ContractShield icon
ContractShield icon

ContractShield

Intelligent Web Application Firewall that protects APIs in real-time against OWASP Top 10 attacks, injection attempts, and SSRF.

ContractShield screenshot 1

Cost / License

Application type

Platforms

  • Self-Hosted
-
No reviews
0likes
0comments
0news articles

Features

Suggest and vote on features

Properties

  1.  Lightweight

Features

  1.  No Tracking
  2.  SQL Injection Protection
  3.  Web Application Firewall

 Tags

ContractShield News & Activities

Highlights All activities

Recent activities

ContractShield information

  • Developed by

    CH flagzeekmartin
  • Licensing

    Open Source (Apache-2.0) and Freemium product.
  • Pricing

    Subscription that costs up to $500 per month + free version with limited functionality.
  • Written in

  • Alternatives

    2 alternatives listed
  • Supported Languages

    • English
    • French

AlternativeTo Categories

Network & AdminSecurity & Privacy

GitHub repository

  •  0 Stars
  •  0 Forks
  •  0 Open Issues
  •   Updated  
View on GitHub
ContractShield was added to AlternativeTo by ContractShield on and this page was last updated .
No comments or reviews, maybe you want to be first?

What is ContractShield?

ContractShield is a Web Application Firewall (WAF) designed to protect web applications and APIs in real-time. It defends against OWASP Top 10 attacks including SQL injection, cross-site scripting (XSS), command injection, prototype pollution, SSRF (Server-Side Request Forgery), and path traversal attempts.

ContractShield provides endpoint-specific validation rules, configurable rate limiting, and request body inspection. It supports both monitor and block modes, allowing teams to observe threats before enforcing rules. Available as an npm package for Node.js/Express and a Python SDK for FastAPI/Django, it integrates directly into existing application code with minimal configuration through a simple YAML policy file.

Built in Switzerland, ContractShield is designed for SMBs and mid-market companies looking for enterprise-grade API protection without the complexity of traditional WAF solutions.

Official Links