# Node.js frameworks privacy ratings

Web and API frameworks for Node.js. Telemetry and dependencies matter for every app built on them.

**Our pick:** [Koa](https://privacyratings.com/node-frameworks/koa/): A small core built on async middleware, from the team behind Express. MIT licensed, with no telemetry.

| Name | Grade | Jurisdiction | Description |
| --- | --- | --- | --- |
| [Koa](https://privacyratings.com/node-frameworks/koa/) (our pick) | D (50/100) | Unknown | Minimal web framework for Node.js from the team behind Express, built around async middleware functions. |
| [Express](https://privacyratings.com/node-frameworks/express/) | A (100/100) | United States (Five Eyes) | Minimal web framework for Node.js that provides routing and middleware for building web applications and APIs. |
| [Fastify](https://privacyratings.com/node-frameworks/fastify/) | A (100/100) | United States (Five Eyes) | Web framework for Node.js focused on low overhead, with a plugin system and JSON schema based validation and serialization. |
| [Elysia](https://privacyratings.com/node-frameworks/elysia/) | B (80/100) | Unknown | TypeScript web framework designed for the Bun runtime, with end-to-end type safety and schema validation. |
| [Hono](https://privacyratings.com/node-frameworks/hono/) | B (80/100) | Unknown | Small web framework built on Web Standards that runs on Node.js, Bun, Deno, Cloudflare Workers and other JavaScript runtimes. |
| [Nitro](https://privacyratings.com/node-frameworks/nitro/) | B (80/100) | Unknown | Server toolkit for building web servers and APIs in JavaScript and TypeScript, built on h3 and deployable to many hosting platforms and runtimes. |
| [Oak](https://privacyratings.com/node-frameworks/oak/) | B (80/100) | Unknown | Middleware framework for HTTP servers on Deno, Node.js, Bun and Cloudflare Workers, modeled on Koa, with a built-in router. |
| [Restify](https://privacyratings.com/node-frameworks/restify/) | B (80/100) | Unknown | Node.js web service framework for building REST APIs, with a focus on observability and correctness. |
| [AdonisJS](https://privacyratings.com/node-frameworks/adonisjs/) | D (50/100) | Unknown | TypeScript-first MVC web framework for Node.js that includes routing, an ORM, authentication and validation. |
| [Encore.ts](https://privacyratings.com/node-frameworks/encore-ts/) | D (50/100) | Sweden (Fourteen Eyes) | TypeScript backend framework with a Rust-based runtime, where APIs and infrastructure such as databases, queues and cron jobs are declared in code. |
| [Feathers](https://privacyratings.com/node-frameworks/feathers/) | D (50/100) | Unknown | TypeScript and JavaScript framework for building real-time applications and REST APIs on Node.js. |
| [LoopBack](https://privacyratings.com/node-frameworks/loopback/) | D (50/100) | United States (Five Eyes) | TypeScript framework for Node.js for building REST APIs and microservices, with OpenAPI support, dependency injection and database connectors. |
| [Meteor](https://privacyratings.com/node-frameworks/meteor/) | D (50/100) | Unknown | Full-stack JavaScript platform for building web and mobile applications with real-time data on Node.js. |
| [Moleculer](https://privacyratings.com/node-frameworks/moleculer/) | D (50/100) | Unknown | Microservices framework for Node.js with service discovery, load balancing, fault tolerance and pluggable message transporters. |
| [NestJS](https://privacyratings.com/node-frameworks/nestjs/) | D (50/100) | Unknown | TypeScript framework for building server-side Node.js applications, using modules, dependency injection and decorators on top of Express or Fastify. |
| [Total.js](https://privacyratings.com/node-frameworks/total-js/) | D (50/100) | Slovakia | Node.js framework for building web applications, REST services and real-time apps, with no third-party dependencies in its core and built-in NoSQL storage. |
| [tRPC](https://privacyratings.com/node-frameworks/trpc/) | D (50/100) | Unknown | TypeScript library for building end-to-end type-safe APIs, sharing types between server and client without schemas or code generation. |
| [Hapi](https://privacyratings.com/node-frameworks/hapi/) | D (40/100) | Unknown | Web framework for Node.js for building applications and services, with built-in input validation, caching and authentication support. |
| [Sails](https://privacyratings.com/node-frameworks/sails/) | D (40/100) | Unknown | MVC web framework for Node.js built on Express, with auto-generated REST APIs, WebSocket support and the Waterline ORM. |

## Criteria

- **Open source** (weight 3): Is all the source code needed to run the product public?
- **No trackers or telemetry** (weight 3): Are the website and apps free of third-party trackers, with any analytics anonymous and any telemetry off by default?
- **No ads or data sales** (weight 2): Is the product funded without advertising, ad targeting or selling user data?
- **Independent audit** (weight 2): Has an independent security or privacy audit been published within the last three years?

Source: https://privacyratings.com/node-frameworks/
