macOS
brew install gotestwaflocal Homebrew formula metadata
brew / rank 9421
Tool for API and OWASP attack simulation. Version 0.5.8 via Homebrew; verified 2026-07-27. Also installable with nix: nix profile install nixpkgs#gotestwaf.
install
brew install gotestwaflocal Homebrew formula metadata
nix profile install nixpkgs#gotestwafnixpkgs package indexes · pkgs/by-name/go/gotestwaf/package.nix · source: api.github.com
overview
Tool for API and OWASP attack simulation
history
GoTestWAF is Wallarm's Go-based command-line tool for simulating API and OWASP-style attacks against web application firewalls, API gateways, IPS products, and related application-security controls.
The repository was created in January 2020. The README describes a scanner that generates malicious requests by combining payloads, encoders, and request placeholders, then records how the evaluated security solution handled those requests.
The project is packaged as a Docker image and a Homebrew formula, which matches its evaluation-tool use case: users can run it near the target application or security appliance without embedding it into application code.
Users point GoTestWAF at an evaluated URL and run built-in test sets such as OWASP Top 10 and OWASP API, or supply custom YAML test cases. Reports can be generated locally, and releases in 2024 and 2025 emphasize report-format and validation work.
For package catalogs, GoTestWAF is a niche but useful security-testing CLI: it packages repeatable malicious-request generation as a portable Go binary and container, rather than as a SaaS-only scanner.
security posture
narrow executable package without higher-risk signals.
green risk · low confidence · appliance
Before unattended agent use, check whether the tool reads plaintext credentials, writes remote state, publishes artifacts, or shells out to plugins.
local files
These source-backed paths show where this package keeps local settings or durable credentials. Automic Vault can use them as review targets for secret scanning, migration, and command approval.
Config paths the tool may read or write during local use.
config.yamlexecutables
| Command | Kind | Exposure | Note |
|---|---|---|---|
gotestwaf | executable | indexed executable | Discovered from the local executable index. |
freshness
These signals separate page generation age, package-manager activity, and upstream release comparison. Version lag is warned only when an evidence URL and comparable versions are present.
install metadata
| Package key | brew:gotestwaf |
|---|---|
| Version | 0.5.8 |
| Package manager | Homebrew |
| Homepage | https://lab.wallarm.com/test-your-waf-before-hackers/ |
| Repository | https://github.com/wallarm/gotestwaf |
| Last updated | 2026-07-27T16:47:25+02:00 |
| Pulse | updated |
| Bottle | not recorded |
| Service | none declared |
source database matches
Matches are pulled from external package-manager indexes and kept separate from local Automic Vault package links.
gotestwaf
nix profile install nixpkgs#gotestwafsource trail
This page is generated by av-web from the private package SQLite artifact built by scripts/generate-pkg-sqlite.py.
View the package source record on GitHub.