mrkeyoor.com_
Tue 29 Sept 13:57 UTC
Dev Toolsevaluationupdated 29 Sept 2026

wechat-miniapp-radar review

WeChat Miniapp Radar is a Chinese-language decision tool for comparing frameworks, UI libraries, SDKs, examples, and other WeChat mini-program resources. Its README and tracked developer guide are in Chinese, and the measured commit contains no English README or English documentation file.

Verdict

Our WeChat Miniapp Radar run installed 431 packages, used 629 MB, and built in 26 seconds, but npm audit found 17 known vulnerabilities. Use it when a Chinese-speaking team needs to turn 237 ecosystem entries into a manageable evaluation list. Treat its status labels and Advisor output as prompts for testing, since part of the scoring comes from hard-coded name and keyword rules.

We ran it

Lab card: what happened when we ran wechat-miniapp-radarScreenshot of wechat-miniapp-radar (miniapp.jjc.fun)
Install✓ · 28s431 packages · 629 MB
Build✓ · 26s
Testsn/ano test script
Known vulns171 critical · 3 high · 13 moderate · 0 low (npm audit)
Repo179 files~18,024 lines of source · 1.5 MB · 4 CI workflows

Answers from our run

Does wechat-miniapp-radar build from source?

Dependencies installed in 28 seconds (431 packages), and the build succeeded in 26 seconds. We cloned commit a6f9748 into a clean Debian container with 3 CPUs and no project-specific setup.

Does wechat-miniapp-radar have tests you can run?

Not through a standard command: the project exposes no test script or target that our harness could run.

Does wechat-miniapp-radar have known vulnerabilities in its dependencies?

npm audit flagged 17 known advisories in the dependency tree, including 1 critical at the time of our run.

Who should not use wechat-miniapp-radar?

Teams that need English product and contributor documentation: the README, developer guide, interface copy, and generated weekly material are Chinese.

What are the alternatives to wechat-miniapp-radar?

Taro, uni-app, WeChat Mini Program Demo. Our WeChat Miniapp Radar run installed 431 packages, used 629 MB, and built in 26 seconds, but npm audit found 17 known vulnerabilities.

Setup3/5Fast build, but full operation adds several external services
Docs3/5Detailed Chinese guidance, with no tracked English docs
Community5/551,205 stars and same-day merge activity on September 29
Maturity3/5Active code, no tagged releases, and 17 audit findings

Who it’s for

Chinese-speaking teams choosing between Taro, uni-app, native mini-program development, and related tools.
Architects who want a filterable catalog before they run proof-of-concept work.
Maintainers replacing a flat awesome list with status, risk, comparison, and weekly views.
Teams willing to treat Advisor and Doctor output as a shortlist that still needs project-specific verification.

Who it’s NOT for

Teams that need English product and contributor documentation: the README, developer guide, interface copy, and generated weekly material are Chinese.
Security-sensitive deployments that require a clean dependency audit before evaluation: our npm audit found 17 known vulnerabilities, including 1 critical and 3 high severity.
Automation that assumes npm test exists: the repository has custom check commands, but no standard test script or target was available to our runner.
Organizations that cannot redistribute modified GPL-3.0 software under that license's terms.
Buyers who require tagged releases and changelogs: GitHub returned no latest release, and the repository had no tags when checked.

Setup reality

Our sandbox installed commit a6f9748 in 28 seconds, adding 431 packages and using 629 MB on disk. The build succeeded in 26 seconds. The 1.5 MB checkout held 179 files and about 18,024 lines of source. No test target was available to the runner, so tests were skipped. Npm audit reported 17 known vulnerabilities: 1 critical, 3 high, and 13 moderate.

A basic local start needs Node 20 or newer and npm. The catalog can fall back to checked-in YAML and the Advisor can fall back to rules, but a fuller deployment can use Postgres, an OpenAI-compatible API, Vercel Blob, Redis or KV, GitHub access, cron authentication, and an admin token.

The repository is shaped around Next.js and Vercel, with four CI workflow files and no Dockerfile. Its many custom checks live behind npm run check, while the ordinary npm test convention is absent. Plan your own container, secret handling, migrations, and audit cleanup if Vercel is not your target.

The catalog turns 237 resources into a shortlist

The measured commit carries 237 entries covering official documentation, tools, plugins, components, backend SDK components, and demos. Radar filters them by recommendation status, risk, resource type, category, and use case. Compare puts choices such as Taro, uni-app, and native mini-program development beside each other. For a team starting with a spreadsheet of links, that is a meaningful upgrade: one place can narrow the field before anyone builds a prototype.

Generated JSON sits beside the checked-in YAML source, so maintainers can review changes and run a basic trial without Postgres. The project also includes CLI commands for resources, comparisons, health reports, Advisor questions, and Doctor scans.

