The Midpoint
WebPulse classifies every detected framework into one of three generations: legacy (WordPress, Drupal, Joomla, Magento), modern (Next.js, Nuxt, Astro, Angular, React, Vue, Hugo, Rails, Django, Laravel, and others built after 2010 with contemporary architectures), and emerging (SolidJS, Qwik, Hono, and other frameworks still in early adoption). On the broader web (Tranco top 100K, scanned May 2026), legacy frameworks hold 58.3% of detections. Modern holds 41.7%.
On the top 10K (scanned July 2026), the generation split inverts. Modern frameworks hold 48.7%. Legacy has fallen to 43.9%. The remaining 7.4% belongs to emerging frameworks. The higher the traffic tier, the more modern the stack — the top 10K is 14.4 percentage points less legacy than the top 100K.
Where Legacy Lost Ground
The legacy decline is not driven by a single framework collapsing. It is broad-based. WordPress dropped from 30.4% to 22.4%. Drupal dropped from 27.0% to 21.1%. Joomla from 0.5% to 0.3%. Magento from 0.4% to 0.1%. Every legacy CMS in the scan contracted. No legacy framework gained share.
The modern gains are similarly distributed. Next.js gained 7.9 percentage points — the single largest gain of any framework. Astro gained 0.4 points. React gained 0.7 points. Hugo gained 0.4 points. Vue and SvelteKit held roughly steady. The growth is led by Next.js but supported across the modern cohort.
The Security Dimension
Legacy and modern are not just architectural labels. They correlate directly with security exposure. The legacy cohort — WordPress, Drupal, Joomla, Magento — carries a combined 1,746 CVEs in the NVD. The modern cohort's total is lower still. Framework generation is a proxy for vulnerability density, and the high-traffic web is choosing the lower-density option.
The CSP Signal
WebPulse's July 2026 census also measured Content Security Policy header adoption across the full scan. 24.7% of all scanned domains — 2,458 of 9,947 — return a CSP header. This is not a framework metric but a security posture indicator. Sites with CSP headers are actively managing their content security boundaries. The correlation between CSP adoption and modern framework usage is worth tracking as the census expands to the full 10 million site dataset.
What Happens Next
The generation crossover on the high-traffic web is a leading indicator. The top 10,000 sites are run by teams with the resources and incentive to migrate first. The broader web — tens of millions of sites — follows on a longer timeline. WebPulse is currently scanning the June 2026 Common Crawl index to measure the generation split across 10 million domains. The top-10K crossover tells us where the web is heading. The full census will tell us how far behind the rest of the web is.


