🛡️ AntiGüvenlik
TR
Login Register for Free
AntiGüvenlik Logo

Shield Your Website Against Attacks with a Single Line of Code

AntiGüvenlik is an AI-powered, ultra-fast WAF (Web Application Firewall) system that protects your website from SQL Injection, XSS, File Upload Bypasses, DDoS, and Bot attacks.

🛡️ Start Protection Member Login
0.2ms
Operational Latency (Ultra Fast)
100%
PHP 8.5+ Full Compatibility
24+
Advanced Security Modules

Which Attacks Are You Protected Against?

Our system is equipped with more than 60 independent security modules against the most advanced threats targeting your website.

🔄 Recursive Parameter Resolver

Cleans double URL encoding, HTML entities, and base64 obfuscations from threat payloads before scanning.

💉 Basic Injection Scanner

Instantly blocks threats with a robust regex ruleset targeting SQLi, XSS, Path Traversal, and RCE vulnerabilities.

API Request Security & JSON Response

Secures API traffic and blocks malicious attempts, returning JSON format with a 403 Forbidden status code instead of HTML templates.

🚫 Form and Comment Spam Blocker

Analyzes and prevents ad spam, link farms, and automated comments in input fields.

API Schema Validator

Automatically validates if incoming API requests (POST/PUT data) comply with your predefined JSON schemas.

📊 Database Query Rate Limiter

Limits the number of SQL queries and total fetched rows per page request to halt automation tools like sqlmap.

⚙️ Entropy-Based Signatureless Detection

Measures character complexity by calculating Shannon Entropy of request parameters to block zero-day attacks.

🔞 Pornography & Adult Content Filter

Blocks adult/pornographic keywords and bypass attempts using distance, entropy, and deep URL analysis.

🔓 WAF Bypass & Exception Rules

Defines custom exceptions allowing specific IPs, API keys, or trusted subdomains to bypass WAF checks.

💾 Memory Caching

Integrates Redis/APCu caching layers to ensure WAF rule checks complete in under 0.1ms.

⏱️ Token-Bucket Rate Limiter

Limits request frequencies to crush application-layer DDoS/Flood waves.

🧠 Proof-of-Work JS Challenge

Runs background CPU mathematical PoW challenges (100k-200k iterations) on suspicious clients to block advanced bots/DDoS.

🤖 User-Agent / Bot Detector

Identifies and blocks vulnerability scanners (Nmap, Sqlmap, Nikto, etc.) and scraper bots.

🕵️ Proxy / VPN / Tor Blocker

Blocks requests originating from VPNs, Tor networks, and anonymous proxies trying to conceal their tracks.

🌍 GeoIP Country Blocking

Filters and blocks traffic by country codes to eliminate high-volume foreign attacks.

🚫 ASN/ISP Cloud Blocking

Blocks automated attacks directly by cloud provider ASN numbers (AWS, DigitalOcean, Hetzner, etc.).

🚦 Smart Shield & Argo Smart Routing

Optimizes WAF performance and configurations using Argo Smart Routing capabilities.

🧠 Behavioral Bot & Polymorphic Forms

Measures typing/mouse rhythms and dynamically mutates form honeypot traps to eliminate bot submissions.

⌨️ Keystroke Dynamics Biometric Analysis

Evaluates keypress milliseconds rhythm and mouse trajectories on forms to filter human mimics.

🚦 Trusted Proxy & IP Spoofing Guard

Prevents fake IP header injections (X-Forwarded-For etc.) when your site is behind Cloudflare or a proxy.

🔒 SSL/HTTPS Enforcer

Enforces encrypted traffic by automatically redirecting HTTP requests to HTTPS.

📝 Secure HTTP Headers

Injects HSTS, CSP, and X-Frame-Options response headers against Clickjacking, XSS, and MIME sniffing.

🌐 Origin Access Control (CORS)

Validates and blocks cross-origin requests to API and critical endpoints.

🔑 End-to-End Encrypted API Sync

Encrypts all rule synchronizations and log transfers between client WAF and main platform.

🔌 WebSocket Tunnel Inspector

Monitors real-time WebSocket traffic to prevent RCE/SQLi payloads via WebSocket channels.

🌐 Outbound Request & SSRF Blocker

Inspects server-side outbound connections to block unauthorized local or cloud service IP access.

📡 DNS Security & Hijacking Detector

Queries Google/Cloudflare/Quad9 DNS records to detect and alert against DNS hijacking.

🧱 Tarpit Redirect Guard

Delays response times for attackers while redirecting them to exhaust their bot resources.

🛡️ Cryptojacking Shield

Prevents attackers from running unauthorized cryptocurrency mining scripts in client browsers.

