The DXP Scorecard — Independent Platform Evaluation
Independent Platform Evaluation
Scored on implementation experience
Not vendor briefings
← Dashboard

Liferay

Traditional DXPTier 2
Visit Website ↗
Overall Capability
59/ 100
#20of 40overall#9of 15Traditional DXP

Liferay is an enterprise Traditional DXP whose portal heritage shows in genuinely best-in-class access control, workflow, multi-site, and intranet capabilities, backed by a strong compliance and trust posture and an increasingly credible AI story following the 2026 AI Hub GA.

Head-to-Head

Capability59 : 63
Cost Efficiency45 : 73
Build Simplicity44 : 54
Operational Ease43 : 50

Both are open-heritage, self-hostable DXPs strong on governance and extensibility, but Liferay leads decisively on native access control, integrated B2B commerce, and enterprise intranet features, while Drupal offers a larger community, cheaper talent, and a lighter PHP footprint. Liferay's Java/Jakarta stack raises complexity and cost relative to Drupal's more accessible ecosystem.

Full Comparison →
Capability59 : 56
Cost Efficiency45 : 24
Build Simplicity44 : 32
Operational Ease43 : 33

Sitecore edges Liferay on marketing tooling, personalization polish, and visual page building, while Liferay counters with best-in-class authenticated-experience access control, native B2B commerce, and multi-deployment flexibility including self-hosting. Both carry enterprise complexity and premium specialist costs.

Full Comparison →
Capability59 : 77
Cost Efficiency45 : 24
Build Simplicity44 : 24
Operational Ease43 : 42

AEM brings broader marketing-cloud integration, a deeper DAM, and richer personalization, but at even higher cost and complexity than Liferay. Liferay offers more transparent multi-deployment options, stronger native intranet and B2B commerce, and a genuine $0 Free Tier, while trailing Adobe on media handling and MarTech breadth.

Full Comparison →
Capability59 : 70
Cost Efficiency45 : 41
Build Simplicity44 : 54
Operational Ease43 : 50

Optimizely leads on experimentation, personalization, and marketing/commerce experience orchestration, whereas Liferay's strengths are authenticated portals, granular permissions, workflow governance, and integrated B2B commerce. Liferay's self-hosting and compliance depth appeal to regulated buyers; Optimizely suits marketing-driven digital experiences.

Full Comparison →
Compare Liferay against any of 40 platforms →

Use-Case Fit

Marketing
58#16 of 40
Commerce
53#5 of 40
Top Fit
Intranet
65#1 of 40
Multi-Brand
59#5 of 40
Ideal For
  • 88Enterprises building employee intranets and digital workplaces
  • 82B2B organizations needing integrated commerce and portal in one platform
  • 80Regulated industries and public sector with strict compliance and data-residency needs
  • 78Multi-brand and multi-tenant enterprises consolidating portals
  • 72Teams standardizing on open, model-agnostic AI agent automation
Look Elsewhere If
  • 25Small teams or startups wanting fast, low-cost time-to-value
  • 30Marketing-led teams needing native campaign and automation tooling
  • 33Content teams requiring real-time collaborative authoring
  • 35Media-heavy brands needing native video and rich visual commerce

Strengths & Weaknesses

Strengths
  • +
    Best-in-class access control and authorization

    Liferay's permission model is among the most granular in the DXP space — resource-level permissions, Regular/Site/Organization/Asset Library roles, permission inheritance through organization hierarchy, and content-instance and field-level controls. Authentication is equally mature with built-in SAML 2.0 (SP and IdP), OIDC, LDAP, MFA, OAuth 2.0, and SCIM provisioning. This is a genuine competitive advantage rooted in Liferay's portal heritage.

    82.75
  • +
    Employee experience and intranet capabilities

    The employee portal / intranet remains Liferay's strongest use case: AI-driven personalized dashboards, native social features (blogs, message boards, mentions), Knowledge Base, announcements, and out-of-the-box connectors for Microsoft 365, Google Drive, Salesforce, and SAP. Enterprise search and mature RBAC round out a genuinely differentiated digital workplace, validated by analyst recognition and customer deployments.

    73.8
  • +
    Compliance certifications and trust posture

    Liferay carries platform-scope ISO/IEC 27001:2022 plus ISO 27017/27018, SOC 2 Type 2 (annually verified since 2019), CSA STAR L1/L2, and a newly earned ISO/IEC 42001 AI Management System certification. GDPR tooling (erasure dashboard, DPA, SCCs), multi-region data residency, documented data-lifecycle retention, and current multi-standard accessibility VPATs give it a strong regulatory-readiness story.

    78.4
  • +
    Configurable workflow and content governance

    The Kaleo Workflow engine supports fully configurable multi-step approval workflows via XML or a visual designer, with role-based routing, Groovy scripts at transitions, SLA tracking via Workflow Metrics, and per-content-structure assignment in the new CMS. Combined with attribute-driven multisite and cascade publishing (IDC MarketScape recognized), governance depth is a genuine strength.

    69.75
  • +
    Multi-site, multi-tenant and multi-brand architecture

    Sites, Virtual Instances, and the new Spaces organizational units let multiple brands or tenants share a single instance with independent or shared content, per-site Style Books for brand theming, and Omni Admin governance with delegated local administration. Cross-brand user management and brand-scoped workflows make Liferay well-suited to multi-brand portfolios.

    70.5
  • +
    Integrated B2B commerce

    Liferay is one of few DXPs with truly native commerce: catalog, pricing, cart/checkout, and order management with B2B/B2C/B2B2C storefronts. B2B content is purpose-built — customer-specific pricing, multi-level account hierarchies, account-gated catalogs, quote workflows, and contract pricing — rather than adapted from B2C, and it sits natively on the same CMS pages.

    72.75
Weaknesses
  • Opaque pricing and high total cost of ownership

    DXP pricing is entirely sales-gated with no published figures for any enterprise, SaaS, or PaaS plan, and multi-environment licensing plus SaaS usage metrics (MALU/APV) create cost uncertainty at scale. Time-to-first-value runs days to weeks and typical implementations span weeks to many months at $10K–$100K+, keeping TCO well above lightweight headless platforms.

    39.75
  • High concept and configuration complexity

    The platform carries an enormous concept count — Sites, Pages, Fragments, Widgets, Objects, Client Extensions, Asset Libraries, Spaces — with legacy Web Content/Blogs/Documents & Media still coexisting in maintenance mode, so developers must understand two content systems during the transition. portal-ext.properties, OSGi config, and Elasticsearch/cache/cluster tuning demand specialist expertise, and production teams realistically need 3–5 people.

    36.5
  • Upgrade difficulty and operational burden

    The mandatory javax→jakarta migration is repeatedly described as a real re-platforming project, not a routine update, and it compounds with the 'One Platform, One Liferay' maintenance-mode transitions of legacy tools. Self-hosted patching remains manual, non-subscribers get only the quarterly .0 release, and no automated migration tooling exists, making operational ease a persistent weak point.

    38
  • No real-time collaboration

    Liferay offers no simultaneous co-editing, presence indicators, or conflict resolution — content editing uses a last-write-wins optimistic locking model. Collaboration is entirely asynchronous via page comments, mentions, and workflow review trails, a fundamental architectural gap versus modern SaaS content platforms.

    33.5
  • Weak native marketing automation and email

    There is no native email campaign builder, drip-campaign engine, behavioral trigger engine, or automated nurture workflow — marketing automation fundamentally relies on external MAPs (Marketo, Eloqua, HubSpot). Beyond the 2026.Q1 HubSpot Lead Capture connector, there are no native ESP connectors and no dedicated campaign management module with calendars or multi-channel coordination.

    31.33
  • Limited native video and rich-media handling

    Liferay provides no native video hosting, transcoding, streaming, or caption management — production video relies on external shortcuts to YouTube/Vimeo/Facebook/Twitch. Asset delivery lacks focal-point/smart crop, on-the-fly URL transforms, and WebP output conversion, and commerce has no native 360/AR/3D or image-hotspot support, so visual-rich use cases require custom work.

    36.33

Deep Dive

Analyst Editorial

The analyst view on Liferay

DXP Scorecard Analyst Team
Liferay is an enterprise Traditional DXP whose portal heritage shows in genuinely best-in-class access control, workflow, multi-site, and intranet capabilities, backed by a strong compliance and trust posture and an increasingly credible AI story following the 2026 AI Hub GA. Its 2026.Q1 unification onto an Objects-based headless CMS, Client Extensions, and a $0 Free Tier modernize the platform, but the Java/Jakarta core keeps concept complexity, configuration surface, and upgrade burden high. Cost is sales-gated and specialist talent is scarce, so total cost of ownership and time-to-value trail lighter platforms. Liferay is strongest for authenticated experiences — employee intranets, B2B commerce portals, and multi-brand governance — and weakest as a fast, low-cost marketing or headless-content platform.
1Core Content Management65
Content Modeling
1.1.1
Content type flexibility
73H

The Objects-based Headless CMS (2026.Q1 LTS) is the primary content modeling path, with legacy Web Content and Blogs in maintenance mode. Content structures support text, numeric, date, upload, related-content, and referenced (nested) structure fields, plus per-field mandatory flags, localization, and workflow assignment — and 2026.Q2 now lets admins add or reorder structure fields retroactively without deleting existing entries, removing a real prior pain point. Schema-as-code is still unavailable (structures are UI/REST-defined), keeping it below headless-native leaders.

1.1.2
Content relationships
63M

Objects support one-to-many and many-to-many relationship fields, and content structures now include related-content and referenced-structure field types, making relationships first-class in the Headless CMS. There is still no graph-style traversal or polymorphic references in the way Hygraph or Contentful offer. Adequate for enterprise use but behind headless-native platforms.

1.1.3
Structured content support
64M

The 2026.Q1 Headless CMS stores content as structured, reusable data via Objects, and content structures can embed referenced structures — providing genuine component embedding within entries. Page Fragments provide UI-level composition. Rich text output remains HTML with no Portable Text equivalent and no unlimited block nesting, which keeps it in the adequate band rather than best-in-class.

1.1.4
Content validation
60M

Objects support required fields, unique constraints, and picklist restrictions, with Groovy-script validations enabling cross-field and regex-style logic on self-hosted/PaaS deployments. Content structures in the new CMS expose mandatory-field configuration. SaaS deployments rely on Client Extensions for custom validation, making the story deployment-model dependent — which caps the score despite the custom-rule capability.

1.1.5
Content versioning
70H

Liferay maintains solid versioning with full version history, draft/approved/expired states, and revert capability, and Objects support content scheduling with display, review, and expiration dates (2025.Q4+); Object entry versioning underpins the new CMS. No visual diff between versions and no content branching remain the gaps keeping it out of the 80+ band.

Authoring Experience
1.2.1
Visual/WYSIWYG editing
72H

Page Builder with Fragments provides genuine in-context visual editing with drag-and-drop and inline content editing, including Marketplace fragment installation within the page builder and multi-step forms in the Page Editor. The experience is strong for portal/intranet use cases but remains less polished than Sitecore XM Cloud Pages or Optimizely Visual Builder.

1.2.2
Rich text capabilities
60H

CKEditor 5 shipped as a release feature in 2026.Q1 (flag LPD-11235) and is the default editor in 2026.Q2+ — with LPD-11235 reversed to re-enable the deprecated CKEditor 4 — standardizing the editing experience platform-wide, including editable rich-text Fragment fields. Output remains HTML rather than a portable AST, and CKEditor 4 custom plugins require rewriting, which keeps this in the standard-WYSIWYG band.

1.2.3
Media management
71M

The new Spaces-based DAM in the 2026 CMS adds AI-powered image generation, automated AI tagging at upload, faceted search across categories/metadata, and asset integration from external systems (SharePoint, Alfresco, Google Drive), while Adaptive Media still generates responsive srcset renditions — a meaningful step up from the maintenance-mode Documents and Media app. The Spaces DAM is at v1 without full legacy parity, and focal-point cropping and URL-based transforms remain absent, keeping it below the 75+ band.

1.2.4
Real-time collaboration
35M

Liferay does not offer real-time co-editing. Content editing uses an optimistic locking model where the last save wins, with limited warning about concurrent edits. Basic commenting and mentions exist via social features, but no presence indicators or conflict resolution for simultaneous editing.

1.2.5
Content workflows
75H

Kaleo Workflow remains one of Liferay's genuine strengths: custom multi-step approval workflows with conditions, transitions, role-based assignments, and audit trails, definable via XML or a visual designer. The 2026.Q1 content structures support workflow assignment per structure, and workflow actions integrate with Object Actions for notifications and webhooks. Significantly more capable than most CMS platforms.

Content Delivery
1.3.1
API delivery model
72H

Liferay provides OpenAPI-compliant REST and GraphQL endpoints, and the 2026.Q1 LTS Headless CMS is purpose-built for API delivery of structured Object content; publishing a custom Object auto-generates REST APIs. GraphQL supports versioned endpoints and siteId by key or external reference code (2025.Q3+). API design still carries Java heritage with verbose response formats, keeping it just below API-native platforms.

1.3.2
CDN and edge delivery
55M

Liferay Cloud includes a Fastly CDN for hosted deployments; self-hosted instances require BYO CDN. Cache invalidation operates at page/resource level rather than per-content-entry, and there is no edge computing or edge-side personalization. Adequate for cloud-hosted, weak for self-hosted.

1.3.3
Webhooks and event system
62H

Object Actions provide webhook support delivering JSON payloads on CRUD events with optional secret-key verification, plus Client Extension and Groovy Script action types with triggers and conditions. With Objects now powering the Headless CMS, these events cover core content operations. Delivery logs, retry configuration, and payload filtering remain less mature than Contentful or Sanity.

1.3.4
Multi-channel output
63M

The 2026.Q1 Headless CMS decouples content from presentation, storing Objects-based content as structured, reusable data deliverable via REST and GraphQL — and the maintenance-mode designation for legacy Web Content confirms the headless commitment. However, rich text still outputs HTML, no official SDKs exist for modern frameworks, and the headless ecosystem is young.

2Platform Capabilities55
Personalization & Experimentation
2.1.1
Audience segmentation
58M

Liferay deprecated local segment authoring in 2026.Q1 (read-only on new installs), but 2026.Q3 brought Liferay Data Platform (LDP, the evolution of Analytics Cloud) to GA, which now provides dynamic, real-time segment building that activates across DXP and third-party tools. Segmentation is more capable than before but centralized in the separately-licensed LDP; native in-DXP authoring is being removed, so there is no free-standing segmentation engine inside the DXP itself.

2.1.2
Content personalization
57M

Liferay supports content personalization through Experience variants on Content Pages, allowing different segments to see different fragments and content, with fallback to default experience and per-segment preview. With local segment authoring deprecated in 2026.Q1, personalization now depends on Analytics Cloud / Liferay Data Platform–managed segments, adding licensing and setup dependency. Remains page-level rather than component-level targeting.

