Free tool · Coming soon

WAF Detector.What’s guarding the front door?

Detect which WAF or security edge is protecting a site, how it behaves toward ordinary traffic, and what that choice implies for performance, from passive fingerprints only: no attack traffic, no exploit probes, nothing a production site would ever notice.

AT A GLANCEWAF Detector
IN DEVELOPMENT
In buildpart of the first wave
Freeno signup required
Passivefingerprinting only
WAAPedges & CDN WAFs covered
Shareableevidence-backed reports
2026launch window
Part of the CDN World toolkit · first releases in build, July 2026
Freeto use, forever
No signuprequired to run it
Shareableevidence-backed reports
In buildfirst releases, 2026
Measured in your browserWe advise on speed. We practice it.Loaded just now · real numbers from this visit, not a lab score.
Page loaded
First byte
DOM ready
First paint
Largest paint
DNS lookup
TLS handshake
Transferred
Saved by compression
Requests
What it answers

WAF Detector in four questions.

Which WAF is in front

Cloud WAAP, CDN-bundled WAF or appliance: identified from response signatures and challenge behavior.

Its posture toward normal traffic

How the edge treats ordinary requests: challenges, cookies, header rewrites, and what that costs in latency.

The evidence

Every fingerprint that fired, so a security team can verify the identification independently.

The performance implication

Security layers are delivery layers; the report notes what the detected stack typically adds to response times.

Under the hood

How it works.

The same signals our analysts use in paid assessments, automated.

DETECTIONHow it works
Response signature analysis · headers & error pages

WAF products leave consistent fingerprints in headers, cookies and block-page markup; we match them against a maintained library.

Core
Challenge-behavior observation · passive only

How the edge issues JavaScript or interstitial challenges to a plain browser-like request identifies families of products.

Core
Benign-request variation · no attack traffic

Only ordinary, harmless request variations are used, the tool never sends exploit payloads or malformed traffic.

Principle
Edge correlation · CDN context

Cross-referenced with CDN detection, because on modern stacks the WAF and the CDN are usually the same vendor decision.

Supporting
The report

What you’ll get.

THE OUTPUTInside the report
Detected security edge

The product or service in front, with confidence scoring.

Included
Observed behaviors

Challenges, cookies and header rewrites seen during detection.

Included
Performance notes

What the detected stack typically means for latency and caching.

Included
Shareable report

Evidence included, ready for a security review thread.

Included
Use cases

Who it’s for.

Security due diligence

Know what actually protects a property you’re acquiring, auditing or integrating with.

Vendor verification

Confirm the WAF you pay for is the WAF that answers, misrouted zones are more common than anyone admits.

Consolidation planning

Mapping WAFs across an estate is step one of collapsing three security vendors into one.

Market research

See which security edges your market actually deploys, not which ones sponsor conferences.

Status & early access

Free at launch. In build now.

STATUSWhere the build stands
IN DEVELOPMENT
Freeat launch, no signup
2026launch window
200+assessments/yr behind the data
Earlyaccess list open now
Built on assessment data

The toolkit automates the detection and benchmark data behind the assessments we already run, the tools are how we prove the data is good.

Free, no signup, shareable

Every tool ships free with shareable reports; the business model is the advisory behind it, not your email address.

In development now

First releases are in build. Dates are windows, not promises, we ship when the detection is trustworthy.

UNTIL IT SHIPSGet early access →

Want the answer before the tool exists? A free assessment runs the same analysis, human-graded, usually within 24 hours, and puts you on the early-access list for WAF Detector.

Status as of July 2026 · join the list and we’ll notify you at launch
FAQ

WAF Detector questions,
answered straight.

When does WAF Detector launch?

It’s in development as part of the first toolkit wave, with a 2026 launch window; the tools page has the early-access list.

Is this a security scanner?

No, and deliberately so. It sends only ordinary, benign requests and identifies the protection layer from passive fingerprints. It never sends attack payloads, probes for vulnerabilities, or does anything a production site would register as hostile.

Which products can it identify?

The launch library targets the WAFs and WAAP edges we meet most in assessments, the major CDN-bundled WAFs and standalone cloud products, and it will grow the way our CDN signature library did.

Can a WAF hide from it?

Some deployments mask well, and the report says so honestly: a low-confidence result with the evidence shown beats a confident guess.

Why does a CDN advisory build a WAF tool?

Because on modern stacks the WAF and CDN are one buying decision, you can’t advise on delivery without seeing the security layer in front of it.

I need this answered today.

A security-focused assessment covers WAF identification and posture, human-graded.