Which one should I pick for a new project?
Which one should I pick for a new project?
About dromara/sa-token · 2 messages · last activity 9/9/2026
I can only provide guidance based on what's in the repository data, but I need more context to help you decide.
Are you asking whether to use dromara/sa-token for a new project? If so, here's what the signals indicate:
RepoPilot Verdict: WAIT — Solo project — review before adopting
Key findings:
- Architecture grade C (50/100): Limited internal structure visibility from the 2 files parsed
- OpenSSF Scorecard 4.5/10: Weak scores on Code-Review (0/10), CII-Best-Practices (0/10), and SAST (0/10)
- Dependency security: 0 critical/high CVEs detected in dependencies (positive signal)
- Code scanning: No open SAST alerts
What this means:
- The project lacks formal code review practices and automated security scanning
- No CII Best Practices badge, suggesting lower maturity on process standards
- However, it has 19k+ stars and 2.9k forks, indicating community adoption
Recommendation: Before adopting sa-token in production, you should:
- Review its code quality and architecture yourself
- Check if the active maintainer model (described as "solo project") aligns with your team's support needs
- Evaluate whether the authentication features match your requirements
If you're comparing dromara/sa-token to ybq/android-spinkit, please clarify—they solve different problems (Java auth framework vs. Android loading spinner library).
FOLLOW_UPS:
- What type of project are you building?
- Do you need authentication/authorization specifically?
- What's your risk tolerance for upstream maintenance?
Want to ask your own question?
Open chat for dromara/sa-tokenPublic Q&A. Generated by RepoPilot from the actual source of dromara/sa-token. AI answers can be incomplete or stale — verify before relying on them.