Package Health

zephyrus-framework/core

The package has clear documentation, tests, an MIT license, regular releases, and active security tooling. Its young project relies on one contributor, and all three workflow actions are unpinned, so maintenance continuity and build reproducibility remain concerns.

Latest v0.13.0PackagistPackagist

68%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

83

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Repo bus factorcaution

One contributor made all 41 commits in the last 3 months, creating a real continuity risk; organization ownership provides some backing but no active second contributor is shown.

Security policycaution

The repository has no published security policy, making vulnerability reporting and coordinated disclosure less transparent for a security-focused framework.

Version stabilitycaution

v0.13.0 is not a prerelease, but the package remains below major version 1, so its public interfaces may still change substantially.

Workflow auditcaution

The sole workflow was fully analyzed with no dangerous triggers, untrusted checkouts, injection findings, or broad write permissions. However, all 3 action references are unpinned, weakening build reproducibility, while the missing top-level permissions block is acceptable on its own.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
latte/latte
Version ^3.0
—
—
tracy/tracy
Version ^2.10
—
—
symfony/yaml
Version ^7.0
—
—
vlucas/phpdotenv
Version ^5.6
—
—
phpmailer/phpmailer
Version ^6.9
—
—

Weekly Downloads

Info

Last Published
1 month ago
Created
6 months ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform