# Install modsecurity with Homebrew, zypper, apt

Libmodsecurity is one component of the ModSecurity v3 project. Version 3.0.16 via Homebrew; verified 2026-06-29. Also installable with debian: sudo apt install libmodsecurity-dev.

## Install

```sh
sudo av install brew:modsecurity
```

Additional install commands:

### macOS

- Homebrew (100%):

```sh
brew install modsecurity
```

  Evidence: local Homebrew formula metadata

### Linux

- zypper (92%):

```sh
sudo zypper install modsecurity
```

  Evidence: openSUSE Tumbleweed package metadata: modsecurity from https://download.opensuse.org/tumbleweed/repo/oss/repodata/50b07339cb64c8ed4091bdbabddadc1ff5737b090e478818a195b40d8a3292861a879139b4a3987c31109699fde9fbf4a716367ddf4eef77da75f96e3193d6ed-primary.xml.zst

- Debian apt (92%):

```sh
sudo apt install libmodsecurity-dev
```

  Evidence: Debian stable package indexes: libmodsecurity-dev from https://deb.debian.org/debian/dists/stable/main/binary-amd64/Packages.xz

## Package facts

- **Package key:** brew:modsecurity
- **Package manager:** Homebrew
- **Version:** 3.0.16
- **Source summary:** Libmodsecurity is one component of the ModSecurity v3 project
- **Homepage:** <https://github.com/owasp-modsecurity/ModSecurity>
- **Repository:** <https://github.com/owasp-modsecurity/ModSecurity>
- **Last updated:** 2026-06-29T22:26:54Z
- **Generated:** 2026-08-03T19:37:03+00:00

## Executables

- modsec-rules-check (alias)

## Install behavior

- Bottle: not available

## Freshness

- Page generated: 2026-08-03
- Package-manager version: 3.0.16
## Project history and usage

ModSecurity is an open-source web application firewall engine that began in 2002 and became one of the most widely known defensive layers for inspecting HTTP traffic with configurable rules. Ivan Ristic created the original Apache-focused project; later stewardship passed through commercial and community hands, including Thinking Stone, Breach Security, Trustwave SpiderLabs, and OWASP. OWASP's project page records the 2024 transfer from Trustwave to OWASP and frames the project as the WAF engine commonly paired with the OWASP Core Rule Set.

### Project history

Technically, ModSecurity evolved from an Apache module into a cross-platform WAF engine. The v3/libmodsecurity architecture separated the core library from web-server connectors, removing Apache dependencies and allowing connectors for environments such as Nginx and Apache to feed traffic into the same SecRules processing engine. The upstream README describes libmodsecurity as the component that loads and interprets SecRules and applies traditional ModSecurity processing to HTTP content supplied by connectors.

### How it is used

Its adoption history is tied to both open-source infrastructure and commercial WAF support. Breach Security described the project in 2006 as having more than 10,000 deployments, and Trustwave later provided commercial rules and support before announcing end-of-sale in 2021 and end-of-life for Trustwave support on July 1, 2024. Distribution through Homebrew and Linux development packages such as `libmodsecurity-dev` reflects its dual identity as both an installable command-line/dev library package and a component embedded by web-server modules, reverse proxies, hosting panels, and security stacks.

### Sources

- <https://formulae.brew.sh/formula/modsecurity>
- <https://github.com/owasp-modsecurity/ModSecurity>
- <https://owasp.org/www-project-modsecurity/>
- <https://www.helpnetsecurity.com/2006/09/25/breach-acquires-modsecurity-open-source-vendor-thinking-stone/>
- <https://www.levelblue.com/blogs/spiderlabs-blog/modsecurity-version-3.0-announcement>
- <https://www.levelblue.com/security-resources/software-updates/end-of-sale-and-trustwave-support-for-modsecurity-web-application-firewall/>


## Security Notes

No matching local secret-handling manifest was found for modsecurity. Nucleus package metadata is still published here so future coverage has a stable package URL.


## Other Package-Manager Records

- Debian apt - libmodsecurity-dev - 3.0.14-1+deb13u1: normalized package name match | Debian stable package indexes: libmodsecurity-dev from https://deb.debian.org/debian/dists/stable/main/binary-amd64/Packages.xz | ModSecurity v3 library component (development files) | https://www.modsecurity.org/
- Debian apt - libmodsecurity3t64 - 3.0.14-1+deb13u1: normalized package name match | Debian stable package indexes: libmodsecurity3t64 from https://deb.debian.org/debian/dists/stable/main/binary-amd64/Packages.xz | ModSecurity v3 library component | https://www.modsecurity.org/
- Ubuntu apt - libmodsecurity-dev - 3.0.12-1.1build2: normalized package name match | Ubuntu 24.04 LTS package indexes: libmodsecurity-dev from https://archive.ubuntu.com/ubuntu/dists/noble/universe/binary-amd64/Packages.gz | ModSecurity v3 library component (development files) | https://www.modsecurity.org/
- Ubuntu apt - libmodsecurity3t64 - 3.0.12-1.1build2: normalized package name match | Ubuntu 24.04 LTS package indexes: libmodsecurity3t64 from https://archive.ubuntu.com/ubuntu/dists/noble/universe/binary-amd64/Packages.gz | ModSecurity v3 library component | https://www.modsecurity.org/
- zypper - libmodsecurity3 - 3.0.15-2.3: normalized package name match | openSUSE Tumbleweed package metadata: libmodsecurity3 from https://download.opensuse.org/tumbleweed/repo/oss/repodata/50b07339cb64c8ed4091bdbabddadc1ff5737b090e478818a195b40d8a3292861a879139b4a3987c31109699fde9fbf4a716367ddf4eef77da75f96e3193d6ed-primary.xml.zst | Web application firewall engine | https://www.modsecurity.org/
- zypper - modsecurity - 3.0.15-2.3: normalized package name match | openSUSE Tumbleweed package metadata: modsecurity from https://download.opensuse.org/tumbleweed/repo/oss/repodata/50b07339cb64c8ed4091bdbabddadc1ff5737b090e478818a195b40d8a3292861a879139b4a3987c31109699fde9fbf4a716367ddf4eef77da75f96e3193d6ed-primary.xml.zst | Web application firewall engine | https://www.modsecurity.org/
- zypper - modsecurity-devel - 3.0.15-2.3: normalized package name match | openSUSE Tumbleweed package metadata: modsecurity-devel from https://download.opensuse.org/tumbleweed/repo/oss/repodata/50b07339cb64c8ed4091bdbabddadc1ff5737b090e478818a195b40d8a3292861a879139b4a3987c31109699fde9fbf4a716367ddf4eef77da75f96e3193d6ed-primary.xml.zst | Development files for modsecurity, a web application firewall engine | https://www.modsecurity.org/


## Combined YAML source

View the package source record on GitHub. [combined/modsecurity.yml](https://github.com/mxcl/pkgdb/blob/main/combined/modsecurity.yml)


## Sources

- pkg.so package database
- Geiger risk classifier
- curated package history
- pkgdb category and tag curation
- external package-manager database matches
- cross-ecosystem install command graph
