Hello aaPanel community,
I would like to share WAF Pro 2.0, a standalone Web Application Firewall designed for aaPanel.
GitHub Repository:
https://github.com/ByEzel93/wafpro
Direct Download (v2.0):
https://github.com/ByEzel93/wafpro/releases/download/2.0/wafpro-2.0.zip
What is it?
WAF Pro is a fully independent Nginx WAF for aaPanel.
- Does not depend on aaPanel’s free WAF
- Does not require btwaf
- Uses its own Lua-based protection engine
- Supports hot-reload configuration updates without restarting Nginx
Main Features
- Live attack dashboard
- Per-site protection controls
- GET / POST / Cookie / User-Agent filtering
- CC attack protection
- Fake crawler blocking
- IP & URL blacklist/whitelist
- Country-based blocking
- URL-based rate limiting
- Custom multi-condition rules
- Automatic IP banning
- Attack map and analytics reports
- Configuration export/import
Installation
- Download the package directly:
https://github.com/ByEzel93/wafpro/releases/download/2.0/wafpro-2.0.zip
- In aaPanel, go to App Store → Custom Plugin and upload the ZIP file.
- Open the plugin and enable “Engine wired into nginx” from the Global tab.
- Enable protection for the websites you want to secure.
Important Notice
This is a community project provided as-is. It has not undergone extensive long-term production testing yet. Please test it on a staging or non-critical server before deploying it in a production environment.
Feedback & Bug Reports
GitHub Issues:
https://github.com/ByEzel93/wafpro/issues
About Forum Rules
If this post or the repository is considered incompatible with aaPanel forum policies, I am willing to remove the post and/or the repository. This project is shared solely for community use and learning purposes and is not intended as a commercial product.
Thank you for your time, and I appreciate any feedback or suggestions.