
Open Source
Fully open-source under Apache 2.0 License, safe to use
Lightweight
Lightweight with no reliance on third-party services
Private Deployment
Can be deployed on Windows and Linux 64-bit ,Linux Arm64 systems
Independent Engine
Protection functionality does not rely on IIS or Nginx plugins, avoiding installation complexity and compatibility issues
Containerization
Supports containerized deployment
Bot Detection
Detects crawlers from Baidu, Google, Bing, Sogou, 360 Search, Yisou, and ByteDance
SQL Injection Detection
Identifies common SQL injection attacks
XSS Detection
Detects XSS attacks
Scanner Tool Detection
Detects scanner tools
RCE Detection
Detects RCE attacks
Custom Protection Rules
Supports script and interface editing
IP Allow List Access
IPs in the allow list can bypass the firewall
IP Block List Access
IPs in the block list are directly blocked
URL Allow List
URLs in the allow list can be exempted from protection filtering
URL Access Restrictions
Restricts external access to certain URLs
Data Masking
Allows data masking for outputs of specific URLs
CC Protection
Blocks IPs with high request frequency
Flexibility
Protection can be flexibly set for the entire website or specific sites
Security
Automatically generated program, encrypted log storage, encrypted management access, and data masking
Sensitive Word Detection
Supports sensitive word detection with automatic blocking
SSL Folder
Supports automatic deployment of SSL files
Load Balancing
Supports weighted load balancing and IP load balancing modes
Custom IP Library
Allows updating the IP location database
OWASP Ruleset
Supports translation of the latest OWASP ruleset
IPv6
Support for IPv6
Automatic SSL Renewal
Supports automatic SSL certificate renewal
Supports Custom Interception Interface
Supports custom interception interface
Supports Two-Factor Authentication (2FA)
Supports Two-Factor Authentication (2FA)
Firewall IP Block
OS-level IP blocking, outperforming the application-layer blacklist
Cache Rule
Caches static resources to reduce backend load and speed up access
Website Access Authentication
Require a password to access a website; supports HTTP Basic and a custom login page
Tunnel
Intranet penetration tunnels for TCP/HTTP with optional SSL
Batch Task
Batch scheduled configuration tasks
Key Management
Centralized encrypted credential storage for SSL DNS auto-application
Scheduled Task
Built-in scheduled task management
One-Key Modify
One-click change of BT Panel web port (Linux only)
Protection Log
Risk log statistics with per-source-IP drill-down analysis
Access Analytics
Access data analysis and spider (crawler) identification
Notification
Multi-channel notifications and subscriptions
Open Platform
Open platform API with key management
SSL Expiry Check
Batch check of SSL certificate expiration
Threat Intelligence IP Feeds
Subscribe to multiple threat IP feeds, pulled daily and landed automatically into the WAF layer and the system firewall
Web Page Anti-Tampering
Learns a page baseline and compares response hashes, serving the correct copy back and alerting when a page is tampered with
CSRF Protection
Per-site Origin/Referer validation on state-changing requests, with no backend code changes
File Upload Inspection
Dangerous extensions, webshell signatures, declared-vs-real type mismatch and size limit, each toggled independently
IP Group
A reusable IP set shared across sites, referenced by block/allow lists and custom rules; edit once and every site follows
CDN Origin IP
A central library of each CDN vendor's origin-facing ranges, referenced automatically by the site's real-client-IP source
Path Route Rules
Nginx location style routing by URL path to a backend proxy, static files or a redirect
Cookie Security
Fills in missing Set-Cookie security attributes on the response, never overriding values the application already set
Application Management
Hosts local business processes with start/stop/restart, auto-restart on crash, log viewing and upgrade/rollback
Database Support
SQLite by default and works out of the box with nothing extra to deploy; switchable to MySQL or PostgreSQL
Cache Support
In-memory cache by default with no third-party dependency; switchable to Redis when needed

