ORM
Object-Relational Mapping
In short
An ORM is a library that maps database tables to objects in your programming language, letting you read and write data with code instead of raw SQL.
What is an ORM?
An ORM, short for object-relational mapping, bridges two different worlds: the objects and classes your application code uses, and the tables and rows a relational database uses. With an ORM, a row in a users table becomes a User object, and saving that object writes the change back to the database.
Under the hood, the ORM generates SQL for you. You define models that describe your tables, then call methods like find, create, or update, and the ORM translates those calls into SQL queries, runs them, and converts the results back into objects. Most ORMs also handle schema migrations, relationships between tables, and parameterized queries that protect against SQL injection.
Popular ORMs include Hibernate for Java, Entity Framework for .NET, the Django ORM and SQLAlchemy for Python, Active Record for Ruby on Rails, and Prisma, Drizzle, and TypeORM for TypeScript. Think of an ORM as an interpreter: you speak your programming language, and it translates to SQL for the database.
ORMs save time and reduce repetitive code, but they can hide which queries actually run. A common pitfall is the N+1 query problem, where loading a list and then each item's related records triggers one query per item instead of a single joined query. Many teams use an ORM for everyday operations and write raw SQL or use a lighter query builder for complex or performance-critical queries.
At a glance
Key takeaways
- An ORM maps database tables to classes and rows to objects.
- It generates SQL for you, so you work in your programming language.
- Most ORMs handle relationships, migrations, and parameterized queries.
- Watch for hidden inefficiencies such as the N+1 query problem.
Example
// Insert a row without writing SQL by hand
const user = await prisma.user.create({
data: { name: "Ada", email: "ada@example.com" },
});
// Roughly equivalent to:
// SELECT * FROM "User" WHERE email LIKE '%@example.com' ORDER BY name;
const users = await prisma.user.findMany({
where: { email: { endsWith: "@example.com" } },
orderBy: { name: "asc" },
});Readers ask
Should I use an ORM or raw SQL?
An ORM is usually a good default for everyday create, read, update, and delete operations because it is faster to write and safer. Raw SQL is often better for complex reports or performance-critical queries, and many projects use both.
Does an ORM prevent SQL injection?
ORMs use parameterized queries by default, which protects against most SQL injection. You can still be vulnerable if you insert user input into the ORM's raw SQL features without parameters.
What is the N+1 query problem?
It happens when code runs one query to load a list of records and then one extra query for each record's related data. Most ORMs solve it with eager loading, which fetches the related data in one or two queries up front.
See also
- DatabaseDatabases, p. 6A database is an organized collection of data stored on a computer, managed by software that lets applications save, search, and update it efficiently.
- SQLDatabases, p. 40SQL is the standard language for working with relational databases, used to create tables and to insert, query, update, and delete the data stored in them.
- OOPProgramming Fundamentals, p. 40OOP, or object-oriented programming, is a way of structuring code around objects that bundle related data together with the functions that act on that data.
- SQL InjectionSecurity, p. 40SQL injection is an attack where user input is treated as part of a database query, letting an attacker read, change, or delete data they should not reach.
- FrameworkProgramming Fundamentals, p. 20A framework is a reusable foundation of code, tools, and conventions that provides the structure of an application, so developers only fill in their own logic.
- Database MigrationDatabases, p. 8A database migration is a versioned script that changes a database's schema, such as adding a column, so every environment applies the same changes in order.
Spotted a mistake or something missing on this page?Suggest an edit