Pricing plan

Great value at an affordable rate. No hidden costs. No frills.

The Open source version

Freely use the open source version of BunkerWeb to secure your web services. This solution is perfectly suited for hobbyists, organizations with no specific professional needs or simply for testing the solution before using it.

Our professional offers

Explore our professional plans with no commitment.
If the Free plan isn’t enough for your needs, we’ve got you covered — our PRO offers give you access to advanced features, enhanced protection, and expert support.
Enjoy a 30-day free trial on all paid plans and discover the full potential of BunkerWeb.
Upgrade or cancel anytime — you’re in control.

Standard

Shield
Perfect for SMBs, tech startups, and growing IT projects

49€
/monthly
Includes:
Start with a 30 days of free trial
Most Popular
Enterprise

Fortress
Designed for multi-site organizations, scale-ups, and sensitive industries (healthcare, finance, education...)

149€
/monthly
Includes:
Start with a 30 days of free trial
Custom

Sentinel
Do you have specific needs? Let's find a tailored solution to fit your unique requirements

Get a quote based on your needs
Includes:

A fully tailored solution, built around your specific business needs.

OUr Value

Open Source Power, Managed for You

BunkerWeb CLOUD gives you the flexibility and transparency of open source security, with the convenience of a SaaS solution fully operated by our experts.

The Cloud offer

The essential

Starting from
639€
/monthly
Includes:
or Need more ?
Get a quote based on your needs
Includes:

Tell us more about your project, we will come back to you shortly.

ALl plugins list

The core (free) list plugins : 
PluginDescriptionCategory
AntibotDetects and blocks typical malicious bot behavior.Core (Free)
Auth basicProtects access to certain resources using basic HTTP authentication.Core (Free)
BackupLocal backup of BunkerWeb configuration and settings.Core (Free)
Bad BehaviorFilters abnormal HTTP requests to prevent abuse.Core (Free)
BlacklistManually blocks specific IPs or IP ranges.Core (Free)
BrotliEnables Brotli compression to optimize page load times.Core (Free)
BunkerNetCommunity-based IP blocking via the BunkerNet network.Core (Free)
Client cacheConfigures cache headers for clients to improve performance.Core (Free)
CORSManages permissions for cross-origin requests (CORS).Core (Free)
CountryApplies rules based on the visitor's country of origin.Core (Free)
CrowdSecIntegrates CrowdSec's collaborative IP protection.Core (Free)
Custom SSL certificateAllows using custom SSL certificates to secure connections.Core (Free)
DNSBLChecks client IPs against public DNS blacklists to detect threats.Core (Free)
DatabaseConfigures access to a database to store specific data.Core (Free)
ErrorsCustomizes the HTTP error pages shown to users.Core (Free)
GreylistIntroduces a delay for certain requests to detect suspicious behavior.Core (Free)
GzipEnables Gzip compression to reduce HTTP response sizes and speed up load times.Core (Free)
HTML injectionInjects custom HTML into served pages (e.g., banners or scripts).Core (Free)
HeadersManages and modifies HTTP headers to enhance security and privacy.Core (Free)
Let's EncryptAutomatically handles SSL certificates via Let's Encrypt.Core (Free)
LimitLimits requests from the same source to prevent abuse or DoS attacks.Core (Free)
MetricsCollects and exposes performance metrics for monitoring.Core (Free)
MiscellaneousProvides additional options to fine-tune BunkerWeb behavior.Core (Free)
ModSecurityIntegrates the ModSecurity WAF engine for advanced protection.Core (Free)
PHPConfigures and optimizes PHP script execution for web apps.Core (Free)
Real IPEnsures BunkerWeb uses the client’s real IP by analyzing appropriate headers.Core (Free)
RedirectConfigures URL redirections to direct traffic as needed.Core (Free)
RedisIntegrates Redis for temporary data storage and caching.Core (Free)
Reverse ProxyEnables BunkerWeb to act as a reverse proxy, routing requests to backend servers.Core (Free)
Reverse scanAnalyzes client behavior in response to specific info to detect anomalies.Core (Free)
SSLManages SSL/TLS settings to secure connections, including certificate and protocol support.Core (Free)
Security.txtServes a standards-compliant `security.txt` file for security contact info.Core (Free)
Self-signed certificateAutomatically generates and uses self-signed SSL/TLS certificates — ideal for dev or internal use.Core (Free)
SessionsManages user sessions, including cookie settings and expiration.Core (Free)
Web UIProvides a web interface to manage and configure BunkerWeb easily.Core (Free)
WhitelistManages a list of trusted IPs with unrestricted access.Core (Free)
The externals list free plugins : 
PluginDescriptionCategory
ClamAVLocal antivirus scanning for uploaded files.External (Free with setup)
CorazaHigh-performance open-source WAF based on OWASP CRS.External (Free with setup)
DiscordSends security alerts to a Discord channel via webhook.External (Free with setup)
SlackSends security alerts to a Slack channel via webhook.External (Free with setup)
VirusTotalScans uploaded files via the VirusTotal API.External (Free with setup)
WebhookSends customizable alerts to a specified HTTP endpoint.External (Free with setup)
Icon_pro_BW The PRO list plugins :
PluginDescriptionCategory
Anti-DDoSAdvanced protection against DDoS attacks.PRO (Paid)
Backup S3Remote backup to Amazon S3.PRO (Paid)
MigrationEasily migrate the database between environments.PRO (Paid)
MonitoringMonitor service status and performance.PRO (Paid)
Prometheus ExporterExposes metrics for Prometheus, compatible with Grafana.PRO (Paid)
ReportingGenerates weekly or monthly usage and threat reports.PRO (Paid)
User ManagerManage users and their access rights.PRO (Paid)
Common Questions

