History of ModSecurity

ModSecurity’s story spans independent innovation, commercial development, and now community-driven stewardship under OWASP. This history provides an overview of how the project has grown and adapted over time.


2002–2006 Early Beginnings

ModSecurity began as Ivan Ristić’s personal quest in 2002, to give Apache a way to understand and control HTTP traffic. The small module quickly gained attention, and by 2004 it had become Ivan’s full-time focus under his company, Thinking Stone. In 2006, Thinking Stone was acquired by Breach Security, and with more support behind it, ModSecurity 2.0 was completed and unveiled at the OWASP AppSec conference in Seattle, widely considered the project’s first big milestone.

2006–2010 Growth and Community Adoption

ModSecurity grew from a promising idea into a widely trusted tool, with Breach Security shepherding major improvements including the 2.5 release in 2008. Shortly afterward Ivan moved on, but the project kept its momentum. In 2010, Breach was acquired by Trustwave, which relicensed ModSecurity under the Apache License, making it far easier for other vendors and developers to integrate into their own platforms.

2010–2023 Trustwave Era

Under Trustwave, ModSecurity was ported to IIS and NGINX in 2012, reaching more platforms than ever. Its biggest transformation came from within: work on libModSecurity (v3) began in 2015, a standalone, modular engine built to work through connectors rather than tie to a single web server, and the 3.x branch launched in 2018. By 2021, Trustwave retired its commercial ModSecurity offerings, signaling a shift toward community-led stewardship.

2024 Custodianship Transfer to OWASP

In 2024, the transition became official: Trustwave transferred custodianship of ModSecurity to OWASP. This decision ensured the project would continue under open governance, transparent leadership, and a global community committed to its future. It was a pivotal moment that brought ModSecurity back into the heart of the open-source security world.

2024–Present The OWASP ModSecurity Project Today

Today, ModSecurity lives on as a fully community-driven OWASP project: actively maintained, openly governed, and closely aligned with the OWASP Core Rule Set (CRS). It continues to protect countless web applications across Apache, NGINX, and beyond, shaped by contributors worldwide advancing open-source web application security. What began as a small Apache module in 2002 now lives on through a global community, with the story still being written.

Discover the community of developers and maintainers driving ModSecurity forward.