Package Health

romanfedorskij/cron

Non-blocking cron scheduler with forked PHP workers

Latest v0.1.0PackagistPackagist

58%

Total Score

caution

A brand-new v0.1.0 package with rapid initial releases, no sustained commit history, and five unpinned workflow actions.

Health Score Breakdown

Release historycaution

The package is less than one day old, with five releases arriving within roughly 21 hours. This shows active initial publishing but provides almost no evidence of sustained maintenance.

Repo toolingcaution

The repository uses Composer and Make for build tooling, but no security scanning tools were detected. This is a hygiene gap for a package with substantial runtime dependencies, not a severe risk by itself.

Security policycaution

The repository has no security policy. For a new library this is a modest transparency and maintenance gap, though it is not evidence that the package is unsafe.

Version stabilitycaution

The assessed release is v0.1.0 and 80% of recent releases are prereleases, so the API and behavior are likely still changing. No stable-major release history compensates for that uncertainty.

Workflow auditcaution

The single workflow was fully analyzed with no dangerous triggers, injection sinks, or audit findings, and it has no top-level write permissions. However, all five action references are unpinned, leaving avoidable build-reproducibility and action-substitution risk.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Roman Fedorskij

Direct Dependencies

DependencyLast ReleaseScore
psr/log
Version ^3.0
—
—
psr/clock
Version ^1.0
—
—
symfony/yaml
Version ^7.4
—
—
psr/container
Version ^1.1 || ^2.0
—
—
symfony/console
Version ^6.4 || ^7.4
—
—

Weekly Downloads

Info

Last Published
11 hours ago
Created
1 day ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform