Zero of fourteen models named ModSecurity first on the direct prompt; one named AWS WAF. ModSecurity was named by twelve of the fourteen models and AWS WAF by fourteen and ModSecurity carries 26 labels and AWS WAF 54, so the shares are not directly comparable.
Named in one category this edition.
Named in four categories this edition.
Share is the count of first choices across the direct, paraphrase, budget and scale prompts over all fourteen models, for a mid-market B2B company; rank is within the category; every quote names the model and the prompt it came from. Both figures come from the web application firewalls page.
Across every category in the October 2026 Edition, ModSecurity and AWS WAF were named in the same answer forty-four times, of the 58 answers naming ModSecurity and the 181 naming AWS WAF. In those answers AWS WAF took the first choice one time and ModSecurity two.
| Model | Direct | Paraphrase | Comparative | Budget-constrained | Scale-constrained | Negative |
|---|---|---|---|---|---|---|
| Claude Haiku 4.5 | ||||||
| GPT-5.4 mini | ||||||
| Gemini 3.5 Flash | ||||||
| Perplexity Sonar | ||||||
| Grok 4.1 Fast | ||||||
| Mistral Small | ||||||
| DeepSeek V4 Flash | ||||||
| Llama 4 Maverick | ||||||
| Qwen 3.7 Flash | ||||||
| Kimi K2 | ||||||
| GLM 4.7 FlashX | ||||||
| MiniMax M2.5 | ||||||
| GPT-6 Luna | ||||||
| Muse Glimmer 30B |
Bold names in an answer are the products the judge labeled a first choice; a model naming several gives each of them that label. The full answer text for every row is in the record.
Every negative label with a quote, up to three, then the highest-weighted positives, up to three. Six of eight in this category shown.
“ModSecurity, the classic open-source WAF engine, has reached End-of-Life (EOL).” Gemini 3.5 Flash · budget prompt · hard negative
“Avoid/Be cautious with: Unpatched ModSecurity v3 versions” Kimi K2 · negative prompt · hard negative
“A critical vulnerability (CVE-2025-47947) in ModSecurity, a widely deployed open-source WAF, allows attackers to crash systems through denial of service attacks” Claude Haiku 4.5 · negative prompt · soft negative
“If you want the absolute lowest cost and have internal sysadmin skills: go with ModSecurity (free) + OWASP CRS.” MiniMax M2.5 · budget prompt · first choice
“best-value WAF is usually an open-source stack: ModSecurity + OWASP Core Rule Set (CRS)” GPT-5.4 mini · budget prompt · first choice
“ModSecurity with OWASP CRS is the de-facto standard free engine.” Muse Glimmer 30B · budget prompt · first choice
Every negative label with a quote, up to three, then the highest-weighted positives, up to three. Six of eight in this category shown.
“using the provider's native WAF (e.g., AWS WAF) is highly convenient... but may require more manual configuration and rule writing” Gemini 3.5 Flash · scale prompt · soft negative
“AWS WAF, for example, has an 8 KB inspection limit on Application Load Balancers and AppSync; gRPC request bodies aren't inspected” GPT-6 Luna · negative prompt · soft negative
“The WAFFLED results show parsing discrepancies affect AWS, Azure, Cloud Armor, Cloudflare and ModSecurity alike.” Muse Glimmer 30B · negative prompt · soft negative
“Cloudflare or AWS WAF usually give the quickest time-to-value, decent out-of-the-box rules, and scalable bot mitigation” MiniMax M2.5 · paraphrase prompt · first choice
“I'd suggest starting with either Cloudflare WAF ... or AWS WAF (if you're already AWS-based)” Claude Haiku 4.5 · direct prompt · first choice
“Consider managed WAF services (AWS WAF, Azure WAF, Cloudflare) for better maintenance and faster patching” Kimi K2 · negative prompt · alternative
Comparisons are drawn for the top eight products in each category, each against each. The output is the models' output; nothing here is a recommendation by the index.