2.1.3
A/B and multivariate testing
52M

Liferay DXP includes A/B Testing for Content Pages with traffic splitting and conversion goal tracking; statistical significance is calculated. Only A/B tests are supported (no multivariate), results depend on Liferay Analytics Cloud integration, and A/B testing is not supported when staging is enabled. No bandit algorithms or auto-optimization exist.

2.1.4
Recommendation engine
40L

Liferay Analytics Cloud provides content recommendation capabilities based on user interest scoring and ML-detected interest topics, but this is not a full algorithmic recommendation engine. Content recommendations are mostly rule-based (related assets, similar content by category) with no cold-start handling and limited placement flexibility.

Search & Discovery
2.2.1
Built-in search
75H

Liferay has excellent built-in search powered by Elasticsearch with full-text search, faceting, type-ahead suggestions, and Search Blueprints for visual relevance tuning (query boosting, filtering, result ranking). Search analytics are available via Analytics Cloud. This is one of Liferay's genuine competitive advantages.

2.2.2
Search extensibility
68M

Liferay's search is deeply tied to Elasticsearch — custom indexing is supported, search pipeline customization is possible via Java service overrides, and Search Blueprints provide declarative configuration. The 2026.Q1 LTS includes a native Elasticsearch 8 connector. Integration with external search platforms (Algolia, Typesense) is possible but requires significant custom development — no official connectors exist.

Commerce Integration
2.3.1
Native commerce
73H

Liferay Commerce is a fully integrated module with product catalog, pricing engine, cart/checkout, order management, and B2B/B2C/B2B2C storefront types. Unified Product Catalog Management centralizes product configuration and channel/account visibility control, and Marketplace cloud payment apps are installable directly within DXP. Strongest in B2B scenarios with price lists, account groups, and approval workflows.

2.3.2
Commerce platform integration
42M

Liferay's commerce strategy centers on its built-in Commerce module rather than external headless commerce engines. Native ERP connectors exist for SAP (real-time pricing, inventory, order management) with Salesforce and MS Dynamics NAV connectors positioned, but there are no pre-built connectors for Shopify, commercetools, BigCommerce, or Salesforce Commerce Cloud — those require custom API work via HTTP Client, Webhook Trigger, MuleSoft, or Talend.

2.3.3
Product content management
70H

Liferay Commerce has purpose-built product content management with SKU-level content, product specifications, options (size/color/etc.), categories, and media per product. Rich product descriptions and variant handling are well-supported. Particularly strong for B2B catalogs with complex product hierarchies and account-specific pricing. Less polished than dedicated PIM solutions but tightly integrated.

Analytics & Intelligence
2.4.1
Built-in analytics
57M

Liferay Analytics Cloud — now evolved into the Liferay Data Platform (LDP), GA in 2026.Q3 — provides content performance dashboards, user behavior tracking, engagement scoring, unified 360-degree profiles, and asset performance metrics. It is functional and improved but remains a separate SaaS product requiring its own setup and licensing, and isn't deeply embedded in the authoring UX; author productivity metrics stay limited.

2.4.2
Analytics integration
50M

Liferay supports analytics integration via JavaScript tag injection through page configuration, enabling GA4 or similar. There are no purpose-built connectors for GA4, Adobe Analytics, Segment, or Amplitude. CDP integration is not native. Analytics middleware or event helpers are absent — effectively manual script injection.

Multi-Site & Localization
2.5.1
Multi-site management
75H

Multi-site is a core Liferay strength via its Sites architecture — multiple sites share a single instance with independent or shared content, configurations, and themes. Virtual Instances provide tenant-level isolation, and the new Liferay CMS adds Spaces as organizational units with team-specific access under centralized control. Liferay's portal heritage gives it genuine advantage here.

2.5.2
Localization framework
67H

Liferay supports field-level content localization with default locale and fallback chains, supporting 50+ languages out of the box, plus in-context translation for Object form fields in the Page Editor with status tracking. The new Liferay CMS (2026.Q1) provides advanced localization per Space. Locale-specific content branching and advanced translation workflows are not available.

2.5.3
Translation integration
47M

Liferay supports machine translation via Google Cloud Translation and Microsoft Translator, and the new Liferay CMS adds translation tooling per Space. However, there are no native TMS connectors for Phrase, Smartling, Lokalise, or Transifex — these require custom integration. Translation memory is not supported.

2.5.4
Multi-brand governance
65M

Liferay's Sites and Virtual Instances architecture supports multi-brand scenarios — brand-level permissions via Organizations, shared content libraries with per-brand overrides, and centralized administration are achievable. However, there is no explicit 'brand' governance concept; multi-brand is implemented through Sites configuration. Design system support is limited to theme inheritance. Brand-level analytics require separate Analytics Cloud/LDP setup per brand.

Digital Asset Management
2.6.1
Native DAM capabilities
58M

Documents and Media and Asset Libraries — Liferay's established DAM stack with metadata sets, version history with checkout/check-in, file expiration/review dates, and granular permissions — entered maintenance mode in 2026.Q1 in favor of the new Liferay CMS, whose Spaces-based asset management (file types, custom fields, recycle bin, workflows) is still maturing and does not yet demonstrate full parity. Legacy DAM remains functional but frozen; key gaps of no usage tracking and no watermarking/DRM persist across both systems.

2.6.2
Asset delivery & CDN optimization
42M

Adaptive Media generates multiple resolution variants at upload time and serves responsive images via HTML srcset/picture elements. Liferay Cloud (PaaS/SaaS) includes a Fastly-backed CDN; self-hosted requires external CDN configuration. However, there is no focal point or smart crop capability, no on-the-fly URL parameter image transformations, and WebP/AVIF is supported as input format but not auto-converted on output.

2.6.3
Video & rich media management
22H

Liferay does not provide native video hosting, transcoding, or streaming infrastructure. Production video relies on External Video Shortcuts referencing YouTube, Vimeo, Facebook, or Twitch (4 platforms out of the box), a pattern carried into the new Liferay CMS. FFmpeg integration generates preview thumbnails for locally stored video files but is not production streaming. No caption or subtitle management exists within Liferay.

Authoring & Editorial Experience
2.7.1
Visual page builder & layout editing
68H

Content Pages with drag-and-drop Fragments are Liferay's primary authoring surface since DXP 7.3. Fragments support inline text/image editing on the canvas, Master Pages define shared layouts, and device preview modes (desktop/tablet/mobile) are available. 2024.Q4 added multi-element selection (CTRL/SHIFT); 2025.Q3 enabled Marketplace fragment packs installable from the Page Editor; 2026.Q3 enhanced Fragment Headless APIs and fragment management. Limitations: Fragment creation requires HTML/CSS/JS knowledge — no purely no-code component builder; Widget portlets have a different UX paradigm.

2.7.2
Editorial workflow & approvals
73H

Liferay's Kaleo Workflow engine supports fully configurable multi-step approval workflows defined in XML or via visual node-based Workflow Designer. Task assignment supports specific users, roles, or organizational hierarchy; Groovy scripts fire at state transitions; SLA tracking with Workflow Metrics shows on-time vs. overdue items, velocity, and performance by step/assignee. The new Liferay CMS also supports workflow assignment to content structures with task review/approval. Full audit trail of transitions and comments is maintained.

2.7.3
Publishing calendar & scheduling
55M

Liferay supports scheduled publishing via Publications (branch-based, schedule a publication to go live at specific date/time), individual web content display/expiration dates, and Object entries with Publish Date, Expiration Date, and Review Date fields. However, there is no visual content calendar — Publications shows only a table list of scheduled items. Publications entered maintenance mode in 2026.Q1 with no direct replacement announced. No release bundle dependency ordering exists.

2.7.4
Real-time collaboration
32H

Liferay's collaboration model is entirely asynchronous — Page Comments allow editors to leave inline comments on specific fragments in the Content Page Editor (editorial-only, not published), and workflow approvals provide a review trail. The new Liferay CMS adds 'Shared with Me' areas and access controls but still no simultaneous co-editing, no presence indicators, and no content diff/compare view between versions. Last-write-wins on concurrent edits.

Marketing & Engagement
2.8.1
Forms & data capture
55M

Liferay's Forms application (multi-page, conditional rules, validation, data storage) is in maintenance mode as of 2024.Q4 with no further feature development. The recommended path is Objects + Form Container fragments, which supports multi-step forms via stepper components and fires webhook actions on create/update. In-context translation of form fields was added in 2025.Q1. Key gaps remain: no progressive profiling, no native reCAPTCHA, and the Objects replacement requires more assembly than purpose-built form builders.

2.8.2
Email marketing & ESP integration
28M

Liferay has no native email campaign builder or ESP capabilities. The official HubSpot Lead Capture connector submits lead data to HubSpot CRM, and a HubSpot Click to Chat Marketplace app exists, but this is not marketing automation. No native connectors for Mailchimp, Marketo, Eloqua, or Salesforce Marketing Cloud — all require middleware (MuleSoft connector add-on, Tray.io, or custom API work).

2.8.3
Marketing automation
26M

Liferay's 2026.Q3 GA of the Content Marketing Platform (CMP) adds campaign and content planning, and Liferay Data Platform enables real-time segment activation across channels — but Liferay still ships no native drip-campaign engine, behavioral trigger engine, or automated nurture workflows. Automation execution fundamentally relies on external MAPs (Marketo, Eloqua, HubSpot).

2.8.4
CDP & customer data integration
55M

The 2026.Q3 GA of the Liferay Data Platform (LDP), the evolution of Analytics Cloud, delivers a genuine native CDP — stitching identity, behavioral, and CRM data into unified 360-degree profiles and enabling real-time dynamic segments that activate across DXP and third-party tools, positioned to eliminate the need for a separate CDP. It remains a separately-licensed product at v1 GA, and there are still no native connectors to Segment.io, mParticle, or Tealium — reciprocal integration requires custom API work.

Integration & Extensibility
2.9.1
App marketplace & ecosystem
52M

The Liferay Marketplace lists approximately 815 applications covering collaboration, commerce, document management, forms, CRM connectors, identity, and analytics, now spanning DXP Apps, Client Extensions, Low-Code Configurations, Cloud Apps, and full Solutions. Key enterprise integrations exist for Salesforce, SAP, MuleSoft, Camunda, Microsoft Office 365, Google Drive, and Atlassian. However, the catalog is modest, fragmented between legacy module-based (.lpkg) apps and client extension–based Cloud Apps, and not all apps are maintained for the latest quarterly releases.

2.9.2
Webhooks & event streaming
42M

Liferay Objects support Webhook action types delivering JSON payloads on entry create/update/delete with a configurable HMAC secret. Object Actions support conditional triggers (Groovy/field conditions) as pre-send filters. The official Camunda connector uses Liferay webhooks to trigger BPMN processes. However, webhooks are scoped exclusively to Object events — there is no platform-wide event bus covering page publish, workflow state changes, or user events. No retry/dead-letter queue is documented.

2.9.3
Headless preview & staging environments
35M

Publications provides branch-based in-context preview within a single Liferay instance (no shareable external URL) but entered maintenance mode in 2026.Q1 and does not track changes made in the new headless Liferay CMS — the two systems remain disconnected. Classic Staging (Local Live, Remote Live) is also in maintenance mode. No shareable draft preview links for non-authenticated external stakeholders exist in either the legacy stack or the new CMS.

2.9.4
Role-based permissions & governance
78H

Liferay has a mature, granular RBAC system with Regular, Site, Organization, and Asset Library role types; custom roles with permissions down to individual asset instances; field-level permissions for custom Objects; and Space-scoped roles (Space Administrator, Content Reviewer, Member) in the new Liferay CMS. SSO is comprehensive: SAML 2.0 (built-in SP/IdP), OIDC (multi-provider), OAuth 2.0, CAS, and LDAP. SCIM became GA in 2025.Q1, enabling automated user provisioning/deprovisioning with Okta and Azure AD.

3Technical Architecture65
API & Integration
3.1.1
API design quality
65H

Liferay DXP's 2026.Q1 LTS introduced a new API-first headless CMS replacing legacy content tools, alongside OpenAPI-compliant REST and GraphQL APIs with an in-admin API Explorer; the 2026.Q2 release (May 2026) continued on this baseline. 2025.Q3+ added siteKey/externalReferenceCode support to GraphQL endpoints and 2026.Q1+ moved LAR export/import onto the batch framework. Still carries Java verbosity, nested payloads, and multiple coexisting API generations — not higher until the new CMS APIs fully supersede legacy patterns.

3.1.2
API performance
55M

API performance depends heavily on deployment configuration (self-hosted vs Cloud). No published SLAs for API response times. Pagination uses standard page/pageSize parameters; batch headless APIs handle bulk operations. No CDN-backed delivery tier. Performance at scale requires careful Elasticsearch and database tuning — not inherently fast without optimization.

3.1.3
SDK ecosystem
48M

Official SDK coverage remains thin: Java SDK, aging Android/iOS mobile SDKs, and a JavaScript client without full TypeScript support. No official Python, Go, Ruby, or .NET SDKs. Developers can self-generate clients (java, javascript, typescript-fetch) from Liferay's OpenAPI specs via openapi-generator, but no officially published, maintained typed client packages. Lower range for this item.

3.1.4
Integration marketplace
62H

Liferay Marketplace at marketplace.liferay.com has a moderate catalog. 30+ integrations are natively bundled with Liferay 7.4+, covering LDAP, Salesforce, SSO providers, OpenSearch, Solr, MuleSoft, and HubSpot. Many community-maintained connectors have varying quality and update frequency. The marketplace is less vibrant than in the 6.x/7.0 era and smaller than competitors like Contentful or Sitecore.

3.1.5
Extensibility model
74H

Client Extensions are the standard extensibility model in 2026 with four categories (frontend, microservice, configuration, batch), supporting React, Vue, Angular, and Node.js without Java/OSGi knowledge; the 2026.Q1 LTS positions them as the upgrade-safe customization path, and FE client extensions gained HMR for faster iteration. Backend client extensions (documented on Liferay Learn) let developers add custom business logic and orchestrate external workflows via headless APIs. Legacy OSGi extensibility (ModelListeners, ServiceWrappers, custom portlets) remains for deep customization. Limited only by the complexity of the legacy path.

Security & Compliance
3.2.1
Authentication
80H

Authentication remains a genuine Liferay strength. Full SAML 2.0 (SP and IdP), OpenID Connect, LDAP synchronization, MFA support and enforcement, configurable session management, and OAuth 2.0 for API access. SSO is available without top-tier plan gating. Enterprise authentication is mature and battle-tested across large organizations. Not higher because the configuration UX is complex compared to modern SaaS platforms.

3.2.2
Authorization model
85H

One of the most granular permission systems in the DXP space. Resource-level permissions, role-based access with Regular, Site, Organization, and Asset Library roles, individual permission assignment, content-level access control, and permission inheritance through organization hierarchy. Custom roles are fully supported. Field-level and content-instance permissions are available. The permission system is extremely flexible for complex enterprise access requirements.

