IT AI Index
Index Vendors › ModSecurity · September 2026 Edition
1 category · Ranked

ModSecurity

36Judge labels
0First choices
22Negative labels
10 of 12Models named it
1Category
September 2026 Edition. Every number here is derived from the raw labels under vendor table vv2026-09.2, every buyer segment counted.
Best standing
0% in WAF for mid-market buyers
Rank 87 of 87 in the mid-market standingcriticized challenger
0 of 12 models made it the first choice on the direct prompt; 56% of its 18 labels there were negative.
By buyer segmentRead the same way at every buyer size.
In waf · each standing computed within its segment · bars are 0 to 100 · the accent bar is the product's own best reading

Standing by category

Every category where a model named ModSecurity for a mid-market B2B company. Share is first choices across the direct, paraphrase, budget and scale prompts; rank is within every product named in that category.
CategoryFunctionShareRankNegative rateLabelsQuadrant
Web application firewallsNetwork and edge0%87 of 8756%18criticized challenger

Movement

This is the first edition on this tier, so no move can be computed for ModSecurity yet. From the next edition this section shows, per buyer segment, whether its share moved by more than the measured noise floor.

By model

How each model treated ModSecurity across every prompt where it was named for a mid-market B2B company. Twelve models, six prompts per category.
ModelFirst choiceAlternativeMentionNegativeLabels
Claude Haiku 4.501012
GPT-5.4 mini01001
Gemini 3.5 Flash00011
Perplexity Sonar00000
Grok 4.1 Fast01012
Mistral Small00101
DeepSeek V4 Flash01012
Llama 4 Maverick00000
Qwen 3.7 Flash01023
Kimi K201023
GLM 4.7 FlashX00112
MiniMax M2.500011

By framing

Which of the six questions produced the naming. By model says how often; this says asked what. The first-choice count on the right carries the marks of the models that produced it.
FramingLabels by classFirst choices
Direct2 labelsNone
Paraphrase0 labelsNone
Comparative6 labelsNone
Budget-constrained11 labelsNone
Scale-constrained3 labelsNone
Negative14 labelsNone
First choiceAlternativeMentionNegative36 labels in all, every segment counted; 0 of the 0 first choices count toward share, since the comparative and negative framings do not. The bar is one segment per label class, to scale within the framing.

What the models said for it

Verbatim evidence the judge attached to positive labels.

“For technical teams with some security expertise: ModSecurity ... gives you full control at zero software cost.” Kimi K2 · WAF · budget prompt · alternative
“the industry gold standard open-source option is ModSecurity with the OWASP Core Rule Set (CRS)” DeepSeek V4 Flash · WAF · budget prompt · alternative
“ModSecurity with OWASP Core Rule Set is the gold standard for free web application protection” Claude Haiku 4.5 · WAF · budget prompt · alternative
“Gold standard with OWASP CRS; requires technical setup/maintenance.” Grok 4.1 Fast · WAF · budget prompt · alternative

And against it

Verbatim evidence attached to negative labels. A warning on a product with few labels is a warning; on a product with many, it is one voice among them.

“Avoid: Unmanaged Open Source (ModSecurity/CoreRuleSet) ... Do not install this unless you have a dedicated security engineer” Qwen 3.7 Flash · WAF · negative prompt · hard negative
“Avoid running self-hosted, unmaintained ModSecurity engines on production servers.” Gemini 3.5 Flash · WAF · negative prompt · hard negative
“Completely free and self-hosted, but requires significant technical expertise to configure and maintain.” Qwen 3.7 Flash · WAF · comparative prompt · soft negative
“Excessive false positives (esp. SQLi/XSS rules); requires heavy tuning; crashes/bugs in older versions.” Grok 4.1 Fast · WAF · negative prompt · soft negative

Named alongside

The products named in the same answers as ModSecurity, over the 36 answers that named it. Took the first choice instead counts the answers where the other product was the first choice and ModSecurity was named but was not.
ProductSame answerTook the first choice insteadHead to head
AWS WAF26 of 363Not in the top three
Cloudflare22 of 3614Not in the top three
Imperva15 of 360Not in the top three
Sucuri14 of 361Not in the top three
Akamai14 of 360Not in the top three
Cloudflare WAF13 of 3610Not in the top three
Azure WAF8 of 360Not in the top three
Coraza8 of 360Not in the top three
Barracuda6 of 360Not in the top three
Fastly6 of 360Not in the top three
A head-to-head page exists where both products are in a category's top three. The other rows are the same fact without a page behind them, so they link to the product instead.

What carried it into the answer

The sites and pages cited by the answers that named ModSecurity. A fact about retrieval, not a lever on the model.

Citations exist only for the models that return a source list, four of the twelve in this edition, so these counts come from 24 of the 36 answers that named ModSecurity and are not a share of its labels.

Domains cited

wafplanet.com17
openappsec.io16
cyberpress.org15
comparitech.com11
geekflare.com11
dev.to8
expertinsights.com8
reddit.com8
cybersecuritynews.com7
indusface.com6

107 of the 107 domain citations in answers naming ModSecurity came from somebody else's page.

Pages cited

Pages are listed as the models cited them.

Names read as ModSecurity

What the judge wrote, as written, with how often. The vendor table decides that these count as ModSecurity; a claim can dispute any of them.
ModSecurity (open-source) 1ModSecurity (open-source, often with OWASP CRS) 1
Is this your product?

Claim this page

Claiming is free and changes nothing in the data. A claimed page shows a verified contact who is told when each edition publishes and when ModSecurity's standing changes by more than the noise floor; the right to propose corrections to the vendor table, meaning names the judge wrote that should or should not read as ModSecurity, applied by version and listed in the change log; and a one-line description supplied by the vendor and marked as such.

It does not get any change to labels, shares or verdicts, any preview, or any say over which quotes appear. A verification link goes to your work email; an address at modsecurity.org is approved on the spot, any other address is reviewed by hand.

Your name and company appear on the claimed page, or the company alone if you ask below. A title and a LinkedIn address appear there too if you give them, and are left off if you do not. Your email address is never published.

Subscribe to the pack