| Category | Function | Share | Rank | Negative rate | Labels | Quadrant |
|---|---|---|---|---|---|---|
| Web application firewalls | Network and edge | 0% | 87 of 87 | 56% | 18 | criticized challenger |
| Model | First choice | Alternative | Mention | Negative | Labels |
|---|---|---|---|---|---|
| Claude Haiku 4.5 | 0 | 1 | 0 | 1 | 2 |
| GPT-5.4 mini | 0 | 1 | 0 | 0 | 1 |
| Gemini 3.5 Flash | 0 | 0 | 0 | 1 | 1 |
| Perplexity Sonar | 0 | 0 | 0 | 0 | 0 |
| Grok 4.1 Fast | 0 | 1 | 0 | 1 | 2 |
| Mistral Small | 0 | 0 | 1 | 0 | 1 |
| DeepSeek V4 Flash | 0 | 1 | 0 | 1 | 2 |
| Llama 4 Maverick | 0 | 0 | 0 | 0 | 0 |
| Qwen 3.7 Flash | 0 | 1 | 0 | 2 | 3 |
| Kimi K2 | 0 | 1 | 0 | 2 | 3 |
| GLM 4.7 FlashX | 0 | 0 | 1 | 1 | 2 |
| MiniMax M2.5 | 0 | 0 | 0 | 1 | 1 |
Verbatim evidence the judge attached to positive labels.
“For technical teams with some security expertise: ModSecurity ... gives you full control at zero software cost.” Kimi K2 · WAF · budget prompt · alternative
“the industry gold standard open-source option is ModSecurity with the OWASP Core Rule Set (CRS)” DeepSeek V4 Flash · WAF · budget prompt · alternative
“ModSecurity with OWASP Core Rule Set is the gold standard for free web application protection” Claude Haiku 4.5 · WAF · budget prompt · alternative
“Gold standard with OWASP CRS; requires technical setup/maintenance.” Grok 4.1 Fast · WAF · budget prompt · alternative
Verbatim evidence attached to negative labels. A warning on a product with few labels is a warning; on a product with many, it is one voice among them.
“Avoid: Unmanaged Open Source (ModSecurity/CoreRuleSet) ... Do not install this unless you have a dedicated security engineer” Qwen 3.7 Flash · WAF · negative prompt · hard negative
“Avoid running self-hosted, unmaintained ModSecurity engines on production servers.” Gemini 3.5 Flash · WAF · negative prompt · hard negative
“Completely free and self-hosted, but requires significant technical expertise to configure and maintain.” Qwen 3.7 Flash · WAF · comparative prompt · soft negative
“Excessive false positives (esp. SQLi/XSS rules); requires heavy tuning; crashes/bugs in older versions.” Grok 4.1 Fast · WAF · negative prompt · soft negative
Citations exist only for the models that return a source list, four of the twelve in this edition, so these counts come from 24 of the 36 answers that named ModSecurity and are not a share of its labels.
107 of the 107 domain citations in answers naming ModSecurity came from somebody else's page.
Pages are listed as the models cited them.
Claiming is free and changes nothing in the data. A claimed page shows a verified contact who is told when each edition publishes and when ModSecurity's standing changes by more than the noise floor; the right to propose corrections to the vendor table, meaning names the judge wrote that should or should not read as ModSecurity, applied by version and listed in the change log; and a one-line description supplied by the vendor and marked as such.
It does not get any change to labels, shares or verdicts, any preview, or any say over which quotes appear. A verification link goes to your work email; an address at modsecurity.org is approved on the spot, any other address is reviewed by hand.
Your name and company appear on the claimed page, or the company alone if you ask below. A title and a LinkedIn address appear there too if you give them, and are left off if you do not. Your email address is never published.