RichFaces Migration Service

Remove RichFaces from your business-critical Java applications

RichFaces has been end-of-life since 2016, leaving it without patches, blocking your upgrades, and creating a growing security liability. We move your application onto a modern, supported, maintainable stack, without a risky rewrite.

Still Running RichFaces?

RichFaces has been unmaintained since 2016. If it is still in your application, it is blocking your upgrades and quietly accumulating security risk. Virtua specializes in removing it; migrating the UI to PrimeFaces or a modern JavaScript framework, modernizing the app server and frameworks underneath, improving your security posture and preparing your application for the future. This is a repeated, documented specialty for our team.

  • Completed migrations on large, complex enterprise systems
  • Led by JSF / Jakarta Faces and Jakarta EE experts with 20+ years of experience
  • Machine-assisted, human-orchestrated. Every change senior-reviewed.

Same problem, three ways in

Whoever is driving the conversation, RichFaces is the blocker. Here is how it shows up for each of them.

Security & compliance

Unsupported components are failing your scans

If your security team has flagged RichFaces or its dependencies, or an audit surfaced the CISA-listed CVE, the clock is already running. We close the exposure by removing the dead framework and upgrading its aging dependencies; not just patching around it.

Engineering leads

One framework is blocking every upgrade

RichFaces is the reason you cannot move to a current Java version, application server, Spring, or Jakarta EE baseline. Remove it and the rest of your modernization — and your delivery velocity — is unblocked.

Technology leadership

Clients and revenue are on the line

Customers increasingly require modern, secure, supported software. Sitting on an end-of-life UI framework is a reputation and revenue risk. We give you a defensible, sequenced path off it.

What the RichFaces Migration Service is

Virtua removes RichFaces from business-critical Java web applications and migrates them to a modern, maintainable, supportable architecture; improving maintainability, upgradability, security posture, and delivery velocity along the way.

Who it's for

Organizations running business-critical Java web apps that still depend on RichFaces, where that dependency is blocking upgrades and creating security exposure.

What it produces

A modernized application with RichFaces removed and your target architecture in place; more maintainable, more secure, and ready for the upgrades you have been putting off.

Why Virtua

20+ years of Java leadership, recognized JSF / Jakarta Faces, PrimeFaces and Jakarta EE, and modern JS framework expertise, and a track record of completed RichFaces migrations on large, complex systems.

Choose your destinations

Removing RichFaces is a UI migration, so every engagement includes a UI destination (Path A: PrimeFaces or Path B: modern JavaScript). The backend, app server, and infrastructure tracks support the UI migration and provide additional benefits for security, performance, and maintainability.

Path Destination Track Dependency What it covers
A RichFaces → PrimeFaces UI destination Always in scope

Keep the JSF programming model. Often the safest, most cost-effective path when the app is fundamentally sound and business logic is tightly coupled to JSF.

B RichFaces → modern JavaScript UI destination Always in scope

Move to a modern JS framework such as React, Angular, Vue, or Web Components (or Vaadin to stay in Java). Best when you want a modern frontend platform and have, or want, modern JS skills in-house.

C App server & framework upgrades Backend & app server A or B

Bring Java, Jakarta EE, the application server, and frameworks up to current, supported versions — including javax-to-jakarta namespace migration, Spring Framework or Spring Boot, CDI / JPA / Hibernate.

D Java EE → Spring Boot Backend & app server A or B

Move the backend toward Spring Boot where it is the right call; extracting services from EJBs and backing beans and introducing REST or GraphQL APIs. Chosen selectively.

E Cloud-ready modernization Infrastructure UI + backend track

Containerization, configuration and secrets, observability, CI/CD, identity and networking; when removal is part of modernizing how the application is deployed and operated.

F Hybrid (mixed destination) The mixed case Combines A and B

For large systems: high-value screens on PrimeFaces, selected modules rebuilt in modern JS, coexisting on a modernized app server; often phased alongside C, D, and E.

Improve the experience, not just the code

A RichFaces migration is already touching your screens, which makes it the most cost-effective moment to improve them, too. When it fits the engagement, we work with senior designers to fold in a UI refresh and theming alongside better user flows, usability, and information architecture.

How we work

Machine-assisted, human-orchestrated

RichFaces modernization mixes repeatable mechanical changes with high-level architectural decisions and expert judgment. We automate the repetitive work, write the complex parts by hand, and put senior engineers in control of all of it. Faster than purely manual migration and far more reliable than unsupervised AI.

Automated where it's safe

OpenRewrite recipes are used for dependency and configuration updates as well as code transformations. They use a Lossless Semantic Tree (LST), which makes the transformations deterministic, composable, and auditable, rather than a black box. AI coding agents handle simple bug fixes and less common changes.

