{"repo":"fabriziosalmi/secure-proxy-manager","free":true,"listed":false,"github":"https://github.com/fabriziosalmi/secure-proxy-manager","clone":"git clone https://github.com/fabriziosalmi/secure-proxy-manager.git","description":"Secure proxy solution with filtering, real-time monitoring and a modern web UI.","language":"Go","stars":41,"topics":["proxy","proxy-configuration","proxy-tool","squid","squid-proxy","squid-proxy-security","ui","content-filtering","dns-filtering","egress-filtering"],"license":"MIT","category":"networking-infra","readme_excerpt":"Secure Proxy Manager 📖 Documentation: A self-hosted Secure Web Gateway (SWG) — one controllable egress point for a home, lab, or small-office network. It combines a Squid forward proxy, a custom WAF (request/response inspection over ICAP), a DNS sinkhole , and a modern web UI + API into a single Docker Compose stack: the self-hosted counterpart to cloud SWGs like Zscaler / Cloudflare Gateway — with no traffic leaving your network . Block domains and IPs, enforce a default-deny egress allowlist, inspect requests against WAF rules, sinkhole malware/ad domains at the DNS layer, and see what every client is reaching. Malicious requests get 403 'd at the proxy by the WAF; benign traffic passes. Every category is verified with an adversarial test suite — see Tested like an attacker. How it compares Most self-hosted network tools cover one layer. SPM combines forward-proxy egress control, request inspection, and DNS sinkholing in a single stack: Capability Pi-hole / AdGuard Nginx Proxy Manager Cloud SWG (Zscaler…) Secure Proxy Manager --- :---: :---: :---: :---: DNS sinkhole (block at resolve time) ✅ — ✅ ✅ Forward proxy (outbound egress control) — — ✅ ✅ HTTP request/body inspection (WAF) — — ✅ ✅ Default-deny egress allowlist — — ✅ ✅ Reverse proxy / ingress — ✅ — — Self-hosted — traffic stays on your network ✅ ✅ — ✅ Free / no per-seat cost ✅ ✅ — ✅ Pi-hole/AdGuard block only at the DNS layer; Nginx Proxy Manager is reverse-proxy ingress ; cloud SWGs do all of this but as a paid SaaS ","default_branch":null,"files":null,"tree":[],"storefront":"/r/fabriziosalmi","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/fabriziosalmi/secure-proxy-manager/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}