Free WAF Performance Test: Does It Actually Slow Down Your Site?

1 1 13
calendar_today agoschedule2 min read

What I Tested

Factor Setup
Server 2 vCPU, 2 GB RAM VPS
Stack Nginx -> SafeLine (Docker) -> Node.js app
Tool Apache Bench, wrk, curl timing
Baseline Direct to Node.js app (no WAF)
WAF mode SafeLine Community, balanced detection profile

Results

Metric Direct (No WAF) Through SafeLine Difference
Average response 12ms 13ms +1ms
Requests/sec 8,200 7,600 -7.3%
p99 latency 45ms 48ms +3ms
Resource usage 400 MB RAM 1.1 GB RAM +700 MB

The WAF adds about 1 millisecond of latency. Under load, throughput drops about 7%. For the vast majority of sites, this is invisible.

What Actually Adds Latency (Hint: It's Not the WAF)

If your site feels slow, the WAF isn't the problem. Check these first:

  • Database queries without indexes -> 50-500ms
  • Unoptimized images -> seconds of load time
  • No CDN for static assets -> 100-500ms per asset
  • PHP without opcache -> 50-200ms per request
  • Too many third-party scripts -> 2-5 seconds

When Throughput Matters

SafeLine Community Edition caps at about 800 QPS on a single core. That's 69 million requests per day. The $10 Lite plan removes the cap.

Resource Usage

Total VPS RAM SafeLine Left for Apps Works for
1 GB 700 MB ~300 MB Static sites, tiny APIs
2 GB 700 MB ~1.3 GB Most web apps
4 GB 700 MB ~3.3 GB WordPress, Rails, Django

Verdict: 2 GB is the sweet spot.

The Performance Trade-Off

Without WAF With SafeLine
8,200 req/s 7,600 req/s
12ms response 13ms response
0% attack blocking 71.65% attack blocking

Trading 7% throughput for 71% attack blocking — a reasonable trade.

FAQ

Does the semantic engine get slower with more rules?

No. The engine parses request structure once and classifies attacks in a single pass. Detection time is constant.

How does SafeLine's performance compare to ModSecurity?

ModSecurity can add 5-50ms of latency depending on rule complexity. SafeLine stays at about 1ms because of single-pass semantic parsing.

What about RAM usage under heavy load?

SafeLine's memory usage is stable. I tested 500 req/s for an hour: RAM stayed at about 700 MB the entire time. No memory leaks.

Can I run SafeLine on a Raspberry Pi?

Yes. A Pi 4 with 4 GB RAM handles SafeLine plus lightweight apps. ARM Docker images work. Throughput ceiling is lower (around 300-400 QPS on ARM), but viable for homelab.


How many requests per second does your site handle at peak, and what's your current security setup?

🔥 Join developers growing publicly
Share your knowledge, build in public, and grow your developer presence with a global community.

More Posts

Your AI Doesn't Just Write Tests. It Runs Them Too.

Kevin Martinez - May 12

What Is SARIF and How Does It Help Security Tools Work Together?

Ganesh Kumar - Jul 4

Why Your WordPress Site Is Slow (It Is Not Always Hosting)

ApogeeWatcherverified - Jul 13

Your Backup Data Knows More Than You Think. HYCU aiR Is Finally Asking It the Right Questions.

Tom Smithverified - May 14

EKS Auto Mode: What It Actually Changes (and What It Doesn’t)

Alexandre Vazquez - Jul 27
chevron_left
448 Points15 Badges
14Posts
0Comments
1Connections
Homelab operator. Security tools. Self-hosted everything. Open source.

Related Jobs

View all jobs →

Commenters (This Week)

3 comments
3 comments
1 comment

Contribute meaningful comments to climb the leaderboard and earn badges!