← All frameworks
71
React
modern
javascript · frontend · since 2013
acceptable
↑
0.3 pts
vs last month
Updated June 2026
React scores 72/100. Verdict: Acceptable.
Dimension breakdown
Security
20 total CVEs on record. 2 critical severity.
Total Cves
20
Critical Cves
2
Exploited Cves
0
Avg Cvss
4.5
Cves Last Year
3
Performance
Average performance. Room for optimization.
Ecosystem
235,000 GitHub stars. 1,700 contributors. 12 releases in the last year.
Stars
235,000
Contributors
1,700
Releases Last Year
12
Avg Issue Close Days
15
Ai Readiness
Moderate AI-readiness. Can serve structured data but not optimized for it. Client-side rendering may impede AI consumption.
Structured Output
55
Api First
0.0
Headless Capable
0.0
Developer Experience
Strong developer experience. Good docs, modern tooling, active community.
Market Trajectory
Score
90
Market Share Pct
8.0
Cost Of Ownership
Moderate cost. Requires traditional server infrastructure.
Actively exploited vulnerabilities
Updated 2026-08-09
2 entries
2 confirmed vulnerabilities being actively exploited in real attacks right now. Source: CISA Known Exploited Vulnerabilities.
Latest entry: 2026-02-05
React scores 72/100 overall. Strongest dimension: market trajectory (90). Weakest: ai readiness (55).
Latest React insights

What GPTBot Sees Before Your React App Hydrates: Nothing
July 2, 2026 · 5 min
React Compiler Adds 17% Build Overhead: Rolldown Declines
June 29, 2026 · 4 min
React's Most Influential Voice Moves to Next.js
June 28, 2026 · 4 min
i18next Prototype Pollution: The Translation Layer Nobody Thought to Secure.
June 26, 2026 · 5 min
WordPress 7.0 Ships — Then Immediately Starts Migrating Its Own Admin to React 19
June 18, 2026 · 5 min
Retool Launches React AI App Builder: Modern Frameworks Get AI-Native Tooling
June 18, 2026 · 4 min
Next.js 16 Ships Turbopack by Default. React Compiler Cuts Re-Renders 40%. The Supply Chain Didn't Get Faster.
June 17, 2026 · 5 min
Next.js Authorization Bypass: A Crafted Query Parameter Changes Your Route Without Changing the URL. CVE-2026-44574.
June 15, 2026 · 6 min
The Virtual DOM Is Dying. Angular, Vue, and Svelte All Shipped Compiler-Driven Reactivity in 2026.
June 14, 2026 · 7 min