The catalog turns 237 resources into a shortlist
The measured commit carries 237 entries covering official documentation, tools, plugins, components, backend SDK components, and demos. Radar filters them by recommendation status, risk, resource type, category, and use case. Compare puts choices such as Taro, uni-app, and native mini-program development beside each other. For a team starting with a spreadsheet of links, that is a meaningful upgrade: one place can narrow the field before anyone builds a prototype.
Generated JSON sits beside the checked-in YAML source, so maintainers can review changes and run a basic trial without Postgres. The project also includes CLI commands for resources, comparisons, health reports, Advisor questions, and Doctor scans.
Advisor and Doctor make the 237-item catalog actionable
Advisor scores the 237 resources with local rules, selects candidates, and returns fit conditions, migration cost, risks, alternatives, and a validation checklist. With an OpenAI-compatible provider configured, a model rewrites that prepared answer under a schema. It cannot add resource IDs, URLs, stars, or maintenance claims. If the provider fails, the rule-generated answer remains available.
Doctor reads project configuration rather than a vague chat prompt. The repository has fixtures for Taro, uni-app, MPX, and WePY, and Doctor flags framework dependencies, old choices, and migration risk. You can scan a real project, then use Advisor and Compare to build a small candidate set instead of browsing 237 cards.
What happened when we ran it
Our sandbox installed commit a6f9748 in 28 seconds, pulling 431 packages and taking 629 MB on disk. The Next.js build passed in 26 seconds. We ran it in an unprivileged Debian container with 3 CPUs, 8 GB of RAM, Node 22, and no secrets. The checkout contained 179 files and about 18,024 lines of source. These results cover installation and compilation, not recommendation accuracy.
Tests were skipped because the runner found no standard test script or target. Source inspection shows named *:test commands and a long npm run check chain, but we did not run or count those checks. Npm audit reported 17 known vulnerabilities: 1 critical, 3 high, and 13 moderate. That is a dependency warning, not evidence that the hosted site was exploited.
Node 20 is easy, production takes more
Node 20 or newer and npm cover the local application path. The YAML catalog and rule-based Advisor keep a basic trial light. A fuller setup can use Postgres, an OpenAI-compatible endpoint, GitHub access, Blob storage, Redis or KV, cron authentication, an admin token, and Vercel project credentials. Each service is optional for some path, but together they define the production feature set.
There are 4 GitHub Actions workflows for validation, link checking, Pages deployment, and Vercel verification. There is no Dockerfile. Teams outside Vercel must supply an image, migration sequence, database, secret injection, and scheduled jobs. The contributor guide explains npm run check, import, preflight, readiness, and deployment verification in Chinese.
Seventeen advisories keep this out of a careless deployment
The 17 audit findings are the clearest reason to pause before self-hosting. One was critical and 3 were high severity. The project merged security and cache fixes on September 29, 2026, including work after commit a6f9748. That activity does not clear the dependency report from the commit we measured. Review the audit paths and upgrade impact before exposing admin or cron routes.
Some maintenance and risk labels also come from hard-coded names and keywords. WePY and mpvue map to high-risk hold status, while Taro, uni-app, Vant, TDesign, and WeUI map to low-risk adopt status. Those defaults help sort the catalog. Verify releases, issue response, compatibility, bundle behavior, and target devices before making a long-lived choice.
Four workflows show activity, while releases remain untagged
GitHub showed 51,205 stars, 8,988 forks, and a last push on September 29, 2026. The single open item was a pull request, not an issue, and recent merged work covered data snapshots, caching, and dependency security. Four workflow files exercise validation and deployment paths. The push date and pull-request activity show current maintenance.
GitHub returned no latest release, and the tags endpoint was empty when checked. The private package calls itself version 1.0.0, which is not a published product release. Pin a commit, record local schema changes, and review upstream diffs before pulling updates.
Chinese documentation makes this a specialist tool
Both tracked prose guides, README.md and AGENTS.md, are written in Chinese. The interface strings and generated weekly report are Chinese too. An English-speaking team would need to translate product copy and operational instructions, a poor trade unless WeChat mini programs are already central to the business.
Use the shortlist, then verify every finalist
WeChat Miniapp Radar can cut 237 entries down to a few experiments, and our 26-second build makes a trial approachable. With 17 dependency findings and rule-assigned risk labels, the radar should start your evaluation rather than settle it. Build the same real page with its top two candidates and check the maintenance evidence the catalog cannot measure for your team.

