INDIE WEB/独立站与出海·PAYMENT
scosman/CMSaasStarter
一个模板,把支付、认证、定价页都搭好,直接开始卖你的SaaSA single boilerplate that wires up payments, auth, pricing, and a blog — start selling your SaaS today
SaaS网站起步模板,帮开发者快速搭好登录、支付与订阅后台。A SvelteKit boilerplate that bundles subscriptions, auth, pricing, and a blog so you can ship a SaaS faster.
怎么装:Install: git clone
02 / 现在的位置02 / Why now
首次发现FIRST SEEN
03 OCT 202603 OCT 2026
增长GROWTH
-0.0%-0.0%
2.4k → 2.4k stars · 3 个快照2.4k → 2.4k stars · 3 snapshots
状态STATUS
长期未更新Not updated
2366 个 star,说明这个模板已经有不少人试用过,不是无人问津的仓库。Includes both a marketing page and a blog out of the box
03 / 它能帮你做什么03 / What it helps you do
搭好一个带付费会员的网站
让访客注册、登录和管理账户
做出产品介绍、博客和价格页面
让用户查看订阅和修改账户设置
Start with user sign‑up, login, and password reset
Offer monthly or annual subscription plans
Display a pricing table that syncs with Stripe products
Publish blog posts alongside a landing page
Give users a dashboard to manage their account settings
04 / 安装04 / Install
$ README 里给出的安装方式。The installation method given in the README.
两种装法选一个即可 —— 上面那条给命令行用户,下面那条给写代码的用户。Pick one of the two — the first is for command-line users, the second for people writing code.
用 git clone 把仓库克隆到本地,再按文档继续配置。Clone the repo, run `npm install`, copy the example environment file, and start the dev server with `npm run dev -- --open`.
05 / 限制与风险05 / Limits and risk
风险不是警告,是可信度的一部分。以下结论只基于文档静态扫描,我们不会执行项目里的任何代码。Risk here is evidence, not an alarm. These findings come from static scanning of the docs; we never execute a project’s code.
限制LIMITS
存在风险Risk found
静态扫描STATIC SCAN
01下载未知二进制Downloads an unknown binaryreadme
# first time only: chmod +x ./checks.sh
02安装时执行脚本Runs a script during installpackage.json
postinstall: patch-package
静态扫描发现高风险项:文档要求下载并执行未知脚本(chmod +x ./checks.sh),且安装时会有脚本运行(postinstall: patch-package)。The static scan found a high‑risk item: the `checks.sh` script is downloaded and made executable, which could run unknown code. There is also a medium‑risk script that runs during `npm install`. You should review both files before running them.
这里只做静态扫描:读 README、SKILL.md 和依赖清单,不执行代码。没有命中不代表安全。This is static scanning only: we read the README, SKILL.md and dependency list, and never execute code. No findings does not mean safe.
依赖:Dependencies:@supabase/auth-ui-shared, @supabase/auth-ui-svelte, @supabase/ssr, @supabase/supabase-js, handlebars, resend, stripe
{
"agents": [
{
"agent": "vscode",
"evidence": "readme: …te and accessibility issues: [VSCode](https://marketplace.visualst…"
}
],
"apiKey": "it as an environment variable PRIVATE_STRIPE_API_KEY (`.env.local` locally, and Cloudflare e",
"docker": null,
"taxonomy": {
"scores": {
"design": 3,
"ai-tools": 1,
"dev-tools": 1,
"indie-web": 6,
"skill-agent": 0,
"productivity": 0
},
"primary": "indie-web",
"secondary": "payment"
},
"localRuntime": "install: git-clone",
"skillMdTotal": 0,
"skillMdErrors": [],
"treeTruncated": false,
"categoryScores": {
"data": 2,
"agent": 0,
"media": 0,
"design": 11,
"browser": 0,
"devtool": 1,
"security": 0,
"marketing": 3,
"productivity": 0
},
"classification": [],
"scannedSources": [
"readme"
],
"skillMdFetched": 0
}