WAF Detector — Web Application Firewall Identifier avatar

WAF Detector — Web Application Firewall Identifier

Pricing

Pay per usage

Go to Apify Store
WAF Detector — Web Application Firewall Identifier

WAF Detector — Web Application Firewall Identifier

Detect WAF presence and identify the vendor. Fingerprints 15+ WAFs: Cloudflare, Akamai, Imperva, Sucuri, Fastly, AWS WAF, Azure Front Door, F5, ModSecurity, Wordfence. Header, cookie, body & CNAME fingerprinting + attack-payload probe. No API key.

Pricing

Pay per usage

Rating

0.0

(0)

Developer

Hojun Lee

Hojun Lee

Maintained by Community

Actor stats

0

Bookmarked

2

Total users

1

Monthly active users

20 hours ago

Last modified

Categories

Share

Detect whether a website is protected by a WAF (Web Application Firewall) and identify the vendor. Fingerprints 15+ WAFs including Cloudflare, Akamai, Imperva, Sucuri, Fastly, AWS WAF, Azure Front Door, F5, ModSecurity, and Wordfence. No API key required.

How It Works

  1. Header fingerprinting — inspects response headers (Server, CF-RAY, X-Sucuri-ID, etc.)
  2. Cookie fingerprinting — looks for vendor-specific cookies (__cfduid, incap_ses_*, BIGipServer*)
  3. Attack-payload probe — sends a harmless XSS/SQLi-shaped request and inspects the block page for vendor fingerprints
  4. CNAME resolution — resolves DNS CNAMEs for additional vendor edge-network hints

Each candidate match is scored (0–100) using weighted evidence across all four signals, and the highest-confidence match is reported as primary_waf.

Use Cases

  • Security audits — confirm a client's site is actually behind the WAF they're paying for
  • Pentesting recon — identify filtering/blocking infrastructure before testing
  • Competitive research — see what security stack competitors use
  • Vendor migration checks — verify a WAF cutover actually took effect

Input

FieldTypeDescriptionDefault
urlsstring[]URLs to scan for WAF presence["https://example.com"]
maxUrlsintegerMax URLs per run (1–500)100
concurrencyintegerParallel URL checks10

Output

{
"url": "https://example.com",
"domain": "example.com",
"waf_detected": true,
"waf_count": 1,
"primary_waf": "Cloudflare",
"primary_confidence": 95,
"detected_wafs": [
{
"waf": "Cloudflare",
"confidence": 95,
"evidence": ["header:server=cloudflare", "cname:cdn.cloudflare.net"]
}
],
"checked_at": "2026-10-01T10:00:00Z"
}

Pricing

Pay-per-event: $0.005 per URL checked.