Advisor and Doctor make the 237-item catalog actionable

Advisor scores the 237 resources with local rules, selects candidates, and returns fit conditions, migration cost, risks, alternatives, and a validation checklist. With an OpenAI-compatible provider configured, a model rewrites that prepared answer under a schema. It cannot add resource IDs, URLs, stars, or maintenance claims. If the provider fails, the rule-generated answer remains available.

Doctor reads project configuration rather than a vague chat prompt. The repository has fixtures for Taro, uni-app, MPX, and WePY, and Doctor flags framework dependencies, old choices, and migration risk. You can scan a real project, then use Advisor and Compare to build a small candidate set instead of browsing 237 cards.

What happened when we ran it

Our sandbox installed commit a6f9748 in 28 seconds, pulling 431 packages and taking 629 MB on disk. The Next.js build passed in 26 seconds. We ran it in an unprivileged Debian container with 3 CPUs, 8 GB of RAM, Node 22, and no secrets. The checkout contained 179 files and about 18,024 lines of source. These results cover installation and compilation, not recommendation accuracy.

Tests were skipped because the runner found no standard test script or target. Source inspection shows named *:test commands and a long npm run check chain, but we did not run or count those checks. Npm audit reported 17 known vulnerabilities: 1 critical, 3 high, and 13 moderate. That is a dependency warning, not evidence that the hosted site was exploited.

Node 20 is easy, production takes more

Node 20 or newer and npm cover the local application path. The YAML catalog and rule-based Advisor keep a basic trial light. A fuller setup can use Postgres, an OpenAI-compatible endpoint, GitHub access, Blob storage, Redis or KV, cron authentication, an admin token, and Vercel project credentials. Each service is optional for some path, but together they define the production feature set.

There are 4 GitHub Actions workflows for validation, link checking, Pages deployment, and Vercel verification. There is no Dockerfile. Teams outside Vercel must supply an image, migration sequence, database, secret injection, and scheduled jobs. The contributor guide explains npm run check, import, preflight, readiness, and deployment verification in Chinese.

Seventeen advisories keep this out of a careless deployment

The 17 audit findings are the clearest reason to pause before self-hosting. One was critical and 3 were high severity. The project merged security and cache fixes on September 29, 2026, including work after commit a6f9748. That activity does not clear the dependency report from the commit we measured. Review the audit paths and upgrade impact before exposing admin or cron routes.

Some maintenance and risk labels also come from hard-coded names and keywords. WePY and mpvue map to high-risk hold status, while Taro, uni-app, Vant, TDesign, and WeUI map to low-risk adopt status. Those defaults help sort the catalog. Verify releases, issue response, compatibility, bundle behavior, and target devices before making a long-lived choice.

Four workflows show activity, while releases remain untagged

GitHub showed 51,205 stars, 8,988 forks, and a last push on September 29, 2026. The single open item was a pull request, not an issue, and recent merged work covered data snapshots, caching, and dependency security. Four workflow files exercise validation and deployment paths. The push date and pull-request activity show current maintenance.

GitHub returned no latest release, and the tags endpoint was empty when checked. The private package calls itself version 1.0.0, which is not a published product release. Pin a commit, record local schema changes, and review upstream diffs before pulling updates.

Chinese documentation makes this a specialist tool

Both tracked prose guides, README.md and AGENTS.md, are written in Chinese. The interface strings and generated weekly report are Chinese too. An English-speaking team would need to translate product copy and operational instructions, a poor trade unless WeChat mini programs are already central to the business.

Use the shortlist, then verify every finalist

WeChat Miniapp Radar can cut 237 entries down to a few experiments, and our 26-second build makes a trial approachable. With 17 dependency findings and rule-assigned risk labels, the radar should start your evaluation rather than settle it. Build the same real page with its top two candidates and check the maintenance evidence the catalog cannot measure for your team.

Alternatives

ProjectWhat it isPick it when
TaroA React-oriented framework for building mini programs and other application targets.pick this instead when the framework decision is already made and your team needs the implementation layer.
uni-app gh↗A Vue-based framework for shipping one codebase across mini programs, web, and apps.pick this instead when Vue skills and cross-platform delivery matter more than surveying the ecosystem.
WeChat Mini Program DemoAn official-style collection of mini-program component, API, and cloud-development examples.pick this instead when you need working native examples rather than a recommendation layer.

What people are saying

  1. [velocity-scout] justjavac/wechat-miniapp-radar

Sources

  1. WeChat Miniapp Radar repository and README
  2. Package scripts and dependencies at measured commit
  3. Deployment environment template at measured commit
  4. Resource scoring source at measured commit
  5. AI Advisor fallback source at measured commit
  6. Open database query hardening pull request

More dev tools reviews

omarchy-workspace-layout · fermats-last-theorem · yjs · ffuf · ipadecrypt · coursebook · the whole board →