KitGradeSCORED ON WHAT A BUYER CAN CHECK
REFRESHED 05:41 UTCOpen API
38 kits scored16 installed and run here22 read, not run22 free and open source16 paid100 points, method 1.0captured 2026-09-13nothing here is sponsored

Kostra earned 66.6 points of a hundred.

Rank 9 of the 38 kits in the index, and Bullet Train at the top earned 92.2. Every point below was awarded under a published rule and read off a page anyone can open. Put another kit on the bench from the rail, or read the whole ledger.

REPOSITORY
advantailabs/kostra-boilerplate
BUILT ON
Next.js
PRICE
Free
EVIDENCE
Read, not run
LAST COMMIT
2 months ago, 2026-07-20
Maintenance16/30
Completeness19.6/25
Transparency20/20
Documentation5/15
Support6/10
RANK 9 OF 38/READ, NOT RUN, read from its repository, its manifest and its own documentation/EVERY COMPONENT MEASURABLE ON THIS KIT/OUT OF A FULL 100, NEVER A SHARE OF WHAT WAS VISIBLEHow this is calculated
The bench

Maintenance

16 of 30POINTS

Whether the code is still moving, and whether more than one person is moving it.

Last commit

12 pts

54 days since the last commit

Recency of the last commit, 15 points inside a month, 12 inside three, 8 inside six, 4 inside a year, 0 after that.

github.com/advantailabs/kostra-boilerplate

Tagged releases

3 pts

1 tagged release in the last twelve months

Tagged releases in the last twelve months, 10 points at four or more, sliding to 0 at none.

github.com/advantailabs/kostra-boilerplate

Contributors

1 pts

1 contributor

Contributor count, 5 points at twenty or more, sliding to 0 at none.

github.com/advantailabs/kostra-boilerplate

Completeness

19.6 of 25POINTS

How many of the fourteen things people buy a starter kit for are actually in it.

Capabilities found

19.6 pts

11 of the 14 a buyer looks for

For an open-source kit, each capability is looked for in the dependency manifest and the file tree, what the kit ships, not what its README says.

  • Authentication

    file: src/app/api/auth/forgot-password/route.ts

  • Social / OAuth login

    not found in repo tree or manifests

  • Teams & organisations

    file: src/components/icons/Teams.tsx

  • Roles & permissions

    file: src/lib/routes/permissions.ts

  • Payments & billing

    dependency: stripe

  • Transactional email

    dependency: resend

  • Admin panel

    file: src/app/api/admin/users/[id]/restore/route.ts

  • Internationalisation

    not found in repo tree or manifests

  • Test suite

    dependency: jest

  • CI pipeline

    file: .github/workflows/ci.yml

  • Background jobs

    not found in repo tree or manifests

  • Webhook handling

    dependency: svix

  • Blog / content

    file: src/app/(branding)/blog/[slug]/page.tsx

  • File uploads

    dependency: @aws-sdk/client-s3

Next.jsReactTypeScriptPrismaPostgreSQLStripeAWSDocker

Transparency

20 of 20POINTS

How much a buyer can check before paying.

Public source repository

6 pts

advantailabs/kostra-boilerplate

A public source repository, 6 points.

github.com/advantailabs/kostra-boilerplate

Stated licence

4 pts

MIT

A stated licence, 4 points.

github.com/advantailabs/kostra-boilerplate

Price readable without an account

4 pts

Free

A price published on a page that can be read without an account, 4 points.

Public release history

3 pts

latest tag v1.0.0

A public release history, 3 points.

github.com/advantailabs/kostra-boilerplate

Public documentation

3 pts

a README and no site

Public documentation, 3 points.

github.com/advantailabs/kostra-boilerplate

Documentation

5 of 15POINTS

Whether the documentation exists, and how much of it there is.

README only

5 pts

long enough to be the documentation

A README long enough to be the documentation and no site, 5 points.

github.com/advantailabs/kostra-boilerplate

Support

6 of 10POINTS

Whether there is a stated way to get help.

Stated channel

6 pts

GitHub issues

A community channel or issue tracker, 6 points.

github.com/advantailabs/kostra-boilerplate

What happened when we ran it

0COMMANDS

This kit was read, not run. Its row came from its repository, its dependency manifest and its own documentation, and no command was executed against it here. Every figure above says where it was read from.