3.2.3
Compliance certifications
76H

Liferay's Trust Center confirms SOC 2 Type 2 alongside ISO/IEC 27001:2022, ISO/IEC 27017:2015, ISO/IEC 27018:2019, and CSA STAR Level 1 and 2. GDPR tooling (data erasure/export), EU cloud regions, and HIPAA-eligible Cloud deployments are available. Not higher because self-hosted compliance depends on customer infrastructure and certification breadth still trails Adobe.

3.2.4
Security track record
63H

Liferay runs a public bug bounty on Intigriti with a formal responsible disclosure process, CVE assignment, and a maintained Known Vulnerabilities page. However, 2025–2026 brought a steady stream of XSS CVEs (CVE-2025-43776/43777/43778/43746/43757, plus stored XSS in the Workflow Process Builder CVE-2025-62239 and reflected XSS CVE-2025-62248, itself a regression of a previously fixed flaw) alongside an authorization flaw (CVE-2025-62247). Strong disclosure posture offset by high CVE volume and a regression — a process-quality concern that keeps it mid-range.

Infrastructure & Reliability
3.3.1
Hosting model
78H

Liferay offers genuine multi-deployment flexibility: Liferay SaaS (fully managed), Liferay Cloud/PaaS (AWS/Azure/GCP), self-hosted on any infrastructure, and Docker/Kubernetes deployment. The 2026 unified platform replaces separate CE/DXP installations with a single activation-key distribution across all models (2026.Q2 shipped on the same distribution and free tier). Not higher because self-hosted deployments are complex and Liferay Cloud adds significant cost.

3.3.2
SLA and uptime
60M

Liferay Cloud offers 99.95% uptime SLA for production with a public status page (status.liferay.cloud) including per-region uptime history. Incident record is mixed: an 11-hour partial outage in September 2025, shorter incidents in November 2025 and April 2026, and an acknowledged outage in late May 2026. Self-hosted uptime is entirely customer-managed. Not higher given the incident frequency and no vendor SLA for self-hosted.

3.3.3
Scalability architecture
65M

Liferay supports horizontal scaling via clustering with cache coherence and session replication. Elasticsearch clusters handle search load. Liferay Cloud provides auto-scaling. Proven at enterprise scale (Airbus, Bosch). However, scaling requires significant infrastructure expertise — cache coherence, session management, and search index synchronization all need careful configuration. No CDN-backed content delivery layer.

3.3.4
Disaster recovery
62M

Liferay Cloud provides automated backups and point-in-time recovery; self-hosted deployments need custom strategies for database, document library, and Elasticsearch indices. Content export improved in 2026.Q1+ as LAR export/import now uses the batch framework at site and instance scopes, making large exports more reliable. Still no publicly documented RTO/RPO targets, and LAR remains a proprietary format.

Developer Experience
3.4.1
Local development
56H

Liferay provides Blade CLI for scaffolding and Liferay Workspace (Gradle/Maven) for dev environment setup, with Docker-based local development. Client Extensions improved the dev loop with modern JS toolchains (Webpack, TypeScript) and HMR for frontend extensions. However, the full Liferay server must run locally, requiring significant setup and slow startup times — far from the instant-feedback loops of headless CMS platforms.

3.4.2
CI/CD integration
55M

Liferay Cloud has built-in Jenkins-based CI/CD pipelines for building, testing, and deploying, with dev/UAT/prod environment management. Client Extensions integrate naturally with external CI/CD pipelines for automated deploy and rollback. Self-hosted requires custom setup; content migration via LAR remains fragile despite 2026.Q1 batch improvements. No content-as-code workflow, deploy previews, or branch environments.

3.4.3
Documentation quality
66H

Liferay Learn (learn.liferay.com) is a structured, role-based education ecosystem covering implementation, architecture, Client Extensions, headless APIs, and commerce, with structured learning paths and dedicated 2026 deprecation/breaking-change references for the Q1 LTS transition. API reference includes OpenAPI specs. Still limited by Java-centric code examples and gaps in advanced configuration docs.

3.4.4
TypeScript support
42M

Client Extensions support TypeScript via modern Webpack toolchains, and Liferay documents generating typescript-fetch clients from its OpenAPI specs via openapi-generator — a workable but DIY typed-client path. There is still no officially published typed SDK, no auto type generation from content schemas or Objects, and TypeScript is not integrated into the headless API workflow out of the box.

4Platform Velocity & Health56
Release Cadence
4.1.1
Release frequency
66H

Liferay's quarterly cadence continues on schedule through 2026: 2026.Q2 shipped (New Global Menu, release webinar) followed by 2026.Q3.0 and 2026.Q3.1, with the 2026.Q1 LTS and its patch line (2026.Q1.11-LTS) maintained in parallel. The major standalone launch of Liferay AI Hub to GA on 2026-08-19 adds significant net-new capability between quarterly cores. Not higher because the platform core still ships on a quarterly (not monthly) rhythm typical of SaaS leaders.

4.1.2
Changelog quality
58M

learn.liferay.com maintains structured per-quarter release notes plus a '2026 Deprecations and Breaking Changes' reference with per-release sub-pages, and each quarterly release now ships with a documented webinar and service-life/EOL policy. Still short of 75+ because code examples are sparse and migration guidance for complex scenarios remains incomplete.

4.1.3
Roadmap transparency
58M

Liferay publishes a public roadmap at liferay.com/roadmap organized in Now/Next/Later buckets (AI Hub, Content Marketing Platform, Liferay Data Platform) and runs a Feature Requests portal on Liferay Ask with community voting and product-team responses linking Jira tickets. The roadmap communicates high-level vision without committed timelines and voting is not integrated into the roadmap page itself, keeping it below the 70+ tier.

4.1.4
Breaking change handling
57M

The unified 2026 platform keeps upgrades a license-key change rather than a migration, LTS releases carry multi-year support windows, and maintenance-mode transitions of legacy tools are documented with recommended alternatives — structured deprecation practice. No codemods or automated migration tooling exists, and the volume of maintenance-mode transitions still imposes real planning burden.

Ecosystem & Community
4.2.1
Community size
50M

GitHub liferay/liferay-portal remains modest (~2.3K stars, ~3.8K forks) versus headless competitors (Strapi 65k+, Payload 30k+) though the codebase is very active. discuss.liferay.com hosts the Free Tier community with regular per-release activity and liferay.dev retains a deep content archive. The Free Tier (March 2026) is drawing participants but hasn't yet materially grown the overall community footprint.

4.2.2
Community engagement
52M

discuss.liferay.com shows consistent official engagement — Liferay staff post each Free Tier/quarterly release and respond to threads — and the Feature Requests portal receives product-team responses with Jira links. Core development remains overwhelmingly internal with rare external contributions, which caps the score.

4.2.3
Partner ecosystem
54M

Liferay maintains a formal partner program with a searchable directory, regional/global tiers, and developer certification, and Camunda named Liferay its 2026 Technology Partner of the Year for AI-powered orchestration — deepening a strategic alliance around the AI Hub launch. Partner strength remains concentrated in LATAM and Europe; finding Liferay-specialized agencies in North America or APAC is still harder than for AEM or Sitecore.

4.2.4
Third-party content
40M

Third-party coverage ticked up around the 2026 release model and AI Hub launch — XTIVIA published multiple AI Hub analyses ('A First Look', 'Pros, Cons, and Who Should Care'), and Nirvana Lab and others cover the 2026 AI roadmap. Still no significant new Udemy/Pluralsight courses or sustained YouTube series, and much existing content references legacy 7.x versions.

Market Signals
4.3.1
Talent availability
43M

Liferay developer talent remains scarce relative to AEM, Sitecore, or mainstream JS-stack platforms, with the Java/OSGi specialization a high barrier for generalists and the pool concentrated in LATAM, Spain, and India. The Free Tier and unified platform lower the experimentation barrier, but a measurable hiring-pool effect hasn't materialized in job-market signals.

4.3.2
Customer momentum
55M

Momentum strengthened through mid-2026: Liferay AI Hub reached GA (2026-08-19) as a new standalone SaaS product, the company published fresh market research ('54% of companies running AI agents'), earned 2026 Gartner Customers' Choice recognition, and won Camunda's 2026 Technology Partner of the Year. Headcount is roughly stable (~1,145 as of March 2026). Visible net-new enterprise logo announcements remain modest, keeping this mid-range.

4.3.3
Funding and stability
60M

Liferay remains privately held / bootstrapped (Pufferfish Partners) with ~1,145 employees as of March 2026 and no layoff or acquisition news for 2025–2026; sustained R&D investment (unified platform, Free Tier, new CMS, AI Hub GA) signals health. Headcount has drifted modestly downward from ~1.3K in 2023, and the R&D budget remains smaller than publicly traded competitors, capping the score.

4.3.4
Competitive positioning
57M

Liferay holds its 15th consecutive Gartner MQ for DXPs placement with improved execution and substantially improved vision scores (analysts note it sits 'just shy' of Leaders), ranks highest in the Authenticated Experience use case in Gartner Critical Capabilities, and is an IDC MarketScape Leader for AI-enabled full-stack CMS. The AI Hub GA sharpens its 'unbundled, AI-at-the-center' differentiation. Still a Niche Player overall with an on-premise-heavy install base signaling SaaS-transition challenges.

4.3.5
Customer sentiment
68M

Liferay was named a 2026 Gartner Peer Insights 'Customers' Choice' for DXPs — one of only two vendors so recognized among seven — with a 4.6/5 overall rating (64 reviews as of July 2026), the highest of all vendors in the report, and 91% willing to recommend. That is up from the prior 4.4/5 / 83% recommend, with strong sub-scores (deployment 4.5; product, support, and sales 4.4). The still-modest review volume (~64) keeps it below the 75+ band despite the top rating.

5Total Cost of Ownership45
Licensing
5.1.1
Pricing transparency
35H

Liferay DXP pricing remains entirely sales-gated in 2026 — no public pricing for any enterprise, SaaS, or PaaS plan; buyers must request a quote via [email protected]. Enterprise subscriptions reportedly start around $25K–$50K/year but this is never officially published; only the Free Tier carries a clear price of $0. The request-a-quote model creates significant friction for comparison shopping.

5.1.2
Pricing model fit
45M

Self-hosted DXP uses per-server-instance/per-environment subscription licensing that escalates with dev/staging/prod and clustering. SaaS plans meter MALU (Monthly Active Logged-in Users) and APV (Anonymous Page Views), introducing usage-based variability. Predictable at base level, but multi-environment licensing and usage metrics create cost uncertainty at scale; the Free Tier offers a $0 alternative without enterprise features.

5.1.3
Feature gating
50H

The 2026.Q1 release unified CE and DXP into one modular platform gated by activation keys, and the Free Tier now includes clustering on up to three nodes — a genuine improvement. However, security-critical features including multi-factor authentication, SAML SSO, and advanced search tuning still require an Enterprise Subscription key, which is exactly the problematic gating pattern (SSO/security behind enterprise). Free Tier patch access also stops at each quarter's stable release.

5.1.4
Contract flexibility
48M

Liferay requires annual or multi-year subscriptions with no monthly billing option. The Free Tier provides a $0 entry point for development, PoC, and small-scale use, with an in-place upgrade path to enterprise (apply a Subscriber Activation Key, no reinstallation under the unified 2026 platform). No publicly documented startup program; exit and renewal provisions depend on contract negotiation.

5.1.5
Free / Hobby Tier
70H

The unified Free Tier gives everyone the same core DXP installation as enterprise: content management, sites, headless APIs, workflow, all supported databases, and clustering on up to three nodes. However, activation keys are valid only 12 months and must be renewed, keys are domain-registered, patch eligibility ends at each quarter's stable release, and MFA/SAML are excluded. A capable free tier, but the renewal requirement, key gating, and Java infrastructure footprint keep it below lightweight open-source alternatives.

Implementation Cost Signals
5.2.1
Time-to-first-value
40M

Getting to first deployed content with Liferay takes days to weeks, not hours. Setup requires a Java app server, database, Elasticsearch, activation-key registration/deployment, content type definition, and theme work. Docker-based quickstart exists but still demands Java ecosystem knowledge; Liferay SaaS reduces infrastructure setup but onboarding and content modeling remain time-intensive versus headless CMS platforms.

5.2.2
Typical implementation timeline
42M

Typical Liferay projects run weeks to many months: simple portals 4–8 weeks, moderate enterprise projects 3–6 months, complex integration-heavy deployments 9–12+ months, with implementation costs of $10K–$100K+. The quarterly release model and a mandatory javax-to-jakarta migration (guides advise budgeting 2× estimated upgrade time) add ongoing effort, keeping timelines in adequate-to-poor territory for an enterprise DXP.

5.2.3
Specialist cost premium
42H

Liferay developers command a 30–50% premium over generalist web developers. US salaries average ~$127K/year (range ~$96K–$171K), with embedded Liferay specialists costing $180K–$350K/year for 6–12 month engagements and freelance/offshore rates ranging $30–$100+/hr. Java/OSGi skill requirements and a smaller talent pool drive rates up; Client Extensions are lowering the barrier slightly but the core remains specialist territory.

Operational Cost Signals
5.3.1
Hosting costs
50M

Self-hosted Liferay requires multi-component infrastructure — Java application server, MySQL/PostgreSQL database, Elasticsearch cluster, and optionally document storage and caching — putting production hosting at roughly $500–$2000+/month. Liferay SaaS bundles hosting into the subscription (no infra cost) and PaaS adds cloud infra usage on top, so total hosting spend is comparable to other enterprise DXPs regardless of path.

5.3.2
Ops team requirements
40M

Self-hosted and PaaS Liferay's real expense is engineering hours spent on upgrades, patch cycles, and infrastructure maintenance year after year — server patching, database and Elasticsearch management, cache/cluster tuning, and the quarterly-release upgrade cadence realistically demand part-time to full-time DevOps. SaaS reduces this substantially but configuration and deployment management remain; PaaS removes infrastructure ops but not application-level operations.

5.3.3
Vendor lock-in and exit cost
40M

Migration out of Liferay is moderately difficult. Content extracts via headless REST APIs in JSON (a positive), but content models, permissions, workflows, and configurations are not easily portable; the LAR export format is proprietary and custom code (OSGi modules, Fragments, Client Extensions) is platform-specific. The 2026 unification also means even free usage runs the keyed DXP binary rather than a fully independent open-source build, and no vendor migration tooling to competitors exists.

6Build Simplicity44
Learning Curve
6.1.1
Concept complexity
34H

Concept count remains very high: Sites, Pages, Fragments, Widgets, Objects, Client Extensions, Asset Libraries, Roles, plus Spaces (now GA in 2026.Q2) as the headless CMS organizational unit — while legacy Web Content/Blogs/Documents & Media persist in maintenance mode, so two content systems still coexist through the transition. The strategic consolidation on Objects genuinely reduces overlapping abstractions for greenfield builds, but today developers must understand both worlds. Not lower because the Objects-centric direction is now the clear default for new work.

6.1.2
Onboarding resources
57M

Liferay Learn offers a structured, role-based curriculum updated through 2026.Q1, including dedicated courses on Objects data modeling, backend and frontend Client Extensions, Workspaces & Tooling, and Jakarta upgrades, with free access for customers, partners, and community plus an active certification catalog. Still no rapid 'build something in 30 minutes' quickstart, and onboarding assumes enterprise developer context, so it stays mid-range.

