-go | Free Open-Source Tier |
Go-to-market motion1 record
Distribution channels4 records
Marketing channels8 records
OWASP CRS product offering
Product offeringCore offering
OWASP CRS is an open-source set of generic attack detection rules written in SecLang for use with ModSecurity or compatible web application firewalls (WAF engines). The rule set provides comprehensive protection against web application attacks including SQL injection, XSS, LFI, RFI, PHP/Java code injection, SSTI, Shellshock, session fixation, and scanner/bot traffic, and is engineered to deliver OWASP Top Ten coverage with a minimum of false alerts through configurable paranoia levels and anomaly scoring. The project distributes official Docker images for ModSecurity and Coraza stacks, a public testing sandbox, plugin-based extensibility, and developer tooling such as the crs-toolchain.
Product overview
OWASP CRS is an open-source Web Application Firewall (WAF) rule set providing generic attack detection capabilities. The core product is the OWASP CRS rule set itself, which works with compatible WAF engines (ModSecurity v2/v3 and Coraza). CRS 4 introduced a plugin architecture enabling extensibility through official and third-party plugins. The product portfolio includes: the core CRS rule set (versions 3.3 LTS and 4.x), official Docker images bundling WAF engines with CRS, the public CRS Sandbox for testing, rule exclusion packages for popular web applications (WordPress, Drupal, etc.), and the crs-toolchain for developers. The rule set operates at four configurable paranoia levels (PL1-PL4) using anomaly scoring for blocking decisions, protecting against SQL injection, XSS, LFI, RFI, RCE, SSTI, and other attack categories.
Differentiator
Problem solved
Functional benefit
Products and services
- OWASP CRS (Core Rule Set) Open-source generic attack detection rule set written in SecLang for use with ModSecurity v2/v3 and Coraza web application firewalls. Protects web applications against OWASP Top Ten threats (SQL injection, XSS, LFI, RFI, PHP/Java code injection, SSTI, Shellshock, session fixation, scanner/bot traffic, metadata/error leakage) using anomaly scoring and four configurable paranoia levels (PL1–PL4).
- CRS Docker Images Official container images that bundle a WAF engine, web server, and CRS rules for fast deployment. Available variants include owasp/modsecurity-crs:4.25-lts-apache, owasp/modsecurity-crs:4.25-lts-nginx, ghcr.io/coreruleset/coraza-crs:4.25-lts-caddy, ghcr.io/coreruleset/coraza-crs:4.25-lts-nginx (experimental), and ghcr.io/coreruleset/coraza-crs:4.25-lts-apache (experimental).
- CRS Sandbox Public shared testing environment at sandbox.coreruleset.org that lets users evaluate CRS detection capabilities against real payloads without installing a local WAF. Supports multiple WAF engines (Apache/ModSecurity, Nginx/ModSecurity, Coraza/Caddy) and CRS versions, and returns matched rules in JSON, text, CSV, or HTML format for validation and research.
- Rule Exclusion Packages for Popular Web Applications Pre-built rule exclusion packages distributed as plugins to prevent false positives when deploying CRS alongside known web applications. Available for cPanel, DokuWiki, Drupal, Nextcloud, phpBB, phpMyAdmin, WordPress, and XenForo, and enabled via crs-setup.conf configuration variables.
- crs-toolchain CRS developer's command-line toolbelt for assembling regular expressions from specification files (.ra suffix). Provides processors for command-line evasion, definition substitution, file inclusion, and conditional assembly for different paranoia levels, and is used to manage CRS development workflows.
Quantifiable outcome
- Protection against OWASP Top Ten with minimum false alerts
- +1 more outcomes
Companies that use OWASP CRS
Customer profileSegments4 records
Ideal customer profiles4 records
OWASP CRS technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Integration16 records
Feature8 records
OWASP CRS partnerships and signals
Strategic signalPartnerships
Two partnerships are on record, tiered core.
- ModSecuritycoreModSecurity is the primary reference WAF engine for CRS. CRS rules are developed and tested primarily against ModSecurity v2 (Apache) with support for ModSecurity v3 (libmodsecurity) + Nginx. The ModSecurity project is maintained by OWASP as a sister project to CRS.
- Coraza WAFcoreCoraza is a modern Go-based WAF engine implementing the SecLang specification. CRS 4 officially supports Coraza as a recommended engine for new deployments, particularly for Kubernetes and cloud-native environments.
