Stack AtlasBeta · provisional scores

Know what your agent is about to install.

Is a library still maintained, deprecated, or superseded — and what replaced it? Stack Atlas answers from dated GitHub and npm evidence for 13 open-source repositories. Health and momentum are kept separate, every value is labelled verified, derived, or approved, and missing evidence is never scored as zero.

13 repositories · evidence through 2026-09-16 · Methodology

13 of 13 repositories

Authentication and identity

Active, derived

better-auth/better-auth

The most comprehensive authentication framework

Health
97ExemplaryMedium confidence
Momentum
Volatile2 of 4 signals
Stack fit
Not evaluatedNeeds a saved profile
  • Strongest signal: Maintenance scores 100 — Latest non-bot commit: 2026-09-16, 1 day ago.
  • Watch: Governance scores 67 — Issue or PR templates: Missing.
Verified 2026-09-1629,977 starsTypeScript

Validation and schema definition

Active, derived

colinhacks/zod

TypeScript-first schema validation with static type inference

Health
87StrongMedium confidence
Momentum
Surging3 of 4 signals
Stack fit
Not evaluatedNeeds a saved profile
  • Strongest signal: Maintenance scores 85 — Latest non-bot commit: 2026-09-13, 4 days ago.
  • Watch: Governance scores 67 — Issue or PR templates: Missing.
Verified 2026-09-1643,955 starsTypeScript

ORMs and query builders

Active, derived

drizzle-team/drizzle-orm

ORM

Health
66Evaluate carefullyMedium confidence
Momentum
Insufficient history1 of 4 signals
Stack fit
Not evaluatedNeeds a saved profile
  • Strongest signal: Documentation scores 100 — README: Present.
  • Watch: Community depth scores 20 — Top contributor share (90 days): The most active author made 100% of human commits.
Verified 2026-09-1635,792 starsTypeScript

Styling and design systems

Evergreen, approved

lukeed/clsx

A tiny (239B) utility for constructing `className` strings conditionally.

Health
Insufficient evidenceInsufficient evidence
Momentum
Insufficient history1 of 4 signals
Stack fit
Not evaluatedNeeds a saved profile
  • Strongest signal: Stability scores 100 — Primary package ≥ 1.0: clsx@2.1.1.
  • Watch: Documentation scores 33 — Contributing guide: Missing.
Verified 2026-09-169,838 starsJavaScript

Agent frameworks and orchestration

Active, derived

mastra-ai/mastra

Mastra is the modern TypeScript framework for AI-powered applications and agents.

Health
69Evaluate carefullyMedium confidence
Momentum
Surging2 of 4 signals
Stack fit
Not evaluatedNeeds a saved profile
  • Strongest signal: Maintenance scores 100 — Latest non-bot commit: 2026-09-16, 1 day ago.
  • Watch: License could not be machine-identified — health is capped at 69.
Verified 2026-09-1628,111 starsTypeScript

API frameworks and transport

Active, derived

middleapi/orpc

Typesafe APIs Made Simple 🪄

Health
87StrongMedium confidence
Momentum
Volatile3 of 4 signals
Stack fit
Not evaluatedNeeds a saved profile
  • Strongest signal: Maintenance scores 100 — Latest non-bot commit: 2026-09-16, 1 day ago.
  • Watch: Community depth scores 45 — Top contributor share (90 days): The most active author made 96% of human commits.
Verified 2026-09-165,625 starsTypeScript

MCP servers and MCP tooling

Active, derived

modelcontextprotocol/servers

Model Context Protocol Servers

Health
69Evaluate carefullyLow confidence
Momentum
Insufficient history1 of 4 signals
Stack fit
Not evaluatedNeeds a saved profile
  • Strongest signal: Maintenance scores 85 — Latest non-bot commit: 2026-09-03, 14 days ago.
  • Watch: License could not be machine-identified — health is capped at 69.
Verified 2026-09-1690,392 starsTypeScript

Authentication and identity

Superseded, approved

nextauthjs/next-auth

Authentication for the Web.