6.1.3
Framework familiarity
41H

Client Extensions are now the go-to approach for extending Liferay — they run outside the portal container against headless APIs in any language (React, Node.js, Vue, Angular, Spring Boot), across frontend, microservice, configuration, and batch categories, and the 2026.Q1 headless CMS is API-first for any frontend. However, core platform customization still requires Java/Jakarta EE, FreeMarker remains the fragment templating language, and React components must often be wrapped as Web Components. Held here because mainstream-stack development is the default path but the proprietary core persists.

Implementation Complexity
6.2.1
Boilerplate and starter quality
45M

Sample Client Extension projects in Liferay Workspace remain the recommended starting points, with Blade CLI supporting quarterly release targeting and Jakarta upgrades. There are still no official Next.js/Nuxt/Astro starters, no one-click deployments, and no vendor-maintained reference frontend even for the 2026.Q1 headless CMS — searches surface only community GitHub examples. Samples demonstrate individual features rather than complete applications.

6.2.2
Configuration complexity
35H

Configuration surface remains enormous: portal-ext.properties with hundreds of settings, OSGi config, System/Instance/Site Settings, Elasticsearch, cache, and clustering. The Jakarta EE migration completed in the 2026.Q1 LTS is characterized by practitioners as a foundational re-platforming — 'not a weekend project' — touching the app server, Java runtime, and every line of custom code using enterprise APIs, adding substantial upgrade configuration work for existing teams. Defaults suffice for basic operation but production tuning still requires specialist expertise.

6.2.3
Data modeling constraints
48M

The 2026.Q1 headless CMS standardizes content modeling on Liferay Objects — structured, reusable data with auto-generated headless and batch APIs, stable alphanumeric class names (since 2025.Q1), and data model export/import for cross-environment portability. Legacy Web Content Structure risks matter less for new builds since Web Content is in maintenance mode. Automated migration tooling for breaking Object schema changes remains limited, and migrating existing Web Content into the new CMS is still an open effort.

6.2.4
Preview and editing integration
55M

Page Builder still provides solid built-in preview and in-context editing for portal pages, with Marketplace fragments installable directly in the builder. The 2026.Q1/Q2 headless CMS adds in-context analytics in the authoring UI but no evidence of a turnkey draft-preview mode for external Next.js/React frontends — headless preview still requires custom implementation via Client Extensions. Held at the same score: built-in editing remains good, headless preview remains DIY.

Team & Talent
6.3.1
Required specialization
39H

With Client Extensions running outside the container against headless APIs and the 2026.Q1 CMS exposing standard APIs, generalist React/Node developers can handle a growing share of project work without OSGi or deep Java expertise. However, Java/Jakarta EE skills remain mandatory for core customization and upgrades, FreeMarker for fragments, and Liferay's active certification ecosystem reflects how proprietary the full skill set still is. Held here because the accessible-extension surface keeps expanding but the specialist core persists.

6.3.2
Team size requirements
38M

A production Liferay deployment still realistically needs 3-5 people minimum: backend Java developer(s), frontend developer, and DevOps/infrastructure. The headless CMS and Client Extensions shift work toward more accessible skills but don't reduce the infrastructure, upgrade (Jakarta/LTS), and platform-management burden that drives team size. SaaS hosting trims the ops role somewhat, but enterprise deployments remain multi-role projects.

6.3.3
Cross-functional complexity
53M

The headless CMS is explicitly designed to let marketers manage global content without heavy IT reliance, and 2026.Q2 ships concrete editor self-service gains: AI-powered translation for multi-language content, and single-step replacement of text, URLs, or terms across the entire platform, atop Spaces for team-organized repositories and in-context analytics. Page Builder with installable Marketplace fragments remains accessible to non-technical users. New content types (Objects) and custom layouts still require developer involvement and authors need moderate training, so it stays mid-range — but the shipped Q2 tooling measurably reduces post-go-live friction.

7Operational Ease43
Upgrade & Patching
7.1.1
Upgrade difficulty
36H

2026.Q1 LTS shipped as the recommended Jakarta target (5-year subscriber support, 3-year modernization window) and Liferay promotes Client Extensions (API-first, no Java deployed to core) to soften future upgrades, but the Jakarta migration itself is repeatedly described as 'a real project, not a routine update' — every javax.* becomes jakarta.*, Portlet 3.0→4.0, Tomcat 9→10.1, and custom code coupled to internal APIs is the biggest time sink. Not lower because the LTS landed with mature Blade/Workspace source-formatter tooling and a stable multi-year target; not higher because customization-heavy installs still face a compile-breaking namespace migration and manual JSF/Spring tweaks.

7.1.2
Security patching
48H

CVE volume remains high through 2025 — recent disclosures include CVE-2025-3586 (instance-admin code execution via Objects Actions), CVE-2025-62252 (IDOR authorization bypass), and multiple stored/reflected XSS (CVE-2025-3760, CVE-2025-62247) spanning 7.2 GA through 2024.Q4.x. Advisories are transparent (liferay.dev known-vulnerabilities) and service releases ship monthly. Not higher because self-hosted patching remains manual and CE non-subscribers only receive the .0 release each quarter; not lower because cadence is regular and risk-based prioritization is documented.

7.1.3
Vendor-forced migrations
40H

Two compulsory transitions now compound: the mandatory javax→jakarta migration (2025.Q3 onward is Jakarta-only) and the 'One Platform, One Liferay' 2026 model, which shifts legacy Web Content, Blogs, and Documents & Media into maintenance mode in favor of a new headless CMS (Beta in 2025.Q4, Release in 2026.Q1). Not lower because both moves carry long runways — a 3-year LTS window, migration tooling, and Client Extensions to decouple customizations — and classic tools remain supported in maintenance mode; not higher because migrating custom javax code is unavoidable and go-forward content architecture is being redirected on Liferay's timeline.

7.1.4
Dependency management
36M

Self-hosted Liferay still requires Java runtime, application server, database, and Elasticsearch, and the Jakarta transition forces coordinated updates of javax-coupled third-party libraries (Hibernate, Jackson, Log4j) plus an app-server move (Tomcat 9→10.1 / JBoss EAP 7→8). Cloud Native Experience — now GA for AWS on Kubernetes/Terraform/Helm/Argo CD — standardizes infrastructure but adds its own toolchain rather than shrinking the dependency tree. Not higher because OSGi bundle management and the multi-service footprint persist; not lower because CNE and PaaS meaningfully automate provisioning.

Operational Overhead
7.2.1
Monitoring requirements
46M

Cloud Native Experience ships Unified Observability — product-aware metrics and Grafana dashboards for system health and resource consumption — plus HPA and self-healing Kubernetes, and the Liferay Cloud Console provides environment monitoring, logs, and automated backups for PaaS. Self-hosted deployments outside CNE still need custom JVM, database, and Elasticsearch monitoring. Not higher because adoption requires the CNE/PaaS stack and bare self-hosted installs get nothing built in; not lower because product-aware dashboards are now a packaged offering.

7.2.2
Content operations burden
50M

Ongoing content operations still require moderate manual attention — content structure maintenance, taxonomy management, and asset library organization need periodic work, and orphaned content or broken references require manual cleanup. The new headless CMS may reshape this over time, but during its maintenance-mode transition no new content-hygiene automation has landed in the 2025-2026 quarterly releases. Not lower because governance tooling (workflows, expiry, permissions) is mature; not higher because hygiene relies on editorial discipline rather than automated detection.

7.2.3
Performance management
42M

CNE's Horizontal Pod Auto-scaling and self-healing clusters reduce capacity-management effort for cloud-native deployments, and Liferay SaaS/PaaS handle baseline scaling automatically. Self-hosted deployments still demand active cache configuration, database query optimization, Elasticsearch tuning, and JVM garbage collection management to maintain performance at scale. Not higher because custom tuning remains necessary even on managed deployments with heavy customization; not lower because the automated scaling story is genuinely improving.

Support & Resolution
7.3.1
Support tier quality
48M

G2 reviews (4.4 stars, 163 reviews) consistently praise responsive, knowledgeable support and helpful account reps/architects, but quality support remains gated behind premium tiers (Standard/Premium/Platinum) and Community Edition has no official support. Not lower because a meaningful share of enterprise customers report genuinely good experiences and 'quality of support' is a cited strength; not higher because tier gating persists and some reviewers still report delays and documentation gaps.

7.3.2
Community support quality
43M

Liferay maintains an active community Slack with steady vendor participation around Jakarta migration and the 2026 release model (liferay.dev blogs, discuss.liferay.com), but the community is thin relative to WordPress or Drupal ecosystems and Stack Overflow coverage is moderate for common questions and sparse for advanced topics. Not lower because vendor staff actively engage on Slack and blogs; not higher because overall community volume is limited and G2 reviewers call the community small.

7.3.3
Issue resolution velocity
40M

Quarterly releases plus a monthly service-release stream give subscribers a regular fix pipeline, and steady CVE remediation shows active security response. However, CE non-subscribers only receive the .0 release each quarter, so bug fixes can wait months, and non-critical bugs still persist across multiple quarterly releases. Not higher because community-reported issue responsiveness remains mixed and feature requests move slowly; not lower because subscriber-facing security and service cadence is regular.

8Use-Case Fit59
Marketing Sites
8.1.1
Landing page tooling
64H

Liferay's Page Builder with Fragments provides drag-and-drop layout and in-context editing. The Content Marketing Platform (CMP) lets marketers launch landing pages and microsites without leaving the platform, and automated A/B testing is available for conversion optimization. The new headless CMS (GA in 2026.Q1) does not change the page-building experience. Fragment development still requires developer involvement for new layouts, keeping it below dedicated marketing DXPs like Optimizely or Sitecore XM Cloud.

8.1.2
Campaign management
40M

Liferay lacks a dedicated campaign management module with campaign calendars or multi-channel coordination. The CMP adds content workflow capabilities and the Content Dashboard Performance tab provides asset-level engagement metrics, but content scheduling remains the primary campaign-like feature. The new 2026.Q1 HubSpot Lead Capture connector bridges Liferay forms to HubSpot for downstream campaign execution, but campaign orchestration itself still lives in the external MAP. Marketing teams still require external tools for true campaign coordination.

8.1.3
SEO tooling
62M

Liferay supports meta title/description per page, sitemap generation, OpenGraph metadata, and friendly URL management. The Page Audit tool (powered by Google PageSpeed Insights) provides SEO and accessibility recommendations per page. The AI Assistant helps craft SEO-friendly headlines and meta descriptions. Structured data (JSON-LD) still requires custom implementation, redirect management is basic, and there is no SEO scoring or keyword validation tool.

8.1.4
Performance marketing
50M

The native Forms module handles lead capture, and the 2026.Q1 HubSpot Lead Capture connector now automatically syncs Liferay form submissions to HubSpot CRM — contacts, companies, and leads flow into marketing automation and nurture workflows without custom integration. Combined with A/B testing for page optimization and AI Insights surfacing behavior-driven improvements, the lead-capture story is meaningfully stronger. However, there is still no native CTA management, no native conversion tracking, and no UTM parameter awareness — conversion attribution and nurture happen in the connected MAP rather than in Liferay.

8.1.5
Personalization and targeting
70H

Liferay retains a mature personalization engine: audience segmentation by behavior, demographics, location, and custom attributes; content page personalization via Experiences; AI-driven personalized dashboards; and real-time segment evaluation. However, as of 2026.Q1 local segment authoring inside DXP is deprecated — new installations are read-only by default and segmentation work must move to Liferay Analytics Cloud. While Analytics Cloud is first-party, this adds a SaaS product dependency for self-hosted customers and transition friction during the deprecation window, slightly weakening the previously fully self-contained personalization story.

8.1.6
A/B testing and experimentation
68H

Liferay provides native A/B testing for content pages, testing headline variants, layouts, and CTAs with statistical significance tracking and winner detection. Tests are managed within the platform and synced automatically with Analytics Cloud for result reporting against bounce rate and click metrics, with winner publishing as the new default. The capability is solid for content-level experimentation but does not extend to full-funnel or server-side feature flagging.

8.1.7
Content velocity
62M

CMP provides content calendaring and workflow to reduce cycle time. AI Assistant helps draft blog posts, knowledge base articles, and structured page layouts, accelerating initial content creation. Fragment-based page building allows template cloning and reuse. The 2026.Q2 release adds Link Content Fields (author, category, or location maintained once and referenced everywhere, cutting re-entry) and makes CKEditor 5 the default authoring editor, both incrementally improving authoring throughput. The object-based headless CMS (GA in 2026.Q1) provides a more modern authoring interface, though legacy Web Content is now in maintenance mode, creating a transitional period. New page layouts still require developer-built Fragments.

8.1.8
Multi-channel publishing
65H

Liferay's API-first architecture enables create-once, publish-everywhere delivery, and the 2026.Q1 headless CMS strengthens this: content is stored as structured, reusable data built on Liferay Objects and consumable on DXP pages, external applications, or any channel via headless APIs. CMP is built for multichannel and multisite management, enabling content distribution to web, mobile apps, and connected devices from a single authoring environment.

8.1.9
Marketing analytics integration
52M

Liferay Analytics Cloud integrates with DXP to provide visitor behavior tracking, content performance metrics, and segment-level analytics within a Liferay-native interface. The Content Dashboard Performance tab surfaces per-asset engagement metrics. Page Audit tool provides SEO performance signals. However, Analytics Cloud is a separate SaaS product and connection with GA4, Adobe Analytics, or Mixpanel requires tag-based integration and relies on external dashboards for reporting.

8.1.10
Brand and design consistency
62H

Style Books enforce design tokens (colors, typography, spacing) at the site level, and Fragment Libraries provide approved, reusable components that constrain what marketers can assemble. Brand guardrails are enforced through the component palette rather than locked style overrides. This is functional but marketers can still override some styling within allowed component configurations, making it short of full lock-down brand governance.

8.1.11
Social and sharing integration
42M

Liferay supports Open Graph and Twitter Card metadata per page, enabling proper social preview cards across platforms. There is no native social scheduling, push-to-social workflow, or social media management integration. UGC embeds require custom development. Social proof widgets are not native. Basic OG/meta tag management covers the fundamentals but no social publishing workflow is available.

8.1.12
Marketing asset management
58H

Liferay Documents and Media provides a functional DAM layer with Asset Libraries for cross-site sharing, image transformations, tagging, metadata, and search. The AI Assistant can generate image alt text and descriptions. Documents and Media moved to maintenance mode in 2026.Q1 with asset management transitioning to the new headless CMS, but existing capabilities remain supported. Rights management and usage tracking are limited compared to dedicated DAM platforms.

8.1.13
Marketing localization
60M

Liferay provides multi-language content management, translation workflows with third-party connector support, locale-specific URL management, and per-locale content scheduling. Content can be maintained in multiple languages with approval workflows per locale. However, transcreation-specific workflows (market-level campaign variants, region-specific promo calendars) are not native — generic localization is applied to marketing content rather than purpose-built marketing localization.

