What we still need to verify : 3 points in this profile are not yet confirmed against vendor documentation.
- Project maintenance activity has slowed; confirm current release and support status before adopting
- Much of the documentation is written in Chinese; confirm English coverage is sufficient for your team
- Supported runtime and framework versions: verify against project documentation
Treat these points as unconfirmed. They are open items in the catalog's verification queue, and this note stays until each is checked against the vendor's documentation.
What it does
OpenRASP hooks the functions where damage actually happens. The Java agent attaches through the standard JVM agent mechanism and instruments bytecode at points like SQL execution, file read and write, process execution, outbound HTTP requests, XML parsing and deserialization. The PHP build ships as a native extension hooking the equivalent internal functions. When execution reaches one of those points, the agent passes the call context to a detection plugin.
Those plugins are JavaScript, evaluated by an embedded engine, and that design is the interesting part. A plugin receives the operation in progress plus the request that triggered it, so it can ask questions traffic inspection cannot: does this SQL statement contain a fragment taken verbatim from a request parameter, does this file path resolve outside the web root, is this process being spawned from a web request at all. Detection compares the operation against its originating input rather than a pattern library, so payload obfuscation does not help, and you can write plugins in a language most teams already read.
Where it fits
This sits in production or staging, installed by whoever deploys the application, with alerts sent to a self-hosted console that aggregates events across agents. It suits organizations wanting in-application detection without a commercial contract, who have capacity to run the console, keep the agent current and validate it against their own frameworks. Treat the default posture as detection and logging first, enabling blocking per hook type once you have watched real traffic.
Strengths
- Detection at the sink with request context attached, which catches attacks that never look malicious in the raw HTTP.
- Plugins are readable JavaScript, so writing application-specific detection does not require learning a proprietary rule dialect.
- Covers PHP properly, which most commercial runtime protection products have abandoned.
- No licensing barrier to running it broadly across an estate for evaluation.
Limitations
- Java and PHP only, and no path to other runtimes.
- Project activity has slowed considerably, so plan for maintaining it yourself against new framework versions.
- Much documentation and issue discussion is in Chinese, which raises the effort for teams that cannot read it.
- Hooking at execution points adds per-call overhead, which needs measuring on hot paths before production.
Who it suits
A reasonable option for teams running Java or PHP applications who want runtime detection, have capacity to own an open source agent, and will not buy a commercial RASP. Not appropriate where you need vendor support, guaranteed maintenance, or coverage beyond these two runtimes, and a bad idea if nobody can evaluate the agent in your own stack first.
Used OpenRASP? Recommend it under your own name and title.
Recommend this tool