shouldiuse.io

Categories

VERDICT

Should I use jooby: do more! more easily!!?

The modular micro web framework for Java - jooby.io

Depends. A solid pick for Java/Kotlin teams who want a lightweight, Flask-like web framework and can live on community support. Skip it if your shop runs on Spring's ecosystem or you need commercial backing.

Confidence

Medium. Based on 20 public sources: Reddit developer threads, official docs, GitHub, a CVE record, and directory listings. No third-party review platforms or named corporate adopters found.

Ratings

  • Value for money
  • Ease of use
  • Feature depth
  • Support quality
  • Security posture

Pricing

$0

Open source

ModelNot disclosed
Monthly feesNot disclosed
HardwareNot disclosed
Free tierYes

Best for

  • Java/Kotlin microservices
  • Devs who want Flask-style simplicity
  • Teams migrating off Spark Java
  • Fast SaaS backend prototypes

Not for

  • Teams needing commercial support or SLAs
  • Shops standardized on Spring's ecosystem
  • Anyone choosing by raw speed benchmarks
  • Non-Java teams adopting a new stack

Gotchas - check before you buy

high

CVE-2025-31129 affected Jooby; fixed only in 2.17.0 and 3.7.0. Stay current.

medium

Old domain shows spammy dental-cleaning content; only trust.

medium

No published security policy — the /security page is a 404.

medium

Community-run open source: support is maintainer goodwill, not an SLA.

Pros and cons

Pros

  • Free, open-source framework for Java and Kotlin
  • Users call it 'just the best' after switching from SparkJava
  • Modular: more a fullstack framework than a bare micro-framework
  • Deployment called 'a breeze'; easy like Flask
  • Fast builds reported — 16 seconds in one user's case

Cons

  • Niche adoption; Semrush rank ~7.3M suggests small community
  • Slower than Vert.x in one user's Hello World comparison
  • Official security page is broken (404)
  • Old domain now serves unrelated spam content

Sources & method

Analyzed 9/30/2026 - 10 sources - One known CVE (2025-31129), patched in 2.17.0/3.7.0; no published security policy found — the security page 404s.

official x2review x5security x2news x1
  • CVE-2025-31129, Vulnerability in the Jooby Java/Kotlin web framework; fixed in 2.17.0 and 3.7.0.

Key stats

  • Value for money: 5/5

    Rating

  • $0

    Starting price

  • 10

    Sources

  • Analyzed

  • Value for money: 5/5. Free and open source; no license costs
  • Ease of use: 4/5. Users compare it to Flask; very easy
  • Feature depth: 4/5. Modular fullstack design, extensive modules
  • Support quality: 3/5. Active maintainer; CVE patched across two branches
  • Security posture: 2/5. One CVE; security page returns 404
  • $0 Starting price Free, open-source framework
  • Yes Free tier Entire framework is free
  • #7,277,976 Web traffic (Semrush) Signals small, niche adoption
  • CVE-2025-31129 Known CVE Fixed in 2.17.0 / 3.7.0

Pricing

Open source

$0

  • Full framework for Java and Kotlin
  • All modules included
  • Community support only

Security

One known CVE (2025-31129), patched in 2.17.0/3.7.0; no published security policy found — the security page 404s.

  • CVE-2025-31129Vulnerability in the Jooby Java/Kotlin web framework; fixed in 2.17.0 and 3.7.0.⁷

What users say

Reddit developers consistently praise Jooby's simplicity, modularity, and fast builds, with one noting slower raw speed than Vert.x.

“Jooby is just the best. I used to be a fan of SparkJava, but will be using Jooby going forwards. Go Edgar! Here's a 16 second build,”
Reddit, r/java
“Jooby is not a "traditional" micro-framework, but more of a modular fullstack framework. u/edgar-espina does a great job at creating modules/”
Reddit, r/java
“Java (Jooby or Quarkus) But deployment is a breeze, Jooby seems nice. it was very easy to use. It's kind of like Flask.”
Reddit, r/SaaS
Full analysis

Based on 20 public sources: Reddit developer threads, official docs, GitHub, a CVE record, and directory listings. No third-party review platforms or named corporate adopters found.

Free, Flask-like Java/Kotlin micro-framework devs praise; tiny community and niche ecosystem make it risky for support-dependent teams.

Methodology

Based on 20 public sources: Reddit developer threads, official docs, GitHub, a CVE record, and directory listings. No third-party review platforms or named corporate adopters found.

Sources

  1. official
  2. official
  3. review
  4. review
  5. review
  6. review
  7. security
  8. security
  9. news
  10. review

Rate this review

Anonymous. You can change your vote.

Loading votes…

Comments

One queue. No nested comments. Give a display name first. Limit: 200 words per comment and 7 comments per day. You can edit or delete yours.

Save a name to write a comment.

0 / 200 words

No comments yet.