8.1.14
MarTech ecosystem connectivity
53M

Liferay offers out-of-the-box connectors for Salesforce (CRM), SAP, and Microsoft 365, and the 2026.Q1 release adds a native HubSpot Lead Capture connector that syncs form data, contacts, and companies to HubSpot for email marketing and workflow automation — the first pre-built marketing-automation-class connector, closing a prior gap. Flexible API/webhook integration covers other systems and Analytics Cloud provides behavioral data. However, there are still no pre-built connectors for Marketo, Pardot, Eloqua, ad platforms, or CDP systems; broader MarTech integration still requires custom API development or iPaaS.

Commerce
8.2.1
Product content depth
73H

Liferay Commerce provides genuine product content management with catalogs, SKU/variant modeling, product specifications, options, and rich media per product. The 2026 commerce roadmap emphasizes advanced PIM-style catalog tooling, centralized product configuration management at scale, and bulk updates with master configurations. ML-based predictive analytics power personalized product recommendations and order forecasting. B2B-specific features — customer-specific pricing, multi-level account hierarchies, account-gated catalog views — remain strong differentiators.

8.2.2
Merchandising tools
55M

Liferay Commerce provides category management, product display widgets, ML-powered suggested product groups, personalized recommendations, and smart loyalty score alerts. These are functional for B2B catalog merchandising but search merchandising remains basic and content-driven commerce experiences (e.g., shop-the-look, editorial overlays) still require custom development.

8.2.3
Commerce platform synergy
45M

Liferay's commerce strategy is self-contained — Liferay Commerce is the intended path rather than integrating with external platforms. There are no pre-built connectors for Shopify, commercetools, BigCommerce, or Salesforce Commerce Cloud, and integration with these platforms requires custom API development. This is a weakness for composable commerce architectures.

8.2.4
Content-driven storytelling
55M

Liferay's integrated CMS and Commerce layer allows combining editorial content with product data on the same page — product display widgets can be embedded within CMS content pages. Buying guides and product-adjacent editorial are achievable. However, shoppable content (inline add-to-cart within editorial), lookbooks, and shop-the-look experiences are not first-class authoring patterns and require custom Fragment development.

8.2.5
Checkout and cart content
55M

Because Liferay Commerce is native to the DXP, checkout pages are standard CMS pages built with the Page Builder. CMS-managed content — trust badges, promotional banners, upsell widgets — can be placed in cart and checkout pages through the same authoring interface. This is a meaningful advantage over headless-only platforms. However, injecting dynamic CMS content into specific transactional flow steps (e.g., post-add modals) without template changes still requires developer work.

8.2.6
Post-purchase content
42M

Liferay Commerce includes an account portal where customers can view order history, credit limits, and account documentation — providing basic post-purchase content. Smart loyalty score alerts and ML-driven recommendations can surface post-purchase upsell content. However, CMS-managed order confirmation pages, delivery tracking content, product onboarding sequences, and review solicitation workflows triggered by order events are not native capabilities.

8.2.7
B2B commerce content
75H

B2B commerce content is Liferay Commerce's strongest suit. Native capabilities include customer-specific pricing display, multi-level account hierarchies with account-gated catalog visibility, quote-request workflows, contract pricing, spec sheets per product, and gated product documentation. Liferay maps complex relationships like parent-child companies so each entity operates independently across channels while staying governed. These are purpose-built B2B content features, not repurposed B2C capabilities.

8.2.8
Search and discovery content
62H

Liferay Commerce uses Elasticsearch for product search with faceted filtering, category-based navigation, related product display, and search landing pages. Search Blueprints allow content managers to customize result ranking and content blending. AI-powered relevance improvements are included. Content-product search blending is possible within the unified CMS+Commerce environment. Synonym management and search analytics are supported.

8.2.9
Promotional content management
52M

Liferay Commerce supports promotional pricing, discount rules, and tiered pricing structures. CMS-managed promotional banners and product spotlights can be scheduled through the Page Builder. Personalized promotion targeting based on audience segments and intent signals is available. However, countdown timers, promo code display widgets, and channel-specific promotional content management are not native features and require custom development.

8.2.10
Multi-storefront content
58M

Liferay Commerce supports multiple storefronts with multicurrency and multilingual configurations, enabling region- or brand-specific commerce experiences from a single instance. Shared product catalogs with storefront-specific editorial and pricing are achievable, and 2026 roadmap work on centralized product configuration across multiple channels, order types, and accounts strengthens this pattern. However, storefront-specific editorial governance adds operational complexity and there is no dedicated multi-storefront content management dashboard.

8.2.11
Visual commerce and media
45M

Liferay Commerce supports image galleries, multiple media per product, and video embeds on product pages. The Documents and Media system handles image transforms. However, there is no native 360-degree product viewer, AR/3D model integration, or image hotspot functionality. Advanced visual commerce experiences require third-party integrations or custom development. This reflects Liferay's B2B focus where visual richness is less critical than account management depth.

8.2.12
Marketplace and seller content
22L

Liferay Commerce is not designed for marketplace or multi-vendor commerce scenarios. There are no native seller profile management, seller-contributed product descriptions, review aggregation, or content moderation tools for multi-vendor scenarios. Liferay's B2B commerce model assumes a single seller with multiple buyer organizations — not a marketplace model. Implementing marketplace seller content would require extensive custom development.

8.2.13
Commerce content localization
58M

Liferay Commerce supports multicurrency display, multilingual product descriptions, and locale-specific storefront configurations. Generic localization infrastructure applies to product content. Country-specific pricing rules and multilingual catalog management are supported. However, regulatory content (EU labeling, CA Prop 65), locale-specific promo calendars, and currency-aware editorial content blocks are not purpose-built features — they require configuration and some custom work.

8.2.14
Commerce conversion analytics
45M

Liferay Analytics Cloud and the Commerce analytics module provide order forecasting, product-level purchase analytics, and ML-driven engagement insights. Content-to-commerce attribution is partially achievable by correlating content engagement data from Analytics Cloud with order data from Commerce. However, direct revenue attribution to content pages, content-assisted conversion paths, and product content performance dashboards are not native — they require custom reporting or BI tool integration.

Intranet & Internal
8.3.1
Access control depth
88H

Access control remains one of Liferay's strongest capabilities, reflecting its portal heritage. Granular resource permissions, organization-based access hierarchies, role-based content visibility, user group management, SSO integration (SAML, OIDC, LDAP), and department/site-level access control are all deeply supported. For intranet scenarios, Liferay's permission model is best-in-class among DXP platforms.

8.3.2
Knowledge management
78H

Liferay provides purpose-built knowledge management through the Knowledge Base application (hierarchical articles, versioning, search), Wiki, Message Boards, and strong taxonomy/tagging. Search Blueprints surface relevant knowledge, and AI-powered search improves discovery. Content lifecycle management (review dates, expiry) is available for knowledge articles. For enterprise knowledge management, Liferay remains one of the strongest DXP options.

8.3.3
Employee experience
83H

Employee portal capabilities remain Liferay's strongest use case: AI-driven personalized dashboards, notifications, social features (blogs, message boards, mentions), announcements, workflow-driven approvals, and mobile access. Out-of-the-box connectors for Microsoft 365, Google Drive, Salesforce, and SAP enhance the digital workplace experience. Customer deployments like Toll Global Express and Coach demonstrate frontline-inclusive intranet patterns. LDAP/AD directory integration is mature.

8.3.4
Internal communications
70H

Liferay supports targeted internal communications with announcements, department-level news feeds, role-based audience targeting for content visibility, and alert notifications. Mandatory-read workflows and read-receipt tracking are achievable through the Workflow engine. The platform provides solid internal comms infrastructure for enterprise intranets. Purpose-built features like read receipts and acknowledgment dashboards require workflow configuration rather than being out-of-the-box.

8.3.5
People directory and org chart
60M

Liferay has a native people directory integrated with the organization hierarchy and user profile system. Employee profiles can include skills, contact information, and organizational position. Organization hierarchy reflects reporting structures. HR system integration (Workday, BambooHR) is possible via API but no pre-built connectors exist. A visual org chart widget is available as a marketplace app but is not in the core platform.

8.3.6
Policy and document management
62M

Liferay's Documents and Media provides document versioning, metadata, taxonomy, and workflow-based approval. The Knowledge Base supports policy-style content with versioning and review workflows. Mandatory-acknowledgment flows can be configured through the Workflow engine. Automated content expiry and review reminders require custom workflow configuration. This covers the functional basics of policy management but lacks turnkey SOP tracking and audit trail dashboards.

8.3.7
Onboarding content delivery
55M

Liferay's BPM and Workflow engine can automate onboarding content delivery sequences — role-specific task checklists, staged content access, and new-hire notification workflows are achievable. The platform's role-based personalization can surface role-specific onboarding dashboards. However, progressive 30/60/90-day content journeys, LMS-connected learning paths, and HR-triggered new-hire portals require workflow configuration and potentially custom development, rather than being turnkey.

8.3.8
Enterprise search quality
68H

Liferay's Elasticsearch-powered search provides AI-enhanced relevance, faceted filtering, Search Blueprints for customizable ranking, and synonym management. Search covers all Liferay content types natively. Federated search can be extended to index external systems (SharePoint, Confluence) via custom connectors. AI-powered semantic search improvements have been added in recent releases. Search quality for internal content volumes is strong.

8.3.9
Mobile and frontline access
50M

Liferay DXP supports mobile delivery through responsive web and headless APIs, with customer deployments (Toll Global Express, Coach) demonstrating frontline mobile intranet patterns. The platform supports push notifications and mobile-optimized layouts. However, a dedicated native Liferay intranet app (comparable to Unily, Staffbase, or Viva Engage) is not part of the core product — mobile access is primarily via responsive web browser or custom-built mobile apps using the headless APIs. Offline support is not native.

8.3.10
Learning and training integration
42M

Liferay does not have a native LMS or e-learning module. Learning content can be hosted in the platform via Web Content, Knowledge Base, and structured content types. The Workflow engine can track content consumption for basic completion flows. Integration with LMS platforms (Cornerstone, Workday Learning, SAP SuccessFactors Learning) is possible via API but no pre-built connectors exist in the core product. Micro-learning and certification tracking require external LMS.

8.3.11
Social and collaboration features
68H

Liferay has a mature social layer for enterprise intranets: blogs, message boards, comments, reactions, mentions, forums, polls/surveys, idea submission (app), and community spaces (sites) per department or interest group. Peer recognition programs can be built on the platform. Legacy Blogs moved to maintenance mode in 2026.Q1 but remain fully supported, and the new Liferay CMS adds native blog-building on modern fragments and style book tokens. Social features are native and purpose-built for the intranet use case, not bolted-on widgets.

8.3.12
Workplace tool integration
72H

Liferay provides out-of-the-box connectors for Microsoft 365 (including Teams integration), Google Drive, Salesforce, and SAP. Document co-editing via SharePoint/OneDrive integration is supported. Teams notifications and Slack webhooks are achievable. The integration depth provides a meaningful single-pane experience for employees, embedding Office documents and enterprise application content within the intranet. Bot-driven integrations require custom development.

8.3.13
Content lifecycle and archival
55M

Liferay supports content expiry dates, workflow-based review cycles, and archival states for web content and knowledge base articles. Content ownership assignment and expiry notifications can be configured. Stale content flagging and automated review reminders require workflow configuration rather than being turnkey. The overall lifecycle management is functional for intranet governance but below purpose-built intranet platforms with automatic stale content dashboards.

8.3.14
Internal analytics and engagement
52M

Liferay Analytics Cloud provides content engagement metrics, visitor behavior tracking, and segment-level analytics applicable to intranet measurement. Page-level view data, engagement heatmaps, and failed search term analysis are available. Department-level content performance segmentation is achievable via Analytics Cloud segments aligned to organization groups. Dedicated intranet adoption dashboards and ROI reporting are not turnkey — they require custom Analytics Cloud dashboard configuration.

Multi-Brand / Multi-Tenant
8.4.1
Tenant isolation
72H

Liferay supports multi-tenancy through Virtual Instances (separate users, sites, configurations, database/schema-level data separation, and domains) and Sites for lighter isolation. Cross-tenant administration is available to an Omni Admin while local administrators manage their own instances. Virtual Instances share the same JVM, which limits true physical isolation for strict regulatory requirements. As of 2026.Q1, using multiple domains requires an Enterprise Subscription — a licensing rather than architectural constraint.

8.4.2
Shared component library
62M

Fragments can be shared cross-site via Fragment Libraries, Style Books provide brand-level theming per site, and Asset Libraries enable shared content across sites. However, there is no explicit brand override mechanism for shared components — per-brand customization requires site-specific fragment variants — limiting native cross-brand design system support.

8.4.3
Governance model
68H

Liferay's organization hierarchy, site administration model, and role-based permissions provide a functional governance framework. The 2025 IDC MarketScape recognized Liferay for attribute-driven multisite publishing, cascade publishing, visual workflow design, quality gates, and life-cycle automation across content supply chains — confirming governance depth. Virtual Instances enable centralized governance with local variation across regions, brands, or business units. There is still no purpose-built multi-brand governance dashboard.

8.4.4
Scale economics
56M

Multiple brands can share a single Liferay instance, providing infrastructure cost sharing. The 2026.Q1 unified platform (single modular distribution with activation keys replacing separate CE and DXP installations) reduces operational overhead and provides a free tier with quarterly feature releases. However, multiple domains for Virtual Instances now require an Enterprise Subscription, licensing costs still scale with deployment size, and each brand requires independent theme development and content operations.

8.4.5
Brand theming and style isolation
62H

Style Books provide per-site design token configurations (colors, typography, spacing) enabling genuine per-brand visual identity on a shared component foundation. Each site can have its own Style Book assignment, and Fragment Libraries can be brand-filtered. This supports per-brand theming at the platform level while sharing the underlying component structure. Custom theme development is still required for full brand differentiation beyond Style Book tokens.

8.4.6
Localized content governance
55M

Liferay supports per-brand localization through site-level language configurations, translation workflows with approval chains, and locale-specific content scheduling. However, brand-aware translation approval (where Brand A's French team approves translations independently of Brand B's French team) requires careful Workflow configuration per site — it is not a turnkey brand-x-locale governance model. Regional legal content governance per brand requires custom workflow design.

8.4.7
Cross-brand analytics
45M

Liferay Analytics Cloud can be configured to aggregate data across sites (brands) within a single DXP instance, providing per-site and comparative engagement metrics. Publishing cadence and content velocity can be monitored per site. However, there is no executive portfolio dashboard that presents brand-level performance side-by-side out of the box — cross-brand aggregation requires custom Analytics Cloud segment and workspace configuration.

8.4.8
Brand-specific workflows
62H

Liferay's visual Workflow Designer allows independently configured approval chains per site (brand), enabling brand teams to manage their own publishing workflow while central administrators retain audit oversight. Workflow instances can be scoped to specific sites and content types. Central workflow audit logs are available at the system level. Per-brand workflow autonomy with central auditability is a genuine capability.