Playbooks for the judgment calls

Project-specific repeatable tasks that need more judgment are captured into playbooks that engineers or AI can apply consistently.

Hand-written where it isn't

Architectural decisions, complex screens, and edge cases are handled by senior engineers; anywhere automation would be unsafe or imprecise.

Orchestrated by senior engineers

Every change, automated or hand-written, is reviewed by experienced engineers. Architecture, behavior, testing, and production-readiness stay under human control.

Can't I just do this with AI?

Modernizing complex applications requires more than just a coding agent, which is why there are several tools to help with the process, such as IBM Application Modernization Accelerator, Github Copilot App Modernization, and Amazon Q Developer:Transform. These tools use OpenRewrite recipes combined with agentic coding, which is the same process we use. They do not, however, ship our proprietary RichFaces and PrimeFaces recipes. Complex pages and edge cases still need senior human expertise and, most importantly, a tool does not own the outcome. It produces changes and attempts fixes, but it will not decide scope, judge whether a fix is correct, handle nuanced edge cases, or take responsibility for the migration being finished and shipped. We do.

What our clients say

Completed, measurable projects for real enterprise systems.

Tufin Technologies

Working with multiple teams and internal dependencies, we migrated two flagship applications from RichFaces to PrimeFaces, integrated with Angular modules, and performed a significant UI refresh. We also contributed to a broader modernization effort across both products involving upgrades for Jakarta EE, Spring, and Hibernate.

They led the migration of our user interface framework from RichFaces to PrimeFaces, first in SecureTrack and later in SecureChange. As part of the SecureChange effort, they also led a significant refresh of the user interface, aligning it with evolving design standards while preserving functionality and user experience.

In addition, Virtua contributed to a broader modernisation initiative across both SecureTrack and SecureChange involving upgrades to Jakarta EE, Spring, Hibernate, and related technologies. This was a large-scale effort carried out by multiple teams across several engineering groups at Tufin. Virtua contributed to the SecureChange portion of the initiative, working closely with internal teams and providing valuable expertise and implementation support throughout the project.

Kito Mann and Bauke Scholtz worked closely with our engineering teams and integrated smoothly into our development process. They demonstrated strong technical expertise, professionalism, and a high level of commitment to the project's success, and quickly became productive within a very complex codebase. Throughout the engagement, they consistently delivered high-quality solutions and maintained an impressive development pace.

We appreciated Virtua's collaborative approach, professionalism, and technical expertise, and would be very happy to work with them again.

— Asi Elqayam, R&D Group Manager, Tufin Technologies
Real Time Networks

We delivered development, code refactoring, UI/UX design, and architecture — optimizing the codebase for performance, scalability, and maintainability — and helped with build pipelines, artifact repository setup, and SBOM generation while tackling technical debt directly.

Working with Kito, Bauke, and the rest of the Virtua team has been a transformative experience for our organization. Their expertise in software development, UI/UX design, code refactoring, and software architecture not only met but far exceeded our expectations. From day one, they demonstrated unmatched professionalism, technical skill, and a commitment to delivering exceptional results.

The Virtua team seamlessly integrated into our development pipeline, quickly becoming an indispensable part of our team. They not only delivered excellent results but also helped us improve our processes significantly. Their deep expertise in building Java solutions, along with their precision in development and code refactoring, optimized our codebase for performance, scalability, and maintainability. Their thoughtful UI/UX design laid the foundation for a more intuitive and visually appealing user experience.

What sets Virtua apart is their versatility. Beyond software development, they helped us with build pipelines, artifact repository setup, SBOM generation, and served as a trusted sounding board for our technical leadership. They took on a broad range of challenges, providing valuable guidance and ensuring our architecture was robust and future-proof.

Their dedication to collaboration, adaptability, and tackling challenges like technical debt head-on was evident throughout the entire project. They communicated clearly and effectively at every stage, ensuring that quality was never compromised. Their attention to detail and customer-centric approach make them a trusted partner for any development needs.

Thanks to Virtua, our product is now more robust, user-friendly, and future-proof. We couldn’t be more thrilled with the outcome and wholeheartedly recommend their services to any organization seeking top-tier development and design expertise.

— Lee Purvis, CTO, Real Time Networks
Sightline Systems

We completed a full assessment and worked with their team to implement the assessment's recommendations. This included converting the project to Maven, replacing RichFaces with PrimeFaces, removing tech debt, improving performance and upgrading to a recent version of Jakarta EE and WildFly.

