ZephyrPHP - An open-source, GUI-first CMS platform for building modern websites.
68%
Total Score
caution
Usable with caveats: active releases are encouraging, but security oversight is thin.
The package declares six runtime dependencies and no development dependencies. The runtime set is moderate and recognizable, but the absence of development dependencies provides little evidence of a maintained test or development setup.
Composer is used as the build tool, but no security scanning tools were detected. For a framework handling authentication, encryption, and other security-sensitive features, that weakens maintenance transparency.
The repository has no published security policy. That leaves vulnerability reporting and response expectations unclear for a security-sensitive framework.
Version v0.4.60 is not a stable-major release, so the framework is still below 1.0 and may have compatibility changes ahead. It is not marked as a prerelease, which partly offsets that concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^3.0 | — | — |
twig/twig Version ^3.17 | — | — |
php-di/php-di Version ^7.0 | — | — |
symfony/console Version ^6.0|^7.0 | — | — |
vlucas/phpdotenv Version ^5.6 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.