Skip to content
How we score

Methodology

Every number is evidence-based. Here's how we measure framework health.

Security 25%

Vulnerability count and severity from NIST NVD. Active exploit tracking from CISA KEV. Patch velocity from release history.

Performance 15%

Core Web Vitals and TTFB from real-world usage data. Measured across actual sites, not synthetic benchmarks.

Ecosystem Health 15%

Contributor activity, release cadence, issue resolution time, PR merge velocity. Abandonment detection.

AI-Readiness 15%

The dimension that distinguishes WebPulse. Scores structured data output, API-first architecture, semantic HTML, and machine parseability. The web is shifting from human to AI consumption.

Developer Experience 10%

Community size, documentation quality, tooling maturity, developer satisfaction signals.

Market Trajectory 10%

Adoption trends, download velocity, job demand, new project creation rates.

Cost of Ownership 10%

Infrastructure requirements, maintenance burden, security patching load. Static frameworks score highest.

How we identify a site's platform

We fetch a site's homepage and look for signatures each platform leaves behind: paths and markup in the HTML (for example /wp-content/ or /sites/default/files/), generator meta tags, script names, HTTP headers and cookie names. Each signal has a weight, and a platform is reported only when the evidence clears a threshold. A cookie can support a match but never make one on its own if its name is generic: session cookies such as PHPSESSID or JSESSIONID are set by many platforms.

Percentages are always of sites where a platform was identified, never of "the web". Some platforms are easier to see than others: WordPress leaves strong signatures, while server frameworks such as Spring or Laravel can only be identified from headers and cookies.

Datasets

Tranco census. The Tranco top 100,000 research ranking (list Y8YJG), scanned 2026-09-27. 74,472 sites responded and a platform was identified on 27,721 (37.2%). Used for ranking tiers and "top sites" figures.

Common Crawl census. 10,002,735 platform detections from Common Crawl's January–May 2026 crawls, processed 2026-06-05. Built from archived HTML without HTTP headers, so header-only platforms are undercounted. Each domain counts once. Used for "wider web", country and sector figures.

Vulnerabilities. CVE records from NIST NVD matched by each platform's CPE product identifier, and the CISA Known Exploited Vulnerabilities catalog, refreshed daily.

Corrections

September 2026. Our detector matched cookie patterns as fragments of the whole cookie header, and a single cookie could decide a match. Drupal's pattern matched any session cookie, and Spring's matched any Java server. Scans that read HTTP headers (our Tranco scans from May and July 2026, and the July 2026 Common Crawl scan) overstated Drupal, Spring, Laravel and legacy shares. We fixed the detector, re-scanned the Tranco top 100,000, and replaced the affected figures on our data pages. The Common Crawl census above did not read headers and was not affected. Some articles published before the fix cite the earlier figures; we are correcting them.

September 2026. Daily vulnerability counts drifted because updates added modified CVEs without removing old ones, and several platforms were matched to the wrong NVD product. Counts are now rebuilt in full each day from verified product identifiers.

About

Adyog is a web security company. WebPulse is our contribution to making framework decisions evidence-based. Scores are computed algorithmically. No framework vendor pays for placement or influence. adyog sells web security services; WebPulse's findings come from the data above, and we publish them whether or not they point to work we offer.