Dify
Open-source low-code LLM application development platform with 138K+ GitHub stars (April 2026) — the largest agent-framework footprint measured by stars, ahead of Flowise (~40K) and near n8n (~130K). 1M+ deployed apps, 180K+ developers, 400+ model integrations.
Dimension breakdown
Score · confidenceOpen-source low-code LLM application development platform with 138K+ GitHub stars (April 2026) — the largest agent-framework footprint measured by stars, ahead of Flowise (~40K) and near n8n (~130K). 1M+ deployed apps, 180K+ developers, 400+ model integrations. Combines visual workflow orchestration, RAG pipeline, agent framework, and model management in a single self-hostable platform.
Community Edition is free forever; Dify Cloud Professional at $59/mo. Founded March 2023 by the LangGenius community; recent v1.9.0.
Viability is strong on community adoption; monetization is less proven than LangChain peers.
the DifyTap disclosure (2026-06-22) includes an unpatched CVE-2026-41948 (CVSS 9.4, unauthenticated cross-tenant path traversal via the Plugin Daemon API) — fix pending as of disclosure; 3 sibling CVEs fixed in 1.14.2 — triggering a critical-security-vuln cap until patched.
Use cases
Not yet assessed — this section fills in as ACES research covers the tool.
Risk flags
Critical security vuln
securityTemporaryUnpatched critical security vulnerability
Caps Enterprise / Compliance at 25
Removed when — CVE patched and verified, or security incident resolved with post-mortem published
Status rationale
Detected. Dify has the largest agent-framework GitHub star count measured in this catalog (138K+ as of April 2026), 1M+ deployed apps, and 180K+ developers — a clear community signal.
Held at Detected because: (1) no internal hands-on evaluation performed (handsOn=not_tested), (2) monetization and enterprise revenue are less proven than LangChain peers at this evaluation depth, and (3) this is an initial desk evaluation at moderate depth.
Movement triggers
Upgrade to Tracked if: additional enterprise customer references documented, commercial revenue trajectory confirmed, and/or SOC 2 or formal compliance certification verified. Upgrade to Assessed if: internal hands-on evaluation completed with documented pilot results.
Downgrade if: community momentum reverses materially or monetization fails to develop beyond the Community Edition.
Risks & limitations
Critical Security Vuln
ModerateRadar cap: critical-security-vuln
Integration surface
Not yet assessed — this section fills in as ACES research covers the tool.
Adoption & benchmarks
Not yet assessed — this section fills in as ACES research covers the tool.
Spotted something wrong or missing here? Suggest a change →
Per-source contributions
Click any dimension to see the underlying sources and citations.
More in this category