shouldiuse.io

VERDICT

Should I use Dotnet?

Microsoft's free, open-source developer platform for web, cloud, desktop, and mobile apps - dotnet.microsoft.com

Depends. Genuinely free and mature — use it if you are a dev team building web or cloud apps and C# is on the table. Skip it if you are not writing code; it is a framework, not an app, and switching stacks for its own sake just burns time.

Confidence

High. Based on 30+ public sources. Note: .NET is a free developer platform, not a paid SaaS — G2 results for 'dotnet Report Builder' were excluded as a different product.

Ratings

  • Value for money
  • Ease of use
  • Feature depth
  • Support quality
  • Security posture

Pricing

$0

.NET SDK & Runtime

ModelNot disclosed
Monthly feesNot disclosed
HardwareNot disclosed
Free tierYes

Best for

  • Enterprise web APIs
  • Windows-heavy IT shops
  • Cross-platform C# teams
  • High-traffic cloud services

Not for

  • Non-technical founders wanting an app, not a framework
  • Teams with zero C# developers
  • No-code / low-code buyers
  • One-off scripts — Python or Node is simpler

Gotchas - check before you buy

high

CVE-2025-55315 (CVSS 9.9) means Core patches must be applied immediately, not quarterly.

medium

Runtime is free, but surrounding tooling and enterprise support cost extra.

medium

NuGet dependencies can carry vulnerabilities; auditing is your job, tooling exists but is on you.

medium

Every .NET version has a support end date; plan migrations or buy Microsoft extended support.

Pros and cons

Pros

  • Completely free and open source — no licensing costs, commercial use allowed
  • Cross-platform: runs on Linux, macOS, Windows, Android
  • Microsoft-backed with official docs, tutorials, and support policies
  • C# ranks among the top 5 languages; deep ecosystem
  • Used by major consumer brands like Just Eat and Moonpig

Cons

  • CVSS 9.9 vulnerability in Core forced emergency patches (Oct 2025)
  • Three-year LTS window called too short for enterprises
  • Community debates say startups under-adopt it; smaller hiring pool
  • Open-source maintenance described as 'heavily under-funded'
  • Out-of-band security updates force unplanned upgrade work

Sources & method

Analyzed 9/26/2026 - 14 sources - Actively patched by Microsoft, but a CVSS 9.9 ASP.NET Core CVE in 2025 shows serious vulnerabilities do land here.

official x4review x4security x5news x1
  • CVE-2025-55315 — ASP.NET Core request smuggling, CVSS 9.9, disclosed Oct 2025; called the worst .NET vulnerability ever by analysts. Patched via out-of-band releases.
  • CVE-2026-40894 — OpenTelemetry .NET DoS, Denial-of-service vulnerability in the OpenTelemetry .NET component, Apr 2026.
  • CVE-2026-50526 — Microsoft security advisory, .NET security advisory published Jul 2026 via dotnet/announcements.

Key stats

  • Value for money: 5/5

    Rating

  • $0

    Starting price

  • 14

    Sources

  • Analyzed

  • Value for money: 5/5. Free and open source; zero licensing costs
  • Ease of use: 4/5. Modern CLI, solid tooling, quick-start tutorials
  • Feature depth: 5/5. Web, mobile, desktop, cloud — full stack
  • Support quality: 3/5. Free community support; 3-year LTS criticized
  • Security posture: 3/5. Fast patches, but 9.9-CVE shows real exposure
  • $0 Price Free, open source, no licensing costs
  • .NET 10 Latest version 10.0.7 out-of-band security update shipped
  • 3 years LTS support window Criticized as too short by enterprises
  • CVSS 9.9 Worst recent CVE ASP.NET Core, disclosed Oct 2025

Pricing

.NET SDK & Runtime

$0

  • Full platform including ASP.NET Core
  • Open source, commercial use allowed
  • Paid Microsoft support is separate

Security

Actively patched by Microsoft, but a CVSS 9.9 ASP.NET Core CVE in 2025 shows serious vulnerabilities do land here.

  • CVE-2025-55315 — ASP.NET Core request smugglingCVSS 9.9, disclosed Oct 2025; called the worst .NET vulnerability ever by analysts. Patched via out-of-band releases.⁵
  • CVE-2026-40894 — OpenTelemetry .NET DoSDenial-of-service vulnerability in the OpenTelemetry .NET component, Apr 2026.⁸
  • CVE-2026-50526 — Microsoft security advisory.NET security advisory published Jul 2026 via dotnet/announcements.⁹

What users say

Community sentiment swings between strong loyalty and recurring gripes about security patching and slow startup adoption.

“Why I think .NET is the best framework”
Reddit, r/dotnet
“what do you find most frustrating about dotnet?”
Reddit, r/dotnet
“Why isn't dotnet core popular among startups?”
Hacker News

Alternatives

Compare Dotnet with each alternative.

  • Node.js

    JavaScript everywhere; bigger startup hiring pool.

  • Spring Boot

    Mature JVM option for enterprise backends.

  • Django (Python)

    Faster prototyping; friendlier for scripts and data.

Companies that use it

Full analysis

Based on 30+ public sources. Note: .NET is a free developer platform, not a paid SaaS — G2 results for 'dotnet Report Builder' were excluded as a different product.

Free Microsoft dev platform. Strong pick if your team writes C#; irrelevant if you're not building software.

Methodology

Based on 30+ public sources. Note: .NET is a free developer platform, not a paid SaaS — G2 results for 'dotnet Report Builder' were excluded as a different product.

Sources

  1. official
  2. official
  3. official
  4. official
  5. security
  6. security
  7. security
  8. security
  9. security
  10. review
  11. review
  12. review
  13. review
  14. news

Rate this review

Anonymous. You can change your vote.

Loading votes…

Comments

One queue. No nested comments. Give a display name first. Limit: 200 words per comment and 7 comments per day. You can edit or delete yours.

Save a name to write a comment.

0 / 200 words

No comments yet.