# Open-source Node.js frameworks

19 open-source Node.js frameworks rated against public privacy criteria.

1. [Koa](https://privacyratings.com/node-frameworks/koa/) (our pick): D (50/100). Minimal web framework for Node.js from the team behind Express, built around async middleware functions.
2. [Express](https://privacyratings.com/node-frameworks/express/): A (100/100). Minimal web framework for Node.js that provides routing and middleware for building web applications and APIs.
3. [Fastify](https://privacyratings.com/node-frameworks/fastify/): A (100/100). Web framework for Node.js focused on low overhead, with a plugin system and JSON schema based validation and serialization.
4. [Elysia](https://privacyratings.com/node-frameworks/elysia/): B (80/100). TypeScript web framework designed for the Bun runtime, with end-to-end type safety and schema validation.
5. [Hono](https://privacyratings.com/node-frameworks/hono/): B (80/100). Small web framework built on Web Standards that runs on Node.js, Bun, Deno, Cloudflare Workers and other JavaScript runtimes.
6. [Nitro](https://privacyratings.com/node-frameworks/nitro/): B (80/100). Server toolkit for building web servers and APIs in JavaScript and TypeScript, built on h3 and deployable to many hosting platforms and runtimes.
7. [Oak](https://privacyratings.com/node-frameworks/oak/): B (80/100). Middleware framework for HTTP servers on Deno, Node.js, Bun and Cloudflare Workers, modeled on Koa, with a built-in router.
8. [Restify](https://privacyratings.com/node-frameworks/restify/): B (80/100). Node.js web service framework for building REST APIs, with a focus on observability and correctness.
9. [AdonisJS](https://privacyratings.com/node-frameworks/adonisjs/): D (50/100). TypeScript-first MVC web framework for Node.js that includes routing, an ORM, authentication and validation.
10. [Encore.ts](https://privacyratings.com/node-frameworks/encore-ts/): D (50/100). TypeScript backend framework with a Rust-based runtime, where APIs and infrastructure such as databases, queues and cron jobs are declared in code.
11. [Feathers](https://privacyratings.com/node-frameworks/feathers/): D (50/100). TypeScript and JavaScript framework for building real-time applications and REST APIs on Node.js.
12. [LoopBack](https://privacyratings.com/node-frameworks/loopback/): D (50/100). TypeScript framework for Node.js for building REST APIs and microservices, with OpenAPI support, dependency injection and database connectors.
13. [Meteor](https://privacyratings.com/node-frameworks/meteor/): D (50/100). Full-stack JavaScript platform for building web and mobile applications with real-time data on Node.js.
14. [Moleculer](https://privacyratings.com/node-frameworks/moleculer/): D (50/100). Microservices framework for Node.js with service discovery, load balancing, fault tolerance and pluggable message transporters.
15. [NestJS](https://privacyratings.com/node-frameworks/nestjs/): D (50/100). TypeScript framework for building server-side Node.js applications, using modules, dependency injection and decorators on top of Express or Fastify.
16. [Total.js](https://privacyratings.com/node-frameworks/total-js/): D (50/100). Node.js framework for building web applications, REST services and real-time apps, with no third-party dependencies in its core and built-in NoSQL storage.
17. [tRPC](https://privacyratings.com/node-frameworks/trpc/): D (50/100). TypeScript library for building end-to-end type-safe APIs, sharing types between server and client without schemas or code generation.
18. [Hapi](https://privacyratings.com/node-frameworks/hapi/): D (40/100). Web framework for Node.js for building applications and services, with built-in input validation, caching and authentication support.
19. [Sails](https://privacyratings.com/node-frameworks/sails/): D (40/100). MVC web framework for Node.js built on Express, with auto-generated REST APIs, WebSocket support and the Waterline ORM.

Source: https://privacyratings.com/open-source/node-frameworks/