Working with the Virtua team has been an outstanding experience for our organization. Their expertise and guidance were instrumental in helping us modernize and significantly improve our application while navigating several major software upgrades. As Java Champions, their depth of knowledge and practical experience were evident in every phase of the project.

Beyond delivering high-quality development work, Virtua provided valuable recommendations on upgrade strategies, implementation approaches, and code adjustments that helped ensure a smooth transition with minimal disruption. They also played a key role in helping our team adopt a new GitHub repository structure and GitFlow methodology, improving both our collaboration and development processes.

What stood out most was their willingness to truly partner with our team. They mentored developers when needed, assisted with Sprint deliverables, and consistently provided thorough documentation for every process and solution they implemented. Their professionalism, technical expertise, and collaborative approach made them a seamless extension of our own team.

Thanks to Virtua’s contributions, our application is more modern, maintainable, and better positioned for future growth. I would absolutely work with them again and highly recommend them to any organization looking for a knowledgeable and dependable development partner.

— Curtis Smith, CTO, Sightline Systems

The people who wrote the framework will migrate your framework

Between them, our principals served on the JCP Expert Groups that defined JSF, contributed directly to the Jakarta Faces specification and the Mojarra reference implementation, wrote the books, maintain the ecosystem's standard utility library, and helped write the Eclipse Foundation's official Jakarta EE tutorial. If you need to migrate a business-critical JSF application, this is the team to do it.

Kito D. Mann

Kito D. Mann

Principal Consultant

Internationally recognized authority on JSF and Jakarta EE who has personally led RichFaces removals on large, mission-critical systems.

  • Oracle Java Champion, IBM Champion, and Google Developer Expert in Web Technologies (alumnus)
  • Served on the JCP Expert Groups that defined JSF since 1.2, plus CDI, MVC, and the Portlet specs
  • Led teams building web apps using JS frameworks as well as teams building Java backends, for on-prem and cloud deployments
  • Author of JavaServer Faces in Action, one of the first books on JSF
  • International speaker on Java, Jakarta EE and related topics (Devoxx, JavaOne, Devnexus, JAX, and many more)
  • Led the Eclipse Foundation's Jakarta EE Tutorial refactor to the Antora pipeline and wrote its intro chapter
  • Launched the first online community for JSF (JSFCentral) and conferences covering JSF (JSF One/JSF Summit).
Bauke Scholtz

Bauke Scholtz

Principal Engineer

Known across the Jakarta EE community as BalusC; he helped build the frameworks you are migrating to and from.

  • Oracle Java Champion and Duke's Choice Award recipient (2015, for OmniFaces)
  • Direct contributor to the Jakarta Faces specification and the Mojarra reference implementation — the foundation beneath both RichFaces and PrimeFaces
  • Co-creator and maintainer of OmniFaces, the ecosystem-standard Faces utility library (150K+ downloads/month)
  • Author of The Definitive Guide to Jakarta Faces in Jakarta EE 10 (2022) and the earlier Definitive Guide to JSF in Java EE 8 (2018)
  • Rewrote the Jakarta Servlet and Jakarta Faces sections of the Eclipse Foundation's Jakarta EE Tutorial
  • Has personally led RichFaces removals since 2011
  • The #1 all-time answerer of the [jsf] tag on Stack Overflow, with 1M+ reputation

Ways to engage

We meet you where you are: assess, pilot, implement, or rescue.

Assessment & Roadmap

Best when you know RichFaces must go but not the best path.

We review your architecture, codebase, UI-framework usage, dependencies, and goals, then deliver a practical, sequenced roadmap with options, risks, a recommended target architecture, and effort ranges.

Pilot / Vertical Slice

Best when you have a direction but want to validate before scaling.

We migrate representative screens, convert a workflow, or stand up a coexistence model — producing working software, exposing hidden risk, and yielding a repeatable playbook.

Implementation Support

Best when a roadmap exists and you need experienced execution.

We lead the migration or take the hardest screens and components, establish conventions, mentor, review PRs, build automation, and debug the difficult JSF / PrimeFaces / Jakarta EE / Spring issues.

Advisory, Enablement & Rescue

Best when your team is executing but needs guidance, or a migration has stalled.

Architecture and component-mapping, mentoring, troubleshooting and escalation, automation-strategy guidance, training, and recovery support for migrations that hit unexpected complexity.

Most engagements start with an assessment, and we scope follow-on work from what we find. If you already know your direction, we can begin with a pilot, or go straight to implementation or advisory. If your project is already underway, we can start with implementation, advisory, or rescue.

Frequently asked questions

Is RichFaces still supported, and when did it reach end of life?

