# Front-end and full-stack frameworks privacy ratings

JavaScript front-end, single-page and full-stack frameworks. Some collect telemetry from developers by default.

**Our pick:** [Svelte](https://privacyratings.com/web-frameworks/svelte/): Compiles components to small, fast JavaScript with no virtual DOM and no telemetry, and works well with TypeScript. The Forward Email webmail and apps use Svelte and TypeScript on Tauri (github.com/forwardemail/mail.forwardemail.net).

| Name | Grade | Jurisdiction | Description |
| --- | --- | --- | --- |
| [Svelte](https://privacyratings.com/web-frameworks/svelte/) (our pick) | B (80/100) | Unknown | Component framework for JavaScript and TypeScript that compiles components into JavaScript at build time instead of using a virtual DOM. |
| [Alpine.js](https://privacyratings.com/web-frameworks/alpine-js/) | B (80/100) | Unknown | Lightweight JavaScript framework that adds reactive behavior to HTML through attributes written directly in the markup. |
| [Backbone.js](https://privacyratings.com/web-frameworks/backbone-js/) | B (80/100) | Unknown | Lightweight JavaScript library that gives web applications structure with models, collections, views and a router. |
| [Blitz.js](https://privacyratings.com/web-frameworks/blitz-js/) | B (80/100) | Unknown | Full-stack toolkit for Next.js that adds authentication, a zero-API data layer and code generation. |
| [htmx](https://privacyratings.com/web-frameworks/htmx/) | B (80/100) | Unknown | JavaScript library that lets HTML elements issue HTTP requests and swap in server-rendered HTML through attributes, without writing JavaScript. |
| [Inferno](https://privacyratings.com/web-frameworks/inferno/) | B (80/100) | Unknown | JavaScript library for building user interfaces with a virtual DOM and a React-style component API. |
| [jQuery](https://privacyratings.com/web-frameworks/jquery/) | B (80/100) | United States (Five Eyes) | JavaScript library for DOM manipulation, event handling and Ajax, maintained under the OpenJS Foundation. |
| [Marko](https://privacyratings.com/web-frameworks/marko/) | B (80/100) | Unknown | HTML-based UI language and framework for JavaScript, originally from eBay, that compiles components for streaming server rendering and partial hydration in the browser. |
| [Mithril.js](https://privacyratings.com/web-frameworks/mithril-js/) | B (80/100) | Unknown | Small client-side JavaScript framework for building single-page applications, with a virtual DOM and built-in routing and HTTP utilities. |
| [Nuxt](https://privacyratings.com/web-frameworks/nuxt/) | B (80/100) | Unknown | Vue-based framework for building web applications with server-side rendering, static generation and file-based routing. |
| [React Router](https://privacyratings.com/web-frameworks/react-router/) | B (80/100) | Unknown | Routing library and full-stack framework for React, whose framework mode continues the Remix framework. |
| [RedwoodSDK](https://privacyratings.com/web-frameworks/redwoodsdk/) | B (80/100) | Unknown | Full-stack React framework from the RedwoodJS team that runs on Cloudflare Workers, built as a Vite plugin with server components, server-side rendering and realtime features. |
| [Remix](https://privacyratings.com/web-frameworks/remix/) | B (80/100) | Canada (Five Eyes) | Full-stack web framework for JavaScript and TypeScript from Shopify, built on web standards such as the Fetch API and HTML forms. Its earlier React-based version continues as the framework mode of React Router. |
| [SolidJS](https://privacyratings.com/web-frameworks/solidjs/) | B (80/100) | Unknown | JavaScript library for building user interfaces with JSX and fine-grained reactivity, updating the DOM directly without a virtual DOM. |
| [SolidStart](https://privacyratings.com/web-frameworks/solidstart/) | B (80/100) | Unknown | Full-stack framework for SolidJS, a reactive UI library, with routing, server functions and server-side rendering. |
| [SvelteKit](https://privacyratings.com/web-frameworks/sveltekit/) | B (80/100) | Unknown | Framework for building web applications with Svelte, a compiler-based UI framework, with routing, server-side rendering and static site generation. |
| [Astro](https://privacyratings.com/web-frameworks/astro/) | C (65/100) | United States (Five Eyes) | Web framework for content-driven websites that renders pages to HTML and loads JavaScript only for interactive components. |