8.4.9
Content syndication and sharing
62H

Liferay supports cascade publishing and attribute-driven multisite publishing — recognized by IDC MarketScape 2025 as key strengths. Asset Libraries enable corporate-level content shared across brand sites with site-level override capability. Content can be pushed from a master site to child brand sites with controlled local adaptation. This covers the core corporate-to-brand syndication pattern, though the override granularity per content element is limited.

8.4.10
Regional compliance controls
50M

Liferay provides per-site compliance configurations — cookie consent management, GDPR features, and accessibility settings can be configured per Virtual Instance or site. Virtual Instances separate data at the schema level, supporting regional and business-specific regulatory compliance. Publishing guardrails (e.g., preventing GDPR-non-compliant publishing) are achievable via Workflow quality gates. Data residency is configurable in Liferay Cloud deployments. However, turnkey per-brand/region compliance rules with automated publishing guardrails are not a native self-service feature.

8.4.11
Design system management
58M

Liferay provides a centrally maintained design foundation through Fragment Libraries (shared components) and Style Books (design tokens). Fragment Libraries can be versioned and updated centrally, with updates propagating to consuming sites. Style Books provide brand-level extensions of the central token set. This covers the core federated design system pattern. However, version governance (preventing specific brands from using older Fragment versions) and brand extension without forking are limited.

8.4.12
Cross-brand user management
68H

Liferay's Virtual Instance and Organization hierarchy enable central admin management of all brands with autonomous brand-level team administration. The Omni Admin can manage all Virtual Instances from a single control plane while local administrators oversee users, sites, and content for their own portals. SSO (SAML, OIDC) operates across all instances. The model effectively provides central governance with delegated brand autonomy.

8.4.13
Multi-brand content modeling
54M

Liferay's Web Content Structures can be shared across sites, providing a base content model usable by multiple brands, and the object-based headless CMS (GA 2026.Q1) stores content as structured, reusable data. The 2026.Q2 Link Content Fields add relational modeling — an entry (author, category, location) is maintained once and referenced across brands rather than duplicated — improving shared-model reuse. Site-specific structure variations allow some per-brand customization. However, extending a shared base model per brand without forking (e.g., Brand A adds a video field independently of Brand B) is still not natively supported — model changes typically require forking the base structure.

8.4.14
Portfolio-level reporting
42L

Liferay does not provide an out-of-the-box executive portfolio reporting dashboard spanning multiple brands/sites. Content freshness by brand, publishing SLA adherence, and cost allocation per tenant are not native reporting dimensions. Analytics Cloud provides per-site engagement data but requires custom configuration to aggregate into portfolio-level executive views. Operational reporting across the brand portfolio requires custom BI tool integration (Tableau, Power BI).

9Regulatory Readiness & Trust75
Data Privacy & Regulatory
9.1.1
GDPR & EU data protection
80H

DPA applies by default to cloud customers in EEA, UK, Latin America, and Mexico, with SCCs implemented for cross-border transfers; other customers can request it. Liferay publishes a detailed sub-processor table (entities, locations, functions, transfer mechanisms) with 10 days' notice before new appointments. EU residency via Frankfurt and Hamina (Finland), UK via London, plus a built-in Personal Data Erasure dashboard. Meets the 80 threshold for DPA + EU residency + SCCs + public sub-processor list; not higher without additional EU-specific attestations.

9.1.2
HIPAA & healthcare compliance
68M

Liferay's Trust Center lists HIPAA readiness alongside ISO 27001/27017/27018, SOC 2 Type 2, and CSA STAR Level 2, and the healthcare industry page documents Business Associate Agreement capability under HIPAA with SaaS, PaaS, or self-hosted options for PHI control. HIPAA has no formal platform certification program, so this rests on BAA availability plus documented healthcare deployments. Not 70+ because BAA terms and plan eligibility remain a case-by-case offer rather than a published self-service legal document.

9.1.3
Regional & industry regulations
67M

GDPR built-in with DPA and erasure tooling; CCPA via DPA; LGPD coverage implied by default DPA application to Latin America plus São Paulo hosting; Spain's Esquema Nacional de Seguridad (ENS) listed on the Trust Center. The new ATO FastTrack initiative (launched Sept 4, 2026) adds a documented US-government readiness path — an authorization-ready low-code platform with Zero Trust controls, plus FIPS 140-3 readiness and OSCAL-based documentation coming by end of 2026. Not higher because ATO FastTrack is a path to agency ATO, not a FedRAMP authorization Liferay itself holds, and no IRAP/C5/HITRUST exists.

Security Certifications
9.2.1
SOC 2 Type II
78H

Current SOC 2 Type 2 attestation, independently verified annually since 2019, covering Liferay PaaS, SaaS, Analytics Cloud, and Managed Services. Reports available to customers upon request, and the DPA allows a recent SOC report to substitute for customer audits. Not 85+ because the specific Trust Service Criteria covered beyond Security are still not publicly documented.

9.2.2
ISO 27001 / ISO 27018
80H

Liferay holds ISO/IEC 27001:2022 (certificate ISMS-LS-5319) with scope covering development, operations, maintenance, and delivery of the DXP and Cloud Services Platform — platform scope, not just infrastructure. Also certified ISO/IEC 27017:2015 and ISO/IEC 27018:2019 for cloud PII processing, audited by A-LIGN. Meets the 80+ threshold for platform-scope ISO 27001 plus ISO 27018.

9.2.3
Additional certifications
74H

Portfolio now adds ISO/IEC 42001 (AI Management System, certified Dec 2025 — among the first companies globally), a meaningful current attestation, on top of CSA STAR Level 1 (CAIQ) and Level 2, CSA Trusted Cloud Provider, Spain ENS, and ISO 27017. ATO FastTrack signals FIPS 140-3 readiness in progress for 2026. Still no PCI DSS, FedRAMP authorization, or Cyber Essentials Plus, which caps the score below 78.

Data Governance
9.3.1
Data residency & sovereignty
80H

Liferay Cloud offers region choice across US, EU (Frankfurt, Hamina), UK (London), Brazil (São Paulo), India (Mumbai), and Australia (Sydney), with each environment independently placeable for granular data sovereignty. Backups are restricted to the instance's data region and never leave it; on-premise/self-hosted DXP provides complete residency control. Meets the 78+ threshold for multiple regions with contractual guarantees.

9.3.2
Data lifecycle & deletion
76H

Post-termination retention is documented: customers have 14 days to retrieve data after subscription end, with permanent deletion 30 days after termination; Analytics Cloud retention defaults to 13 months and is configurable. Built-in Personal Data Erasure dashboard provides self-service right-to-erasure with APIs for third-party integration, plus data portability export. Meets the 75+ threshold for self-service export + documented retention + API-based erasure.

9.3.3
Audit logging & compliance reporting
75H

Comprehensive audit framework captures logins, password and entitlement changes, group membership, and content operations, with output in CSV or JSON. Native SIEM integration via Splunk, ELK stack, Syslog audit message processor, and CloudAMQP; ATO FastTrack reinforces continuous monitoring within a Zero Trust posture. DPA additionally grants customer audit rights with documentation support. Meets 75+ for comprehensive logs with native SIEM integration.

Platform Accessibility
9.4.1
Authoring UI accessibility
73H

Liferay publishes a current 'DXP Admin Experience Accessibility Conformance Report' (VPAT 2.5Rev, dated Nov 29 2025 for the 2025.Q4 release) — formal conformance documentation specifically for the authoring/admin interface, now covering WCAG 2.x, Revised Section 508, and EN 301 549. Conformance evaluated with automated static analysis plus manual testing using screen readers, magnifiers, and speech recognition. Exceeds the 70 threshold given current, authoring-specific, multi-standard formal documentation.

9.4.2
Accessibility conformance documentation
73H

Current VPAT-based ACRs are publicly downloadable for procurement: December 2025 Admin Experience and Sites Experience reports (VPAT 2.5Rev), covering WCAG 2.x, Section 508, and EN 301 549. A dedicated accessibility compliance page is maintained. Meets 70+ for current, public, multi-standard VPAT/ACR availability; not higher because ATAG 2.0 assessment is still not documented.

10AI Enablement54
AI Content Creation
10.1.1
AI text generation & editing
57H

AI Creator remains GA in the Web Content and DAM editors (ChatGPT via a user-supplied OpenAI key, with tone and word-count controls), and with AI Hub reaching GA (Aug 19, 2026) the built-in AI writing tasks in Liferay CMS — change tone, fix grammar, summarize text — are now shipping rather than beta, alongside a Content Site Generator for AI-assisted multi-page site creation. Still no documented brand voice guardrails or custom prompt template governance, holding the score in the basic-generation band despite the GA milestone.

10.1.2
AI image & media generation
50H

AI Creator integrates DALL-E for image generation from text prompts with results stored directly in the DAM — a genuine native AI image pipeline, GA. Auto-tagging of images and documents at ingest via OpenNLP, Google Cloud, and Microsoft Cognitive Services providers partially covers discoverability. No dedicated auto alt-text generation or AI video processing documented, keeping this mid-band.

10.1.3
AI translation assistance
55M

Bulk automated translation via Google Cloud Translation and Amazon Translate is built into the localization workflow (categories, images, structures, and content in bulk), with side-by-side review, and AI Hub (now GA) offers translation agent templates that auto-translate content on publish. No brand voice preservation across locales or translation quality scoring documented, which keeps this in the basic-MT band.

10.1.4
AI metadata & SEO automation
42M

Auto-tagging of web content, documents, blogs, and images via OpenNLP, Google Cloud, and Microsoft Cognitive Services is GA, and the Page Audit Tool surfaces SEO/accessibility diagnostics via Google PageSpeed Insights. SEO titles, meta descriptions, canonicals, and hreflang are configurable and localizable in the UI but are manually authored — no AI generation of SEO copy or schema suggestions documented, capping this at partial automation.

AI Workflow Automation
10.2.1
AI-assisted content operations
57M

Multiple AI assists are woven into editorial: auto-tagging on publish, automated multi-language translation, AI Insights recommendations, and — with AI Hub now GA (Aug 2026) — shipping agent templates for content tagging, translation, support-ticket triage, and user segmentation, plus a centralized AI Assistant that coordinates tasks against DXP search context. Held below 60 because the assists still operate as discrete features rather than a single unified editorial AI workflow.

10.2.2
Agentic workflow automation
64H

Liferay AI Hub reached general availability on Aug 19, 2026 (public beta since June) — a named, standalone agentic product with a visual Agent Builder (prebuilt nodes for LLM calls, data lookups, API integrations, and custom scripting), multi-agent orchestration chaining specialized agents end-to-end, prebuilt agent templates, MCP-based data access, and audit-trailed, permission-scoped execution. Lands in the solid-GA band rather than 80+ because human review checkpoints and event-driven triggers are still 'coming in later releases,' so approval gates within agentic runs are not yet shipped and the GA is early with maturing docs.

10.2.3
Content intelligence & insights
42M

AI Insights analyzes user behavior and content performance to surface real-time layout and content strategy recommendations (e.g., proactive surfacing of renewal content, frustration detection triggers), and the Content Dashboard provides taxonomy-based content analytics. Still no AI-driven content gap analysis, topic clustering, or editorial priority scoring comparable to dedicated content intelligence dashboards.

10.2.4
AI content auditing & quality
35M

The Page Audit Tool surfaces SEO and accessibility issues via Google PageSpeed Insights — useful but rule-based and external-API-driven rather than AI-native. With AI Hub now GA, 'automated compliance review' is a shipping agent template you can build audit-at-scale flows on, but it is a DIY building block, not a turnkey audit product. No AI quality scoring, brand voice compliance checking, or duplicate/thin content detection documented, keeping this near the band floor.

AI Search & Personalization
10.3.1
AI/semantic search
62H

Liferay Enterprise Search ships production semantic search — text embeddings stored in Elasticsearch via txtai or Hugging Face providers with cosine/dot-product similarity — and the 2026.Q1 LTS native Elasticsearch 8 connector adds Reciprocal Rank Fusion (RRF) hybrid keyword+vector search. Held below 65 because semantic search remains an LES paid add-on rather than base-DXP functionality.

10.3.2
AI-powered personalization
50M

Content and product recommendations driven by role, history, and behavior are GA, AI Insights adds ML-based layout optimization suggestions, and AI Hub (now GA) offers predictive audience segmentation as a shipping agent template. But that segmentation is template-based agent tooling you assemble rather than a native ML personalization engine, segment execution remains largely rule-driven, and no cold-start handling or personalization performance analytics is documented, keeping this in the AI-assisted band.

AI Platform & Extensibility
10.4.1
MCP server availability
48H

Liferay DXP ships an official MCP server (2026.Q1+) with live docs for GitHub Copilot, Cursor, and Claude, and it supports real read/write/publish operations — agents can create/update Object entries, advance workflows, and update content and commerce data with permission scoping. It still requires the beta feature flag LPD-63311 (confirmed current in 2026), and AI Hub additionally consumes MCP servers for agent data access; the persistent beta status keeps this at the top of the announced/beta band rather than the GA band.

10.4.2
Bring your own AI model/key (BYOM/BYOK)
72H

Liferay's AI stack is BYOM-first with no bundled proprietary model: AI Creator uses a user-supplied OpenAI key, and AI Hub's GA confirms an open, model-agnostic architecture connecting Anthropic, Google, and OpenAI models with the ability to swap or add models without rebuilding agents. AI Tasks adds Ollama and Hugging Face local-model support. No explicit data residency controls for the AI inference pipeline documented, holding the score below 75.

10.4.3
AI developer extensibility & agent APIs
62M

Developer AI tooling strengthened with AI Hub GA: a visual Agent Builder assembling agent logic from prebuilt nodes (LLM calls, data lookups, API integrations, custom scripting), an official MCP server (beta) with read/write/publish, AI Tasks providing LangChain4J orchestration, and comprehensive headless REST APIs. Held below the 70 dedicated-AI-SDK band because there is still no first-party AI SDK, LlamaIndex integration, or RAG-optimized delivery endpoint documented.

10.4.4
AI governance, safety & audit trails
60M

AI Hub's GA (Aug 2026) materially strengthens governance: every AI interaction is logged in a full audit trail, agents inherit DXP permissions and operate on behalf of authenticated users (permission-scoped data access), and Liferay now layers in explicit EU AI Act compliance controls on top of ISO/IEC 42001 AIMS certification, GDPR data locality, HIPAA-aligned controls, and SOC 2 audit readiness. Capped below 75 because brand voice enforcement, hallucination detection, and human-in-the-loop review gates are not yet shipped (review checkpoints remain slated for later releases).

10.4.5
AI observability & usage analytics
44M

AI Hub, now GA, provides a centralized home dashboard to build, manage, and monitor agents and chatbots, tracking agent usage and performance over time — Liferay's first real AI observability layer. Held in the basic band because monitoring is agent-operations-focused rather than per-user AI consumption or prompt effectiveness, cost/quota transparency is thin (list pricing withheld), and BYOK token cost tracking still lives in the model provider's console.