Scale indicators2 records
Recent moves6 records
Expansion highlights5 records
OWASP CRS competitors and assessment
Company assessmentBroad incumbents
- Azure Web Application Firewall: Microsoft-managed WAF on Azure Application Gateway and Front Door with built-in OWASP rule sets. A cloud-platform incumbent that competes for CRS's Kubernetes and cloud-native use cases, particularly for Microsoft-centric enterprises.
- Akamai App & API Protector: Cloud security platform from Akamai offering managed WAF rules covering OWASP Top Ten and beyond. Competes with CRS on rule-coverage breadth and accuracy, delivered as a managed service rather than self-hosted.
- F5 Distributed Cloud WAF: Enterprise WAF product from F5 (incorporating NGINX App Protect) targeting the same web application protection use cases CRS addresses, with commercial support and deeper integration into NGINX-based infrastructure.
- Cloudflare WAF: Managed WAF ruleset bundled with the Cloudflare CDN/edge platform. Competes with CRS at the rule-coverage and OWASP-Top-Ten-mitigation layer, but delivers a fully managed, zero-ops alternative that displaces self-hosted ModSecurity/Coraza+CRS deployments.
- Imperva WAF: Enterprise WAF (now part of Imperva/Thales) offering managed rule sets covering OWASP threats. Targets the same enterprise web-application protection use case as CRS, with commercial support and SLAs.
- Barracuda WAF: Commercial WAF appliance and virtual appliance with built-in OWASP coverage. Competes with CRS in mid-market and enterprise self-hosted deployments, offering a unified hardware/software/rule stack versus the CRS fragmented open-source toolchain.
- AWS WAF: AWS-managed WAF with managed rule sets including AWS-managed rule groups for OWASP Top Ten. Competes for the same workloads as CRS in cloud-native deployments, but with native AWS integration and a commercial SLA.
Direct peers
- Coraza WAF: Open-source Go-based WAF engine implementing the SecLang specification that CRS rules run on. Listed as CRS's recommended engine for new deployments, particularly in Kubernetes environments — a tightly coupled, complementary technology pairing.
- ModSecurity: OWASP sister project and the reference WAF engine for CRS rules. ModSecurity v2 (Apache) and ModSecurity v3 (libmodsecurity) are the two of three officially supported engines for CRS — the projects are interdependent at the protocol/specification level.
Emerging players
- open-appsec: Open-source WAF using machine learning for threat prevention, integrating with NGINX, Envoy, and Kubernetes Ingress. Targets the same self-hosted, Kubernetes-native deployment segment as Coraza+CRS but uses a fundamentally different detection engine.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat6 records
Key risks6 records
Key highlights6 records
Customer concentration
OWASP CRS social profiles
Digital presenceOWASP CRS financial estimates
Financial estimateRevenue estimate
Valuation estimate
OWASP CRS leadership team
Management profileNumber of profiles
OWASP CRS funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
OWASP CRS M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about OWASP CRS
What does OWASP CRS do?
OWASP CRS is an open-source set of generic attack detection rules written in SecLang for use with ModSecurity or compatible web application firewalls (WAF engines). The rule set provides comprehensive protection against web application attacks including SQL injection, XSS, LFI, RFI, PHP/Java code injection, SSTI, Shellshock, session fixation, and scanner/bot traffic, and is engineered to deliver OWASP Top Ten coverage with a minimum of false alerts through configurable paranoia levels and anomaly scoring. The project distributes official Docker images for ModSecurity and Coraza stacks, a public testing sandbox, plugin-based extensibility, and developer tooling such as the crs-toolchain.
Is OWASP CRS a public or private company?
OWASP CRS is a private company. It is classified as nonprofit foundation owned and is currently operating.
When was OWASP CRS founded?
OWASP CRS was founded in 2001. It employs 1 to 10 people.
How does OWASP CRS make money?
Two revenue lines are on record. Open Source Distribution is the primary driver. The others are sponsorship and Donations.
Who are OWASP CRS's main competitors?
Broad incumbents on record are Azure Web Application Firewall, Akamai App & API Protector, F5 Distributed Cloud WAF, Cloudflare WAF, Imperva WAF, Barracuda WAF and AWS WAF. Direct peers are Coraza WAF and ModSecurity. open-appsec is listed as an emerging player.
Does OWASP CRS have an API?
No public API is recorded for OWASP CRS.
What industry is OWASP CRS in?
OWASP CRS's product category is Web Application Firewall Rules. Its primary akta.pro industry code is HDADACAA, Web Application Security (WAF, RASP), with a secondary code of HDADACAI, Runtime Application Self-Protection & In-App Detection. Its SIC code is 7370.