Novaris Framework: The core foundation of the Novaris Content Management System (CMS), providing a robust and flexible architecture designed to power dynamic content-driven websites
67%
Total Score
caution
Usable with caveats: a one-day-old package with one contributor and unpinned workflow actions is not yet mature.
This is the only release and was published less than one hour before collection, so there is little evidence of long-term release stability despite substantial recent repository activity.
All 345 recent commits came from one contributor, creating a concentrated maintenance dependency; organization ownership provides some handoff capacity but no second active contributor is shown.
Composer build tooling is present, but no security scanning tooling was detected, leaving a modest transparency and maintenance gap.
The repository has no security policy, so vulnerability reporting expectations are not documented.
The workflow audit completed cleanly with no untrusted checkout, injection, or high-confidence security findings. However, both analyzed action references are unpinned, which weakens build reproducibility and supply-chain hygiene.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/yaml Version ^6.0 | — | — |
league/config Version ^1.2 | — | — |
vlucas/phpdotenv Version ^5.6 | — | — |
guzzlehttp/guzzle Version ^7.9 | — | — |
league/commonmark Version ^2.10.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.