📡 Dynamic Rule Sync

Allows WAF client to dynamically sync rules from the parent platform without code updates.

🎭 Session Hijack & IP Subnet Guard

Binds user sessions to browser fingerprints and IP subnets to stop session theft.

🧱 Brute Force Throttling

Limits and rate-limits login panels to block repeated false credential submissions.

🎫 CSRF Form Shield

Injects unique tokens into HTML forms to prevent Cross-Site Request Forgery.

📲 Two-Factor Authentication (2FA)

Provides extra account security via OTP (One-Time Password) app integrations.

👁️‍🗨️ Sensitive Data Masking

Masks passwords, credit cards, or ID numbers accidentally exposed in HTML outputs.

🚨 Threshold Auto-Ban Motor

Automatically blacklists and blocks malicious IPs exceeding the rate limits.

🔑 Credential Stuffing Protection

Validates logins against hardware, browser, and location profile changes.

🔑 Leaked Password Checker (Pwned API)

Warns or blocks users when they set passwords found in public data breaches via Pwned API.

📝 Invisible Cryptographic Watermark

Embeds zero-width characters in output to identify data scrapers.

🔓 Self-Unban Portal

Enables blocked users to unban themselves by completing a mathematical Proof-of-Work check.

🔍 File Integrity Monitor (FIM)

Tracks critical system files and alerts administrators on unauthorized changes.

🩹 Self-Healing Engine

Automatically restores hacked or modified critical system files from clean backups in seconds.

☣️ MIME-Type & Magic Byte Jail

Validates finfo MIME types and Magic Bytes (MZ, ELF, PHP) of uploads to quarantine malware.

🧹 Malware Scanner (Antivirus)

Scans old codebase files to find web shells and malicious PHP code.

☣️ Ransomware Canary Files

Places fake backup bait files in server directories to instantly freeze PHP execution upon manipulation.

🩹 Polymorphic Self-Protection

Dailly mutates and encrypts WAF client file to prevent malware from disabling it.

Time Machine Attack Replay

Freezes and replays server inputs and logs immediately leading to file integrity breach.

🎭 Hardware Fingerprint Analysis

Creates WebGL/AudioContext profiles of users to bind session tokens.

🧩 Browser Extension Firewall

Scans visitor extensions to find credential stealing browser add-ons.

🚨 Self-Destruct Button

One-click emergency lock to encrypt critical directories and put site on maintenance mode under heavy attack.

👑 Super Admin Control Center

Distributes custom rules and blacklists to all client websites from one central portal.

📊 Visual Analytics

Visualizes visitor segments and blocked attacks using rich HSL graphs.

🗑️ Auto Log Rotation

Prunes old telemetry data automatically to speed up database queries.

👁 Live Traffic Stream

Categorizes and streams human traffic, search engine crawls, and threats in real-time.

🔄 Static Cache Management

Creates and purges file caching folders under client directories.

Rocket Loader (Async JS)

Asynchronously loads JS files to maximize frontend performance.

👁 Read-Only Admin Role

Role restriction to analyze logs and traffic without altering rules.

📲 Telegram Instant Alerts

Delivers attack details, payloads, and IPs instantly to the admin's Telegram.

🖥️ Server Resource Monitor

Tracks CPU/RAM/GPU usage and sends alerts when thresholds are breached.

🍯 Invisible Honeypot traps

Catches spam bots using hidden forms invisible to humans.

🍯 Honeytrap Links

Injects bait links into code to instantly block scanning crawlers.

🎫 Polymorphic Honeypots

Mutates CSS names and honeytrap fields on every single page load.

🧱 Tarpit Delays

Artificially slows response rates for malicious scanner clients to drain their bandwidth.

🍯 Active Deception Block Page

Traps scanners by serving infinite data feeds and fake MySQL error streams.

🍯 Poison Response & Custom Block page

Provides custom blocked templates and decoys to slow down attackers.

🤖 AI-Powered Attack Scoring

Runs an lightweight probabilistic machine learning script locally to score request anomalies.

🛡️ DOM-WAF & Cryptojacking shield

Prevents DOM injection exploits and halts browser-based cryptocurrency miners.

👨‍💻 Digital Forensics Analyst

Tracks WebGL/GPU, audio fingerprint, local IP, and behavioral stats of hackers in real-time.

How It Works

Take full control of your website's security in just 3 steps.

01. Sign Up

Create a free security account in seconds and access your dashboard.

02. Download Code

Download the antiguvenlik.php file integrated specifically for you from the dashboard.

03. Add to Your Site

Upload the file to your site's root and include it at the top of your config file. Your protection starts instantly!

✉️

Contact & Support Notice

To contact us, you must register and log in to the system, and write a message from the Support Tickets section in the left menu.