We’ve been using SafeLine for a few months now on several production applications. What we really like is the self-hosted nature — it gives us full control over traffic filtering and logging without sending data to a third-party service. Deployment was pretty straightforward (we’re using it with Docker), and the documentation was good enough to get us up and running quickly.
In terms of protection, it handles common web attacks well, especially SQL injection and XSS. The custom rule feature is very useful — we’ve added a few business-specific filters without much hassle. Performance-wise, it hasn’t introduced noticeable latency.
The development team is frequently maintaining the project. Their support is also very fast and incredibly awesome.
Overall, it’s a great fit if you want a reliable, customizable WAF you can fully control. Would recommend it to teams that have some technical background and want an alternative to cloud-based WAFs. Review collected by and hosted on G2.com.
Documentation is not very complete and helpful Review collected by and hosted on G2.com.