Task Scheduler for CodeIgniter 4
60%
Total Score
caution
Usable with caveats: maintenance has gone quiet and workflow supply-chain hygiene is weak.
A post-update-cmd lifecycle script runs during Composer updates, which adds execution surface beyond ordinary installation. No provided signal shows that this script is harmful or unusually broad, so this is a modest hygiene concern.
The package is about 177 days old with two releases, both within the last 12 months. Its short history provides limited evidence of long-term maintenance, although the releases were made close together during initial development.
The repository recorded zero commits and zero active maintainers in the last three months. That is a concrete maintenance gap, though the project is still young and was pushed more recently than the measured commit window.
All 11 action references are unpinned, weakening build reproducibility, and the docs workflow has four high-confidence template-injection findings; because no untrusted trigger or checkout was found, these remain workflow hygiene concerns rather than standalone severe risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
codeigniter4/queue Version ^1.0 | — | — |
codeigniter4/settings Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.