---
title: 13.03 Cron Jobs Reference
description: SimpleRisk uses 10 cron scripts under simplerisk/cron/ — a unified entry point (cron.php) plus 9 specialized scripts for notifications, backups, queue…
---

[Skip to content](https://support.simplerisk.com/kb/13-03-cron-jobs-reference#main-content)

English

Show submenu for translations

[Customer portal](https://support.simplerisk.com/tickets?hsLang=en)

[![SimpleRisk logo of a man walking a tight rope](https://support.simplerisk.com/hs-fs/hubfs/simplerisk_logo_long_small-4.png?width=377&height=72&name=simplerisk_logo_long_small-4.png)](https://www.simplerisk.com/)

Open main navigation

Close main navigation

- English
  
  Show submenu for translations
- [Customer portal](https://support.simplerisk.com/tickets)
- [Contact us](https://www.simplerisk.com/about-us/contact-us)

[Contact us](https://www.simplerisk.com/about-us/contact-us)

 How can we help you?

- There are no suggestions because the search field is empty.

1. [SimpleRisk Knowledge Base](https://support.simplerisk.com/kb?hsLang=en)
2. [Administrator Guide](https://support.simplerisk.com/kb/administrator-guide?hsLang=en)
3. [13 Reference](https://support.simplerisk.com/kb/administrator-guide?hsLang=en#13-reference)

# 13.03 Cron Jobs Reference

## SimpleRisk uses 10 cron scripts under simplerisk/cron/ — a unified entry point (cron.php) plus 9 specialized scripts for notifications, backups, queue processing, vulnerability management, assessments, and cleanup. Some run every few minutes, some hourly, some long-running. Compliance audit auto-initiation runs as a queue job rather than a dedicated script. This reference catalogs each script's purpose and expected schedule.

## Why this is a reference article

This article catalogs SimpleRisk's cron scripts. For the conceptual workflow of running cron, see [The Cron Jobs](https://support.simplerisk.com/kb/02-07-the-cron-jobs?hsLang=en). For troubleshooting cron-related issues, see [Troubleshooting Common Issues](https://support.simplerisk.com/kb/12-04-troubleshooting-common-issues?hsLang=en).

## Where the scripts live

All cron scripts are in `simplerisk/cron/`:

```
simplerisk/cron/
├── cron.php
├── cron_assessments.php
├── cron_backup.php
├── cron_notification.php
├── cron_promise_worker.php
├── cron_queue_loader.php
├── cron_queue_worker.php
├── cron_temporary_cleanup.php
├── cron_tfidf_recalculation.php
└── cron_vulnmgmt.php
```

10 scripts total. Each has a specific responsibility. `cron_audit.php`, which used to initiate compliance audit cycles, was retired — see [Cycle / lifecycle automation](https://support.simplerisk.com/kb/13-03-cron-jobs-reference#cycle--lifecycle-automation) below for where that work lives now.

## The orchestrator

### `cron.php`

The unified entry point. Designed to be invoked by system cron at a regular interval (typically every 5-10 minutes); it then calls the relevant child scripts based on their schedules.

For installs that prefer to invoke each script independently, the child scripts can be called directly from system cron entries.

**Typical schedule**: every 5-10 minutes via system cron.

## Notification and email

### `cron_notification.php`

Processes the queued notifications (the `notification_sent_log` and related queues). For each pending notification, dispatches via SMTP using the configured mail settings.

**Typical schedule**: every 5-15 minutes. Faster cadence reduces notification latency; slower cadence reduces SMTP load.

**Logs**: `notice` level for successful sends; `error` for SMTP failures.

**Failure mode**: queued notifications accumulate without sending; users notice missing email.

## Cycle / lifecycle automation

Compliance audit cycle initiation used to run here, as its own `cron_audit.php` script. It's now the `core_audit_initiate` queue job, processed by `cron_queue_worker.php` under Background work below — same hourly cadence, no separate cron entry to maintain.

### `cron_assessments.php`

Manages assessment cycles (Assessments Extra). Handles assessment dispatch, response collection, completion processing.

**Typical schedule**: hourly.

**Logs**: assessment-cycle events.

## Background work

### `cron_queue_worker.php`

The general-purpose background job worker. Picks up queued jobs (workflow executions, AI jobs, large data operations, compliance audit auto-initiation via the `core_audit_initiate` job) and processes them. Many installs run this continuously rather than on cron schedule; some invoke it from cron.

**Typical schedule**: continuous (long-running) or every 1-2 minutes from cron.

**Logs**: per-job pickup and execution; errors on job failure.

**Failure mode**: queued jobs accumulate; workflows don't fire; AI requests hang.

### `cron_queue_loader.php`

Loads jobs into the queue based on schedule triggers. The loader is what makes scheduled workflows fire — it scans for time-based triggers and queues the corresponding executions.