No. RichFaces reached end of life in June 2016 and has received no updates since, including no security patches. There is no supported release, no vendor behind it, and a shrinking pool of developers who still know it. Staying on it means any newly discovered vulnerability will never be fixed, and the framework keeps blocking the Java, application-server, and Jakarta EE upgrades around it. Removing RichFaces is the best path that closes the exposure and unblocks the rest of your modernization.

Are there known RichFaces security vulnerabilities?

Yes; several, including multiple critical ones. The headline is CVE-2018-14667, a critical expression-language injection in RichFaces 3.x that allows remote code execution; it is listed in CISA's Known Exploited Vulnerabilities catalog and has been observed exploited in the wild. There are further critical, unauthenticated remote-code-execution flaws across both the 3.x and 4.x lines — CVE-2018-12533 and CVE-2018-12532, both rated CVSS 9.8 — plus the deserialization flaw CVE-2013-2165 and the code injection CVE-2015-0279. Because the project is dead, none of these will ever be officially patched upstream. The only durable fix is to remove RichFaces from your application.

Should we migrate RichFaces to PrimeFaces or to a modern JavaScript framework?

It depends on your application and your team. Migrating to PrimeFaces keeps the JSF programming model and is often the safest, most cost-effective route when the app is fundamentally sound and business logic is tightly coupled to JSF. Moving to a modern JavaScript framework such as React, Angular, or Vue fits teams that want a modern frontend platform and have, or want, modern JS skills in-house. Large systems often land on a hybrid: high-value screens on PrimeFaces, selected modules rebuilt in JavaScript, on a modernized app server. We help you choose based on your actual code, team and goals.

How risky is a RichFaces migration on a business-critical system?

Managed well, far less risky than staying put. We reduce risk with incremental migration, acceptance criteria defined with you per workflow, coexistence models that keep the app running, and the option to validate with a pilot before scaling. We recommend involving your QA function early and can build automated tests with Selenium or Playwright if you want that in scope. We have done this on systems far larger than most, so the failure modes are familiar and planned for.

Should I rewrite my RichFaces application instead of migrating it?

Usually not. A full rewrite throws away decades of embedded business logic and carries enormous cost and risk. Our approach preserves business functionality while modernizing, and where a clean break genuinely makes sense we do it selectively, module by module, with coexistence rather than a big-bang gamble. Rewrites are the exception, chosen deliberately, not the default.

Is there a maintained fork of RichFaces we can use instead?

There is an unofficial community fork that has patched the known CVEs, and it can be a legitimate short-term way to close those specific holes. But it is a stopgap, not a strategy. It is a single-maintainer effort with no security team and no guarantee the next vulnerability gets fixed; adopting it is itself an upgrade with new dependencies and re-testing. It still requires JDK 8, old dependencies with their own security vulnerabilities, and old application servers. The fork can buy a little time on the CVEs; it cannot move your architecture forward.

Can AI just migrate RichFaces automatically?

AI coding agents are very capable, but complex applications require more than just a coding agent. We know because we've spent a lot of time cleaning up projects where the team attempted using a coding agent alone. We follow a structured process that includes AI-assisted analysis, OpenRewrite recipes for repeatable, deterministic changes, plus agent-driven changes and bug fixes. Architecture decisions, behavior preservation, complex JSF pages, and the judgment-heavy edge cases require senior engineers. Letting AI rewrite a mission-critical application unsupervised is how you get subtle, hard-to-find defects. Our model is machine-assisted and human-orchestrated: automation where it is safe, hand-written code where it is not, and senior engineers owning all of it.

Can't we just run Copilot, Amazon Q, or IBM's tool ourselves?

You can, and sometimes using tools such as IBM Application Modernization Accelerator, Github Copilot App Modernization, and Amazon Q Developer:Transform is the right call; we use those tools ourselves when they fit. But for RichFaces specifically, three things separate our work from running a tool alone. The off-the-shelf tools do not ship recipes for RichFaces or PrimeFaces, which is the hardest, most framework-specific part; complex pages and edge cases still need deep JSF and PrimeFaces expertise; and a tool does not own the outcome. Running the tool is itself a project, and the project needs expert owners who decide scope, judge whether each fix is correct, and take responsibility for the migration being finished and shipped. That is the role we fill.

How long does a RichFaces migration take?

It depends on the size and complexity of the application, our level of involvement with the implementation and how much you want to improve along the way. The assessment produces sequenced phases and effort ranges so you can plan budget and timeline with real numbers.

Let's get RichFaces out of your stack

Tell us about your application and where it is stuck. We will help you scope the path off RichFaces via assessment, pilot, implementation, or rescue.

Get a migration assessment