Score History

How composite scores (0–100) have changed over time. Click legend items to show/hide metrics.

+13.4 capability
analyst note

Recent Updates

September 202634 score changes

Liferay's momentum is modestly positive, with gains concentrated in Platform Velocity, which climbed +2.6 on the back of a newly published Now/Next/Later public roadmap and the general availability of AI Hub, whose centralized agent dashboard sharply lifted AI observability and governance scoring. Compliance & Trust also ticked up to 75.4, reinforced by AI Hub's full audit-trail logging, while Build Simplicity improved slightly; Cost Efficiency was the lone dimension to slip, edging down to 45.2. Practitioners should note the mixed picture around AI maturity: even as observability and governance strengthened, agentic workflow automation and audience segmentation both regressed as Liferay retired local segment authoring and repositioned agentic capabilities under the still-maturing AI Hub.

Score Changes

AI observability & usage analytics2240(+18)

AI Hub, now GA, provides a centralized home dashboard to build, manage, and monitor agents and chatbots, tracking agent usage and performance over time — Liferay's first real AI observability layer. Held in the basic band because monitoring is agent-operations-focused rather than per-user AI consumption or prompt effectiveness, cost/quota transparency is thin (list pricing withheld), and BYOK token cost tracking still lives in the model provider's console.

Roadmap transparency4258(+16)

Liferay publishes a public roadmap at liferay.com/roadmap organized in Now/Next/Later buckets (AI Hub, Content Marketing Platform, Liferay Data Platform) and runs a Feature Requests portal on Liferay Ask with community voting and product-team responses linking Jira tickets. The roadmap communicates high-level vision without committed timelines and voting is not integrated into the roadmap page itself, keeping it below the 70+ tier.

Agentic workflow automation6250(-12)

Liferay AI Hub reached general availability on Aug 19, 2026 (public beta since June) — a named, standalone agentic product with a visual Agent Builder (prebuilt nodes for LLM calls, data lookups, API integrations, and custom scripting), multi-agent orchestration chaining specialized agents end-to-end, prebuilt agent templates, MCP-based data access, and audit-trailed, permission-scoped execution. Lands in the solid-GA band rather than 80+ because human review checkpoints and event-driven triggers are still 'coming in later releases,' so approval gates within agentic runs are not yet shipped and the GA is early with maturing docs.

AI governance, safety & audit trails4252(+10)

AI Hub's GA (Aug 2026) materially strengthens governance: every AI interaction is logged in a full audit trail, agents inherit DXP permissions and operate on behalf of authenticated users (permission-scoped data access), and Liferay now layers in explicit EU AI Act compliance controls on top of ISO/IEC 42001 AIMS certification, GDPR data locality, HIPAA-aligned controls, and SOC 2 audit readiness. Capped below 75 because brand voice enforcement, hallucination detection, and human-in-the-loop review gates are not yet shipped (review checkpoints remain slated for later releases).

Audience segmentation6255(-7)

Liferay deprecated local segment authoring in 2026.Q1 (read-only on new installs), but 2026.Q3 brought Liferay Data Platform (LDP, the evolution of Analytics Cloud) to GA, which now provides dynamic, real-time segment building that activates across DXP and third-party tools. Segmentation is more capable than before but centralized in the separately-licensed LDP; native in-DXP authoring is being removed, so there is no free-standing segmentation engine inside the DXP itself.

Compliance certifications7076(+6)

Liferay's Trust Center confirms SOC 2 Type 2 alongside ISO/IEC 27001:2022, ISO/IEC 27017:2015, ISO/IEC 27018:2019, and CSA STAR Level 1 and 2. GDPR tooling (data erasure/export), EU cloud regions, and HIPAA-eligible Cloud deployments are available. Not higher because self-hosted compliance depends on customer infrastructure and certification breadth still trails Adobe.

Community engagement4752(+5)

discuss.liferay.com shows consistent official engagement — Liferay staff post each Free Tier/quarterly release and respond to threads — and the Feature Requests portal receives product-team responses with Jira links. Core development remains overwhelmingly internal with rare external contributions, which caps the score.

Competitive positioning5055(+5)

Liferay holds its 15th consecutive Gartner MQ for DXPs placement with improved execution and substantially improved vision scores (analysts note it sits 'just shy' of Leaders), ranks highest in the Authenticated Experience use case in Gartner Critical Capabilities, and is an IDC MarketScape Leader for AI-enabled full-stack CMS. The AI Hub GA sharpens its 'unbundled, AI-at-the-center' differentiation. Still a Niche Player overall with an on-premise-heavy install base signaling SaaS-transition challenges.

Native DAM capabilities6258(-4)

Documents and Media and Asset Libraries — Liferay's established DAM stack with metadata sets, version history with checkout/check-in, file expiration/review dates, and granular permissions — entered maintenance mode in 2026.Q1 in favor of the new Liferay CMS, whose Spaces-based asset management (file types, custom fields, recycle bin, workflows) is still maturing and does not yet demonstrate full parity. Legacy DAM remains functional but frozen; key gaps of no usage tracking and no watermarking/DRM persist across both systems.

TypeScript support3842(+4)

Client Extensions support TypeScript via modern Webpack toolchains, and Liferay documents generating typescript-fetch clients from its OpenAPI specs via openapi-generator — a workable but DIY typed-client path. There is still no officially published typed SDK, no auto type generation from content schemas or Objects, and TypeScript is not integrated into the headless API workflow out of the box.

Customer momentum4852(+4)

Momentum strengthened through mid-2026: Liferay AI Hub reached GA (2026-08-19) as a new standalone SaaS product, the company published fresh market research ('54% of companies running AI agents'), earned 2026 Gartner Customers' Choice recognition, and won Camunda's 2026 Technology Partner of the Year. Headcount is roughly stable (~1,145 as of March 2026). Visible net-new enterprise logo announcements remain modest, keeping this mid-range.

Free / Hobby Tier7470(-4)

The unified Free Tier gives everyone the same core DXP installation as enterprise: content management, sites, headless APIs, workflow, all supported databases, and clustering on up to three nodes. However, activation keys are valid only 12 months and must be renewed, keys are domain-registered, patch eligibility ends at each quarter's stable release, and MFA/SAML are excluded. A capable free tier, but the renewal requirement, key gating, and Java infrastructure footprint keep it below lightweight open-source alternatives.

Additional certifications7074(+4)

Portfolio now adds ISO/IEC 42001 (AI Management System, certified Dec 2025 — among the first companies globally), a meaningful current attestation, on top of CSA STAR Level 1 (CAIQ) and Level 2, CSA Trusted Cloud Provider, Spain ENS, and ISO 27017. ATO FastTrack signals FIPS 140-3 readiness in progress for 2026. Still no PCI DSS, FedRAMP authorization, or Cyber Essentials Plus, which caps the score below 78.

Content personalization6057(-3)

Liferay supports content personalization through Experience variants on Content Pages, allowing different segments to see different fragments and content, with fallback to default experience and per-segment preview. With local segment authoring deprecated in 2026.Q1, personalization now depends on Analytics Cloud / Liferay Data Platform–managed segments, adding licensing and setup dependency. Remains page-level rather than component-level targeting.

Changelog quality5558(+3)

learn.liferay.com maintains structured per-quarter release notes plus a '2026 Deprecations and Breaking Changes' reference with per-release sub-pages, and each quarterly release now ships with a documented webinar and service-life/EOL policy. Still short of 75+ because code examples are sparse and migration guidance for complex scenarios remains incomplete.

Third-party content3538(+3)

Third-party coverage ticked up around the 2026 release model and AI Hub launch — XTIVIA published multiple AI Hub analyses ('A First Look', 'Pros, Cons, and Who Should Care'), and Nirvana Lab and others cover the 2026 AI roadmap. Still no significant new Udemy/Pluralsight courses or sustained YouTube series, and much existing content references legacy 7.x versions.

Framework familiarity3841(+3)

Client Extensions are now the go-to approach for extending Liferay — they run outside the portal container against headless APIs in any language (React, Node.js, Vue, Angular, Spring Boot), across frontend, microservice, configuration, and batch categories, and the 2026.Q1 headless CMS is API-first for any frontend. However, core platform customization still requires Java/Jakarta EE, FreeMarker remains the fragment templating language, and React components must often be wrapped as Web Components. Held here because mainstream-stack development is the default path but the proprietary core persists.

Data modeling constraints4548(+3)

The 2026.Q1 headless CMS standardizes content modeling on Liferay Objects — structured, reusable data with auto-generated headless and batch APIs, stable alphanumeric class names (since 2025.Q1), and data model export/import for cross-environment portability. Legacy Web Content Structure risks matter less for new builds since Web Content is in maintenance mode. Automated migration tooling for breaking Object schema changes remains limited, and migrating existing Web Content into the new CMS is still an open effort.

Cross-functional complexity4952(+3)

The headless CMS is explicitly designed to let marketers manage global content without heavy IT reliance, and 2026.Q2 ships concrete editor self-service gains: AI-powered translation for multi-language content, and single-step replacement of text, URLs, or terms across the entire platform, atop Spaces for team-organized repositories and in-context analytics. Page Builder with installable Marketplace fragments remains accessible to non-technical users. New content types (Objects) and custom layouts still require developer involvement and authors need moderate training, so it stays mid-range — but the shipped Q2 tooling measurably reduces post-go-live friction.

Personalization and targeting7370(-3)

Liferay retains a mature personalization engine: audience segmentation by behavior, demographics, location, and custom attributes; content page personalization via Experiences; AI-driven personalized dashboards; and real-time segment evaluation. However, as of 2026.Q1 local segment authoring inside DXP is deprecated — new installations are read-only by default and segmentation work must move to Liferay Analytics Cloud. While Analytics Cloud is first-party, this adds a SaaS product dependency for self-hosted customers and transition friction during the deprecation window, slightly weakening the previously fully self-contained personalization story.

AI text generation & editing5255(+3)

AI Creator remains GA in the Web Content and DAM editors (ChatGPT via a user-supplied OpenAI key, with tone and word-count controls), and with AI Hub reaching GA (Aug 19, 2026) the built-in AI writing tasks in Liferay CMS — change tone, fix grammar, summarize text — are now shipping rather than beta, alongside a Content Site Generator for AI-assisted multi-page site creation. Still no documented brand voice guardrails or custom prompt template governance, holding the score in the basic-generation band despite the GA milestone.

Content type flexibility7072(+2)

The Objects-based Headless CMS (2026.Q1 LTS) is the primary content modeling path, with legacy Web Content and Blogs in maintenance mode. Content structures support text, numeric, date, upload, related-content, and referenced (nested) structure fields, plus per-field mandatory flags, localization, and workflow assignment — and 2026.Q2 now lets admins add or reorder structure fields retroactively without deleting existing entries, removing a real prior pain point. Schema-as-code is still unavailable (structures are UI/REST-defined), keeping it below headless-native leaders.

Structured content support6264(+2)

The 2026.Q1 Headless CMS stores content as structured, reusable data via Objects, and content structures can embed referenced structures — providing genuine component embedding within entries. Page Fragments provide UI-level composition. Rich text output remains HTML with no Portable Text equivalent and no unlimited block nesting, which keeps it in the adequate band rather than best-in-class.

Rich text capabilities5860(+2)

CKEditor 5 shipped as a release feature in 2026.Q1 (flag LPD-11235) and is the default editor in 2026.Q2+ — with LPD-11235 reversed to re-enable the deprecated CKEditor 4 — standardizing the editing experience platform-wide, including editable rich-text Fragment fields. Output remains HTML rather than a portable AST, and CKEditor 4 custom plugins require rewriting, which keeps this in the standard-WYSIWYG band.

API design quality6365(+2)

Liferay DXP's 2026.Q1 LTS introduced a new API-first headless CMS replacing legacy content tools, alongside OpenAPI-compliant REST and GraphQL APIs with an in-admin API Explorer; the 2026.Q2 release (May 2026) continued on this baseline. 2025.Q3+ added siteKey/externalReferenceCode support to GraphQL endpoints and 2026.Q1+ moved LAR export/import onto the batch framework. Still carries Java verbosity, nested payloads, and multiple coexisting API generations — not higher until the new CMS APIs fully supersede legacy patterns.

Security track record6563(-2)

Liferay runs a public bug bounty on Intigriti with a formal responsible disclosure process, CVE assignment, and a maintained Known Vulnerabilities page. However, 2025–2026 brought a steady stream of XSS CVEs (CVE-2025-43776/43777/43778/43746/43757, plus stored XSS in the Workflow Process Builder CVE-2025-62239 and reflected XSS CVE-2025-62248, itself a regression of a previously fixed flaw) alongside an authorization flaw (CVE-2025-62247). Strong disclosure posture offset by high CVE volume and a regression — a process-quality concern that keeps it mid-range.

Disaster recovery6062(+2)

Liferay Cloud provides automated backups and point-in-time recovery; self-hosted deployments need custom strategies for database, document library, and Elasticsearch indices. Content export improved in 2026.Q1+ as LAR export/import now uses the batch framework at site and instance scopes, making large exports more reliable. Still no publicly documented RTO/RPO targets, and LAR remains a proprietary format.

Feature gating5250(-2)

The 2026.Q1 release unified CE and DXP into one modular platform gated by activation keys, and the Free Tier now includes clustering on up to three nodes — a genuine improvement. However, security-critical features including multi-factor authentication, SAML SSO, and advanced search tuning still require an Enterprise Subscription key, which is exactly the problematic gating pattern (SSO/security behind enterprise). Free Tier patch access also stops at each quarter's stable release.

Required specialization3739(+2)

With Client Extensions running outside the container against headless APIs and the 2026.Q1 CMS exposing standard APIs, generalist React/Node developers can handle a growing share of project work without OSGi or deep Java expertise. However, Java/Jakarta EE skills remain mandatory for core customization and upgrades, FreeMarker for fragments, and Liferay's active certification ecosystem reflects how proprietary the full skill set still is. Held here because the accessible-extension surface keeps expanding but the specialist core persists.

Monitoring requirements4446(+2)

Cloud Native Experience ships Unified Observability — product-aware metrics and Grafana dashboards for system health and resource consumption — plus HPA and self-healing Kubernetes, and the Liferay Cloud Console provides environment monitoring, logs, and automated backups for PaaS. Self-hosted deployments outside CNE still need custom JVM, database, and Elasticsearch monitoring. Not higher because adoption requires the CNE/PaaS stack and bare self-hosted installs get nothing built in; not lower because product-aware dashboards are now a packaged offering.

Regional & industry regulations6567(+2)

GDPR built-in with DPA and erasure tooling; CCPA via DPA; LGPD coverage implied by default DPA application to Latin America plus São Paulo hosting; Spain's Esquema Nacional de Seguridad (ENS) listed on the Trust Center. The new ATO FastTrack initiative (launched Sept 4, 2026) adds a documented US-government readiness path — an authorization-ready low-code platform with Zero Trust controls, plus FIPS 140-3 readiness and OSCAL-based documentation coming by end of 2026. Not higher because ATO FastTrack is a path to agency ATO, not a FedRAMP authorization Liferay itself holds, and no IRAP/C5/HITRUST exists.