| [Analog](https://privacyratings.com/web-frameworks/analog/) | D (50/100) | Unknown | Full-stack meta-framework for Angular built on Vite, with file-based routing, server-side rendering, static generation and API routes. |
| [Angular](https://privacyratings.com/web-frameworks/angular/) | D (50/100) | United States (Five Eyes) | TypeScript-based web application framework from Google, with components, dependency injection, routing and a CLI. |
| [Aurelia](https://privacyratings.com/web-frameworks/aurelia/) | D (50/100) | Unknown | JavaScript and TypeScript front-end framework for building web applications with standards-based components, data binding and dependency injection. |
| [Ember.js](https://privacyratings.com/web-frameworks/ember-js/) | D (50/100) | Unknown | JavaScript framework for building web applications, with conventions, a CLI, routing and a data layer. |
| [Fresh](https://privacyratings.com/web-frameworks/fresh/) | D (50/100) | United States (Five Eyes) | Web framework for Deno from Deno Land that renders pages on the server with Preact and ships JavaScript only for interactive islands. |
| [Gatsby](https://privacyratings.com/web-frameworks/gatsby/) | D (50/100) | United States (Five Eyes) | React-based framework for building static websites and apps, with a GraphQL data layer and plugins for content sources. |
| [Lit](https://privacyratings.com/web-frameworks/lit/) | D (50/100) | United States (Five Eyes) | Library for building Web Components with reactive properties and declarative templates. |
| [Next.js](https://privacyratings.com/web-frameworks/next-js/) | D (50/100) | United States (Five Eyes) | React framework from Vercel for building web applications with server-side rendering, static generation and API routes. |
| [Preact](https://privacyratings.com/web-frameworks/preact/) | D (50/100) | Unknown | Small JavaScript library with a React-compatible component API for building user interfaces. |
| [Qwik](https://privacyratings.com/web-frameworks/qwik/) | D (50/100) | Unknown | Web framework that serializes application state into HTML so pages resume in the browser without hydration. |
| [React](https://privacyratings.com/web-frameworks/react/) | D (50/100) | United States (Five Eyes) | JavaScript library for building user interfaces from components, used for web and native applications. |
| [Stencil](https://privacyratings.com/web-frameworks/stencil/) | D (50/100) | United States (Five Eyes) | Compiler from Ionic for building reusable web components with TypeScript and JSX that work with any front-end framework or none. |
| [TanStack Start](https://privacyratings.com/web-frameworks/tanstack-start/) | D (50/100) | Unknown | Full-stack React and Solid framework built on TanStack Router and Vite, with type-safe routing, server functions and server-side rendering. |
| [Vike](https://privacyratings.com/web-frameworks/vike/) | D (50/100) | Unknown | Vite-based framework for building web applications with server-side rendering, static generation and routing, used with UI libraries such as React, Vue or Solid. |
| [Waku](https://privacyratings.com/web-frameworks/waku/) | D (50/100) | Unknown | Minimal React framework for building web applications with React Server Components, server-side rendering and static generation. |
| [Vue](https://privacyratings.com/web-frameworks/vue/) | D (40/100) | Unknown | Progressive JavaScript framework for building user interfaces with reactive, component-based templates. |
| [Hydrogen](https://privacyratings.com/web-frameworks/hydrogen/) | F (35/100) | Canada (Five Eyes) | React framework from Shopify for building custom storefronts on the Shopify commerce platform, based on React Router. |

## Criteria

- **Open source** (weight 3): Is all the source code needed to run the product public?
- **No trackers or telemetry** (weight 3): Are the website and apps free of third-party trackers, with any analytics anonymous and any telemetry off by default?
- **No ads or data sales** (weight 2): Is the product funded without advertising, ad targeting or selling user data?
- **Independent audit** (weight 2): Has an independent security or privacy audit been published within the last three years?

Source: https://privacyratings.com/web-frameworks/
