Non-blocking cron scheduler with forked PHP workers
58%
Total Score
caution
A brand-new v0.1.0 package with rapid initial releases, no sustained commit history, and five unpinned workflow actions.
The package is less than one day old, with five releases arriving within roughly 21 hours. This shows active initial publishing but provides almost no evidence of sustained maintenance.
The repository uses Composer and Make for build tooling, but no security scanning tools were detected. This is a hygiene gap for a package with substantial runtime dependencies, not a severe risk by itself.
The repository has no security policy. For a new library this is a modest transparency and maintenance gap, though it is not evidence that the package is unsafe.
The assessed release is v0.1.0 and 80% of recent releases are prereleases, so the API and behavior are likely still changing. No stable-major release history compensates for that uncertainty.
The single workflow was fully analyzed with no dangerous triggers, injection sinks, or audit findings, and it has no top-level write permissions. However, all five action references are unpinned, leaving avoidable build-reproducibility and action-substitution risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^3.0 | — | — |
psr/clock Version ^1.0 | — | — |
symfony/yaml Version ^7.4 | — | — |
psr/container Version ^1.1 || ^2.0 | — | — |
symfony/console Version ^6.4 || ^7.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.