Onboarding resources5657(+1)

Liferay Learn offers a structured, role-based curriculum updated through 2026.Q1, including dedicated courses on Objects data modeling, backend and frontend Client Extensions, Workspaces & Tooling, and Jakarta upgrades, with free access for customers, partners, and community plus an active certification catalog. Still no rapid 'build something in 30 minutes' quickstart, and onboarding assumes enterprise developer context, so it stays mid-range.

Authoring UI accessibility7273(+1)

Liferay publishes a current 'DXP Admin Experience Accessibility Conformance Report' (VPAT 2.5Rev, dated Nov 29 2025 for the 2025.Q4 release) — formal conformance documentation specifically for the authoring/admin interface, now covering WCAG 2.x, Revised Section 508, and EN 301 549. Conformance evaluated with automated static analysis plus manual testing using screen readers, magnifiers, and speech recognition. Exceeds the 70 threshold given current, authoring-specific, multi-standard formal documentation.

Accessibility documentation7273(+1)

Current VPAT-based ACRs are publicly downloadable for procurement: December 2025 Admin Experience and Sites Experience reports (VPAT 2.5Rev), covering WCAG 2.x, Section 508, and EN 301 549. A dedicated accessibility compliance page is maintained. Meets 70+ for current, public, multi-standard VPAT/ACR availability; not higher because ATAG 2.0 assessment is still not documented.

June 20267 score changes

Liferay's momentum this cycle is narrowly positive, with all movement concentrated in Compliance & Trust (+2.1) while Capability, Platform Velocity, Cost Efficiency, Build Simplicity, and Operational Ease held flat. The lift is driven by clearer documentation of Liferay's regulatory posture — HIPAA alignment alongside ISO 27001/27017/27018, SOC 2 Type 2, and CSA STAR Level 2, plus broader regional DPA coverage across EEA, UK, Latin America, and Mexico. For practitioners, the standout signals are the explicit 14-day post-termination data retrieval window and the strengthened healthcare/regional regulatory story, both of which materially de-risk Liferay for regulated and multi-jurisdiction deployments.

Score Changes

HIPAA & healthcare compliance6268(+6)

Liferay's Trust Center lists HIPAA alongside ISO 27001/27017/27018, SOC 2 Type 2, and CSA STAR Level 2, and the healthcare industry page now explicitly documents Business Associate Agreement capability under HIPAA with SaaS, PaaS, or self-hosted deployment options for PHI control. Healthcare use cases are well-documented in the customer base. Not 70+ because BAA terms and plan eligibility are not published as a self-service legal document — 'BAA capability' is softer than a standing BAA offer.

Regional & industry regulations6065(+5)

GDPR built-in with DPA and erasure tooling; CCPA via DPA; LGPD coverage implied by default DPA application to Latin America plus São Paulo hosting region. Spain's Esquema Nacional de Seguridad (ENS) is newly listed on the Trust Center — a meaningful regional framework addition. Still no FedRAMP authorization, IRAP, C5, or HITRUST despite government and healthcare customers. Score reflects GDPR + CCPA + LGPD + ENS breadth without FedRAMP.

Additional certifications6570(+5)

CSA STAR Level 1 (CAIQ) and Level 2 (SOC 2-based attestation) confirmed in the CSA registry, with a separate Liferay PaaS listing added July 2024; CSA Trusted Cloud Provider designation. Spain ENS is newly documented on the Trust Center, and ISO 27017 plus HIPAA round out the portfolio. Still no PCI DSS, FedRAMP, or Cyber Essentials Plus, which caps the score at 70.

Data lifecycle & deletion7276(+4)

Post-termination retention is now explicitly documented: customers have 14 days to retrieve data after subscription end, with permanent deletion 30 days after termination; Analytics Cloud retention defaults to 13 months and is configurable. Built-in Personal Data Erasure dashboard provides self-service right-to-erasure with APIs for third-party integration, plus data portability export. Meets the 75+ threshold for self-service export + documented retention + API-based erasure.

GDPR & EU data protection7880(+2)

DPA applies by default to cloud customers in EEA, UK, Latin America, and Mexico, with SCCs implemented for cross-border transfers; other customers can request it. Liferay now publishes a detailed sub-processor table (entities, locations, functions, transfer mechanisms) with 10 days' notice before new appointments, closing the prior transparency gap. EU residency via Frankfurt, London, and Hamina (Finland) regions, plus built-in Personal Data Erasure dashboard. Meets the 80 threshold for DPA + EU residency + SCCs + public sub-processor list.

Authoring UI accessibility7072(+2)

Liferay publishes a dedicated 'DXP Admin Experience Accessibility Conformance Report 2025' based on VPAT 2.5 — formal conformance documentation specifically covering the authoring/admin interface, alongside a Sites Experience ACR. Conformance evaluated with automated static analysis plus manual testing using screen readers, magnifiers, and speech recognition. Exceeds the 70 threshold given current, authoring-specific formal documentation.

Accessibility documentation7072(+2)

Current VPAT-based ACRs are publicly downloadable for procurement: the August 2024 report (VPAT 2.5) plus separate 2025 Admin Experience and Sites Experience conformance reports and a 7.4 2024-Q3 report. Dedicated accessibility compliance page maintained with Section 508 coverage via the VPAT framework. Meets 70+ for current, public VPAT/ACR availability; not higher because ATAG 2.0 assessment is not documented.

March 20269 score changes

Liferay is stable overall with a modest uptick in Compliance & Trust (+3.8), the only composite dimension showing movement this cycle. The gain is driven by improved accessibility documentation—including a publicly available, current VPAT/ACR—and stronger evidence for HIPAA and ISO 27001 certification scope, reflecting Liferay's continued investment in procurement-ready compliance artifacts. Practitioners in regulated industries should note the strengthened compliance posture, though Capability, Platform Velocity, Cost Efficiency, Build Simplicity, and Operational Ease remain unchanged, signaling no broader momentum shift in the platform's competitive position.

Score Changes

Accessibility documentation5570(+15)

Liferay publishes a current VPAT/ACR publicly available for procurement evaluation, with versions from 2023Q2 and 2024 downloadable from their website. Dedicated accessibility compliance page at liferay.com/accessibility-compliance/digital-experience-platform. Section 508 conformance addressed. Documentation updated on Liferay Learn portal (July 2025). Meets 70+ threshold for current VPAT/ACR available for procurement.

HIPAA & healthcare compliance5562(+7)

Liferay's compliance documentation lists HIPAA alongside SOC 2 and ISO 27001 as part of their infrastructure compliance program. Healthcare portal use cases are well-documented in their customer base. However, a formal publicly-accessible BAA document is not prominently published, and healthcare-specific configuration guidance is limited. Not 70+ because BAA availability is not explicitly documented for self-service.

ISO 27001 / ISO 270187580(+5)

Liferay holds ISO/IEC 27001:2022 certification with platform scope covering development, operations, maintenance, and delivery of DXP and Cloud Services Platform. Also certified ISO/IEC 27017:2015 and ISO/IEC 27018:2019 for cloud PII processing. Certified by A-LIGN. Scope covers 254 individuals. Meets the 80+ threshold for ISO 27001 platform scope plus ISO 27018.

Authoring UI accessibility6570(+5)

Liferay publishes an Accessibility Conformance Report (ACR) based on VPAT 2.4, with the most recent version dated August 2024 and updated July 2025. Conformance evaluated using automated static analysis tools and manual testing with assistive technologies (screen readers, screen magnifiers, speech recognition). This constitutes formally documented WCAG 2.1 AA conformance for the authoring UI, meeting the 70+ threshold.

Data lifecycle & deletion6872(+4)

Built-in Personal Data Erasure dashboard provides self-service right-to-erasure for personal data. Data portability export for user data. Content lifecycle management with versioning and expiration workflows. DPA documents retention terms. Better than most competitors due to purpose-built GDPR tooling. Not 75+ because automated bulk export tooling and post-termination retention specifics are not prominently documented.

Additional certifications6265(+3)

CSA STAR Level 2 third-party attestation (active, updated Aug 2025) is a meaningful additional certification beyond SOC 2 and ISO 27001. CSA Trusted Cloud Provider designation. HIPAA compliance listed in portfolio. ISO 27017 adds cloud-specific security controls. No PCI DSS, FedRAMP, Cyber Essentials Plus, or ENS documented. Solid but not the broadest additional cert portfolio.

Audit logging & compliance reporting7275(+3)

Comprehensive audit framework enabled by default. Captures user login/logout, password changes, entitlement changes, group membership, content operations. Output in CSV or JSON format. SIEM integration via Splunk, ELK stack, Syslog audit message processor, and CloudAMQP. Configurable audit event types. Enterprise portal heritage means audit was designed for compliance from early versions. Meets 75+ for comprehensive logs with native SIEM integration.

Regional & industry regulations5860(+2)

GDPR compliance built-in with DPA and erasure tooling. CCPA covered via DPA amendments. CSA STAR Level 2 third-party audit adds credibility. No formal FedRAMP authorization despite US government customer base. No IRAP, C5, or HITRUST certifications documented. Score reflects GDPR + CCPA coverage with CSA STAR but without FedRAMP or broad regional framework coverage.

Data residency & sovereignty7880(+2)

Liferay Cloud offers multiple global hosting regions: US (Oregon), EU (Frankfurt), UK (London), Brazil (São Paulo), India (Mumbai), Australia (Sydney), and Dubai. Each environment can be placed in a different region for granular data sovereignty. On-premise Liferay DXP provides complete data residency control. Cross-region disaster recovery available. Meets 78+ threshold with multiple regions and contractual guarantees.

July 2025

Liferay continued its steady modernization trajectory with improved cloud-native deployment options and expanded AI features. The platform's traditional strengths in enterprise portals and intranets remained solid, but the growing gap in developer experience and build simplicity compared to modern headless platforms weighed on market perception. Cost structure improvements from the SaaS model began to show modest gains.

Platform News

  • Liferay DXP 2025.Q2 Release

    Featured expanded AI capabilities for content workflows, improved Objects permission model, and enhanced multi-site management for enterprise portals.

  • Liferay Experience Cloud Global Expansion

    Additional cloud regions and data residency options expanded to meet growing regulatory requirements across APAC and LATAM markets.

November 2024

The composable DXP market continued to evolve rapidly with AI-native platforms gaining traction. Liferay maintained its enterprise DXP positioning with incremental improvements to Cloud and Objects, but platform velocity declined further as innovation velocity in the broader ecosystem outpaced Liferay's release cadence. The platform's strongest differentiation remained in complex intranet and multi-brand portal scenarios.

Platform News

  • Liferay DXP 2024.Q3 Release

    Continued iteration on Client Extensions, expanded commerce integration points, and improved content authoring workflows.

  • AI Content Generation Preview

    Preview release of AI-assisted content generation features, leveraging LLM integrations for draft creation and translation assistance.

March 2024

Liferay launched 2024.Q1 under the new versioning scheme with expanded Objects capabilities and improved headless content delivery. Regulatory readiness strengthened with ISO 27001 certification for Liferay Cloud and expanded GDPR tooling. Platform velocity remained steady but failed to close the gap with modern composable DXP alternatives.

Platform News

  • Liferay DXP 2024.Q1 Release

    First release under the new annual-quarterly naming convention, featuring expanded Objects actions, improved page builder, and enhanced analytics integration.

  • ISO 27001 Certification for Liferay Cloud

    Liferay Cloud achieved ISO 27001 certification, strengthening the platform's enterprise compliance posture alongside existing SOC 2 Type II.

  • Expanded GraphQL API Coverage

    Broader GraphQL API support for custom Objects and structured content, improving headless delivery capabilities.

July 2023

Liferay shifted to a quarterly release cadence, improving predictability for enterprise customers. The Liferay Experience Cloud SaaS offering matured with improved onboarding, and the platform saw incremental gains in technical architecture through better microservice support. However, the cost structure remained a challenge for mid-market adoption.

Platform News

  • Quarterly Release Cadence

    Liferay adopted a quarterly versioning scheme (2023.Q1, Q2, etc.), moving away from major version numbers to deliver features more incrementally.

  • Liferay Experience Cloud SaaS Improvements

    Enhanced self-service provisioning and improved Cloud Console for the managed SaaS offering, reducing time-to-value for new deployments.

  • AI-Assisted Content Recommendations

    Early AI features introduced for content recommendations and search relevance tuning within the platform.

November 2022

The headless CMS market heated up significantly with Contentful, Sanity, and others capturing developer mindshare. Liferay's velocity began to slow relative to the broader market despite continued incremental improvements. The platform's strengths in portal, intranet, and complex enterprise workflows remained unmatched by lighter-weight competitors.

Platform News

  • Liferay Experience Cloud Launch

    Liferay rebranded its SaaS offering as Liferay Experience Cloud, signaling a push toward managed cloud delivery to reduce operational burden for customers.

  • Gartner DXP Magic Quadrant 2022

    Liferay maintained its position as a Challenger in the Gartner Magic Quadrant for DXPs, recognized for portal strengths but noted for limited marketing automation capabilities.

March 2022

Post-7.4 adoption phase with Objects gaining traction in the enterprise install base. Liferay maintained solid momentum with regular update releases and growing headless API coverage, though the Java ecosystem was increasingly seen as heavyweight compared to emerging Node.js-based headless CMS competitors.

Platform News

  • Liferay DXP 7.4 Update Series

    Regular quarterly updates expanding Objects capabilities, adding workflow integration and custom actions to the low-code framework.

  • Client Extensions GA

    Client Extensions reached general availability, enabling React/Angular front-ends to be deployed independently from the Liferay core, improving developer experience for JavaScript teams.

June 2021

Liferay 7.4 just launched with the transformative Objects framework, bringing low-code capabilities to the Java-based DXP for the first time. Platform velocity was at a multi-year high as the community rallied around Objects and improved headless APIs, though the underlying Java/OSGi complexity continued to weigh on build simplicity and operational ease.

Platform News

  • Liferay DXP 7.4 GA Release

    Major release introducing Objects (low-code data modeling), improved headless REST/GraphQL APIs, and Client Extensions for decoupled front-end development.

  • Objects Framework Launch

    Low-code framework allowing business users to create custom data models without Java development, a strategic pivot toward citizen developer adoption.

  • Liferay Cloud Kubernetes Migration

    Liferay Cloud transitioned to Kubernetes-based infrastructure, improving scalability and deployment flexibility for managed customers.

Independent
We don't implement these platforms. Our trusted partner community does. Do you need help getting started?

Looking for a Liferay partner?

Agencies, dev shops, and systems integrators vary wildly in how well they deliver on Liferay. We don't take on implementation work ourselves.

Tell us what you're building and we'll come back with a shortlist of firms with a genuine track record on this platform.

How does Liferay stack up against your shortlist?
Side-by-side scoring across all 10 categories and every criterion.
Compare Platforms →