# ModSecurity: how AI models rank it, September 2026

IT AI Recommendation Index, September 2026 Edition. Named in 18 judge labels across 1 categories by 10 of 12 models. Page: https://it-ai-index.com/vendors/modsecurity/

## Standing by category

| Category | Share | Rank | Negative rate | Labels |
|---|---|---|---|---|
| Web application firewalls | 0% | 87 | 56% | 18 |

## What the models said for it

- "For technical teams with some security expertise: ModSecurity ... gives you full control at zero software cost." (Kimi K2, WAF)
- "the industry gold standard open-source option is ModSecurity with the OWASP Core Rule Set (CRS)" (DeepSeek V4 Flash, WAF)
- "ModSecurity with OWASP Core Rule Set is the gold standard for free web application protection" (Claude Haiku 4.5, WAF)
- "Gold standard with OWASP CRS; requires technical setup/maintenance." (Grok 4.1 Fast, WAF)

## And against it

- "Avoid: Unmanaged Open Source (ModSecurity/CoreRuleSet) ... Do not install this unless you have a dedicated security engineer" (Qwen 3.7 Flash, WAF)
- "Avoid running self-hosted, unmaintained ModSecurity engines on production servers." (Gemini 3.5 Flash, WAF)
- "Completely free and self-hosted, but requires significant technical expertise to configure and maintain." (Qwen 3.7 Flash, WAF)
- "Excessive false positives (esp. SQLi/XSS rules); requires heavy tuning; crashes/bugs in older versions." (Grok 4.1 Fast, WAF)

## Record

- Method: https://it-ai-index.com/methodology/
- Raw judge labels and full responses: https://it-ai-index.com/data/
- License: CC BY 4.0. Cite as IT AI Recommendation Index, September 2026 Edition, it-ai-index.com.