Health
88StrongMedium confidence
Momentum
Volatile2 of 4 signals
Stack fit
Not evaluatedNeeds a saved profile
  • Strongest signal: Documentation scores 100 — README: Present.
  • Watch: Maintenance scores 67 — Weeks with commits (last 13): 2 of 13 weeks had commits. Includes bot commits.
Verified 2026-09-1628,365 starsTypeScript

ORMs and query builders

Active, derived

prisma/orm

Next-generation ORM for Node.js & TypeScript | PostgreSQL, MySQL, MariaDB, SQL Server, SQLite, MongoDB and CockroachDB

Health
95ExemplaryMedium confidence
Momentum
Volatile2 of 4 signals
Stack fit
Not evaluatedNeeds a saved profile
  • Strongest signal: Maintenance scores 100 — Latest non-bot commit: 2026-09-16, 1 day ago.
  • Watch: Community depth scores 73 — Top contributor share (90 days): The most active author made 59% of human commits.
Verified 2026-09-1647,612 starsTypeScriptTransferred

Templates, starters, and boilerplates

Superseded, approved

react/create-react-app

Set up a modern web app by running one command.

Health
59Evaluate carefullyLow confidence
Momentum
Insufficient history1 of 4 signals
Stack fit
Not evaluatedNeeds a saved profile
  • Strongest signal: Documentation scores 100 — README: Present.
  • Watch: Community depth scores 0 — Human contributors (90 days): 0 distinct non-bot authors.
Verified 2026-09-16103,257 starsJavaScriptTransferred

HTTP clients and networking

Archived, approved

request/request

🏊🏾 Simplified HTTP request client.

Health
33High riskLow confidence
Momentum
Insufficient history1 of 4 signals
Stack fit
Not evaluatedNeeds a saved profile
  • Watch: Primary package is deprecated on npm — health is capped at 54.
Verified 2026-09-1625,505 starsJavaScriptDeprecated package

Server state and data fetching

Active, derived

TanStack/query

🤖 Powerful asynchronous state management, server-state utilities and data fetching for the web. TS/JS, React Query, Solid Query, Svelte Query and Vue Query.

Health
87StrongMedium confidence
Momentum
Volatile3 of 4 signals
Stack fit
Not evaluatedNeeds a saved profile
  • Strongest signal: Maintenance scores 100 — Latest non-bot commit: 2026-09-16, 1 day ago.
  • Watch: Governance scores 67 — Code of conduct: Missing.
Verified 2026-09-1650,311 starsTypeScript

Web application frameworks

Active, derived

vercel/next.js

The React Framework

Health
96ExemplaryMedium confidence
Momentum
Rising2 of 4 signals
Stack fit
Not evaluatedNeeds a saved profile
  • Strongest signal: Maintenance scores 100 — Latest non-bot commit: 2026-09-16, 1 day ago.
  • Watch: Stability scores 75 — Prerelease share (last year): 87% of 100 releases were prereleases.
Verified 2026-09-16142,348 starsJavaScript

Repositories by category

Agent frameworks and orchestration

API frameworks and transport

Authentication and identity

HTTP clients and networking

MCP servers and MCP tooling

ORMs and query builders

Server state and data fetching

Styling and design systems

Templates, starters, and boilerplates

Validation and schema definition

Web application frameworks

Questions about Stack Atlas

What is a RepoFacts label?
A RepoFacts label summarizes one open-source repository from dated evidence: its maintenance status, a health score with coverage and confidence, momentum by signal family, npm adoption, and reviewed decisions such as supersession. Stack Atlas currently covers 13 repositories.
How does Stack Atlas decide whether a repository is maintained?
It uses the latest commit on the default branch that was not made by a bot account, compared against a six-month cutoff. GitHub's pushed_at and updated_at timestamps are not used, because they move on pushes to any branch and on metadata edits.
How is the health score calculated?
Health averages eight dimensions, including maintenance, security posture, documentation, stability, community depth, and governance, using only signals that have evidence. The score is published with the share of weight the evidence covers; below 50% no score is shown. Critical conditions such as an archived repository or a deprecated package cap the score.
Why isn't momentum a single number?
Momentum compares current and previous windows separately for development, contribution, adoption, and attention. A combined score needs a comparable group of at least 8 repositories per category, which the catalog does not have yet, so each signal is shown on its own.
Does a high health score mean a package is secure?
No. Scores are decision support, not a security audit or certification. Security advisories and dependency data are not collected yet, and the absence of advisory data is not evidence that there are no vulnerabilities.
How current is the data?
A collector records GitHub and npm evidence daily and commits a dated snapshot only when something changed. Every profile shows the date it was last verified, and evidence older than 14 days is marked stale.
Who decides that a repository is superseded or evergreen?
A named reviewer, with evidence links. Those judgments are never derived automatically, and a proposal is not applied until someone other than its proposer approves it.