ZephyrPHP Starter - Create a new ZephyrPHP CMS website
62%
Total Score
caution
Usable with caveats: a young pre-1.0 project lacks security-policy and scanning coverage.
The package is 250 days old with 42 releases in the last 12 months, released about every 40 minutes at the median. This shows active publishing but unusually rapid churn for a young project, which reduces maturity confidence.
The repository has zero stars, forks, and watchers. Popularity is only supporting evidence, but the absence of any community footprint provides no external maturity signal for this young project.
Composer is used as the build tool, which fits the PHP package, but no security scanning tools are configured. The missing scanning reduces supply-chain hygiene confidence without proving a defect.
The repository has no security policy. For a CMS starter with authentication, authorization, APIs, and multiple runtime dependencies, this is a meaningful transparency and maintenance gap.
Version v0.5.23 is not a stable-major release, although it is not marked as a prerelease and recent releases are consistently non-prerelease. The pre-1.0 status leaves greater room for breaking changes.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
zephyrphp/cms Version ^0.9 | — | — |
zephyrphp/auth Version ^0.4 | — | — |
zephyrphp/cache Version ^0.4 | — | — |
zephyrphp/database Version ^0.4 | — | — |
zephyrphp/framework Version ^0.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.