RepoPilot

Which one should I pick for a new project?

About dromara/sa-token · 2 messages · last activity 9/9/2026

Question

Which one should I pick for a new project?

RepoPilot

I can only provide guidance based on what's in the repository data, but I need more context to help you decide.

Are you asking whether to use dromara/sa-token for a new project? If so, here's what the signals indicate:

RepoPilot Verdict: WAIT — Solo project — review before adopting

Key findings:

  • Architecture grade C (50/100): Limited internal structure visibility from the 2 files parsed
  • OpenSSF Scorecard 4.5/10: Weak scores on Code-Review (0/10), CII-Best-Practices (0/10), and SAST (0/10)
  • Dependency security: 0 critical/high CVEs detected in dependencies (positive signal)
  • Code scanning: No open SAST alerts

What this means:

  • The project lacks formal code review practices and automated security scanning
  • No CII Best Practices badge, suggesting lower maturity on process standards
  • However, it has 19k+ stars and 2.9k forks, indicating community adoption

Recommendation: Before adopting sa-token in production, you should:

  1. Review its code quality and architecture yourself
  2. Check if the active maintainer model (described as "solo project") aligns with your team's support needs
  3. Evaluate whether the authentication features match your requirements

If you're comparing dromara/sa-token to ybq/android-spinkit, please clarify—they solve different problems (Java auth framework vs. Android loading spinner library).

FOLLOW_UPS:

  • What type of project are you building?
  • Do you need authentication/authorization specifically?
  • What's your risk tolerance for upstream maintenance?

Want to ask your own question?

Open chat for dromara/sa-token

Public Q&A. Generated by RepoPilot from the actual source of dromara/sa-token. AI answers can be incomplete or stale — verify before relying on them.