WAF Detector — Web Application Firewall Identifier
Pricing
Pay per usage
WAF Detector — Web Application Firewall Identifier
Detect WAF presence and identify the vendor. Fingerprints 15+ WAFs: Cloudflare, Akamai, Imperva, Sucuri, Fastly, AWS WAF, Azure Front Door, F5, ModSecurity, Wordfence. Header, cookie, body & CNAME fingerprinting + attack-payload probe. No API key.
Pricing
Pay per usage
Rating
0.0
(0)
Developer
Hojun Lee
Maintained by CommunityActor stats
0
Bookmarked
2
Total users
1
Monthly active users
20 hours ago
Last modified
Categories
Share
Detect whether a website is protected by a WAF (Web Application Firewall) and identify the vendor. Fingerprints 15+ WAFs including Cloudflare, Akamai, Imperva, Sucuri, Fastly, AWS WAF, Azure Front Door, F5, ModSecurity, and Wordfence. No API key required.
How It Works
- Header fingerprinting — inspects response headers (
Server,CF-RAY,X-Sucuri-ID, etc.) - Cookie fingerprinting — looks for vendor-specific cookies (
__cfduid,incap_ses_*,BIGipServer*) - Attack-payload probe — sends a harmless XSS/SQLi-shaped request and inspects the block page for vendor fingerprints
- CNAME resolution — resolves DNS CNAMEs for additional vendor edge-network hints
Each candidate match is scored (0–100) using weighted evidence across all four signals, and the highest-confidence match is reported as primary_waf.
Use Cases
- Security audits — confirm a client's site is actually behind the WAF they're paying for
- Pentesting recon — identify filtering/blocking infrastructure before testing
- Competitive research — see what security stack competitors use
- Vendor migration checks — verify a WAF cutover actually took effect
Input
| Field | Type | Description | Default |
|---|---|---|---|
urls | string[] | URLs to scan for WAF presence | ["https://example.com"] |
maxUrls | integer | Max URLs per run (1–500) | 100 |
concurrency | integer | Parallel URL checks | 10 |
Output
{"url": "https://example.com","domain": "example.com","waf_detected": true,"waf_count": 1,"primary_waf": "Cloudflare","primary_confidence": 95,"detected_wafs": [{"waf": "Cloudflare","confidence": 95,"evidence": ["header:server=cloudflare", "cname:cdn.cloudflare.net"]}],"checked_at": "2026-10-01T10:00:00Z"}
Pricing
Pay-per-event: $0.005 per URL checked.