Most Popular Questions

Have questions? We’ve gathered answers to the most common inquiries to help you get the most out of BunkerWeb. Explore our FAQ for quick insights, or feel free to reach out if you need more information – the BunkerTeam is here to assist!

BunkerWeb is a next-generation and open-source Web Application Firewall (WAF).

Being a full-featured web server focused on cybersecurity, it will protect your web services to make them "secure by default". BunkerWeb integrates seamlessly into your existing environments (Linux, Docker, Swarm, Kubernetes, …) and is fully configurable (don't panic, there is an awesome web UI if you don't like the CLI) to meet your own use-cases . In other words, cybersecurity is no more a hassle.

BunkerWeb contains primary security features as part of the core but can be easily extended with additional ones thanks to a plugin system.

BunkerWeb protects your web applications from a wide range of threats, including SQL injection, XSS, and DDoS attacks. It also provides features like rate limiting and WAF customization to tailor protection to your specific needs."

With BunkerWeb, you can safeguard your web services from common vulnerabilities and attacks. It offers comprehensive protection for your applications and APIs.

BunkerWeb sets itself apart from other Web Application Firewalls (WAFs) through several key features:

  • Open-source and highly customizable: As an open-source project, BunkerWeb offers complete transparency and allows for deep customization to cater to specific security needs. This flexibility ensures that it can adapt to a wide range of environments and threat landscapes.
  • Seamless integration: BunkerWeb seamlessly integrates into your existing infrastructure, whether you're using Linux, Docker, Kubernetes, or other popular technologies. This streamlined integration process minimizes disruption and reduces deployment time.
  • Advanced features: Beyond basic WAF functionalities, BunkerWeb offers advanced features such as custom rule creation, integration with third-party security tools, and an extensible plugin system. This enables users to tailor their security posture to their exact requirements.
  • Active community: Backed by a vibrant community of developers and users, BunkerWeb benefits from continuous improvement and support. This ensures that the solution remains up-to-date and adaptable to evolving threats.

BunkerWeb can be easily integrated into your existing infrastructure as a reverse proxy, intercepting all HTTP/HTTPS traffic to your web applications. It supports various deployment options, including:

  • Standalone installation: Deploy BunkerWeb on your own servers.
  • Containerization: Use Docker or Kubernetes to containerize BunkerWeb and manage it within your container orchestration platform.
  • Cloud-based deployments: Integrate BunkerWeb with popular cloud platforms like AWS, GCP, or Azure.

 

Yes, BunkerWeb is designed with user-friendliness in mind. It features an intuitive web interface that allows you to configure and manage your WAF without requiring in-depth technical expertise. Additionally, the comprehensive documentation and active community provide ample support for users of all levels.

Key factors contributing to BunkerWeb's ease of use include:

  • Clear and concise documentation: The documentation is well-structured and easy to follow, making it simple for users to get started.
  • Intuitive web interface: The web interface provides a visual representation of your security configuration, making it easy to understand and manage.
  • Community support: The active community provides a valuable resource for troubleshooting and seeking advice.

In summary, BunkerWeb is a powerful and flexible WAF that offers a combination of advanced features, ease of use, and community support, making it an excellent choice for organizations seeking to enhance their web application security.

Get in touch

Contact the BunkerTeam

Whether you’re looking for support, more information, or just want to connect, the BunkerTeam is ready to assist. Let’s secure the web together!

contact@bunkerweb.io

Follow our social media

Send us a message
Feel free to send us any questions, feedback or suggestions you might have.