The repository has tests, recent pushes, two active contributors, and clear release notes for this breaking version. Workflow references are all unpinned, and no security policy or automated security scanning is present.
68%
Total Score
100
50
88
75
The release has 14 runtime dependencies, including PHP extensions, MongoDB, Symfony, logging, and project-specific packages; this is a substantial integration surface but fits a MongoDB job-queue library.
The package has 25 releases since June 2019, but none in the last 12 months; this suggests a slowing release cadence, partly offset by recent repository activity.
The project uses Make and Composer, but no security-scanning tooling was detected, leaving a modest transparency and maintenance gap.
The repository has no security policy, which makes vulnerability reporting and response expectations less clear.
Both workflows were analyzed without audit findings or untrusted triggers, and one scopes permissions read-only. However, all 12 action references are unpinned, weakening build reproducibility and supply-chain hygiene.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^3.0 | — | — |
mongodb/mongodb Version ^2.1 | — | — |
monolog/monolog Version ^3.9 | — | — |
symfony/console Version ^7.3 | — | — |
recruiterphp/geezer Version ^7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.