**Typical schedule**: every 1-5 minutes.

### `cron_promise_worker.php`

Processes promise-style asynchronous results. Specific to certain async patterns the application uses internally.

**Typical schedule**: continuous or every minute.

## Maintenance

### `cron_backup.php`

Performs scheduled database backups. Configurable in the SimpleRisk admin UI for backup frequency, destination, and retention.

**Typical schedule**: nightly.

**Logs**: `notice` for completed backups; `error` for backup failures.

**Failure mode**: backups stop; recovery from incidents becomes more painful.

### `cron_temporary_cleanup.php`

Cleans up temporary files, expired tokens, stale cache entries.

**Typical schedule**: hourly or daily.

**Logs**: `info` for routine cleanup; `notice` if substantial cleanup occurred.

### `cron_tfidf_recalculation.php`

Recalculates TF-IDF (term frequency / inverse document frequency) indices used by the search and recommendation features. The TF-IDF index becomes stale as documents and risks are added; periodic recalculation keeps search relevant.

**Typical schedule**: daily or weekly (it's expensive on large installs).

**Logs**: `notice` on completion.

### `cron_vulnmgmt.php`

Vulnerability Management Extra processing. Handles vulnerability ingestion, deduplication, risk creation from vulnerabilities.

**Typical schedule**: hourly or per ingestion source's cadence.

**Logs**: vulnerability processing events.

## Configuring the cron schedule

The cron schedule is typically configured in two places:

### System cron (Linux)

A `crontab` entry invokes `cron.php` (or specific child scripts):

```
# Every 5 minutes, run the SimpleRisk orchestrator
*/5 * * * * /usr/bin/php /var/www/simplerisk/cron/cron.php >> /var/log/simplerisk/cron.log 2>&1
```

For specific scripts:

```
# Notification processing every 5 minutes
*/5 * * * * /usr/bin/php /var/www/simplerisk/cron/cron_notification.php

# Backup nightly at 2 AM
0 2 * * * /usr/bin/php /var/www/simplerisk/cron/cron_backup.php

# TF-IDF weekly on Sunday at 3 AM
0 3 * * 0 /usr/bin/php /var/www/simplerisk/cron/cron_tfidf_recalculation.php
```

### Application-level scheduling

SimpleRisk's admin UI under Settings cog → Settings Hub → **Backups** tile (which also covers all cron-related schedules) configures the per-task interval expectations. The orchestrator (`cron.php`) reads these and decides which child scripts to run on each invocation.

For installs running the orchestrator pattern, the system cron just invokes `cron.php` frequently; the orchestrator handles per-task scheduling.

## Continuous workers

Some scripts are designed to run continuously rather than on cron schedule:

- **`cron_queue_worker.php`** — typically run as a long-running process via systemd, supervisord, or Docker container. Restarts on failure; processes jobs as they arrive.
- **`cron_promise_worker.php`** — same pattern.

For continuous workers, monitor process health (process running, memory growth, restart count); systemd's standard service management handles most of this.

## Verifying cron is working

```
# Check the cron history table
mysql -u simplerisk -p simplerisk -e "SELECT * FROM cron_history ORDER BY started_at DESC LIMIT 20;"

# Check the debug log for cron-related entries
mysql -u simplerisk -p simplerisk -e "SELECT timestamp, log_message FROM debug_log WHERE log_message LIKE '%cron%' ORDER BY timestamp DESC LIMIT 50;"

# Check the system cron is running (Linux)
systemctl status cron

# Check the SimpleRisk cron log file
tail -50 /var/log/simplerisk/cron.log
```

If `cron_history` shows no recent runs, the cron isn't actually running — check the system cron, the user invoking the cron, and the script's permissions.

## Common pitfalls

A handful of patterns recur with cron jobs.

- **Multi-server deployments running cron on every server.** Duplicate execution of notifications, AI jobs, backups. Pick one cron host.
- **Wrong cron schedule.** A 60-minute notification cron means notifications can be 60 minutes late. Match cadence to operational requirements.
- **Cron user lacks permissions.** The cron-user must be able to read/write the SimpleRisk directory and connect to the database.
- **PHP CLI version mismatch.** The web server may use PHP 8.3 while system cron defaults to PHP 7.4. Specify the PHP version explicitly: `/usr/bin/php8.3` instead of `/usr/bin/php`.
- **Long-running scripts conflicting with the cron schedule.** A `cron_backup.php` that runs for 90 minutes overlaps with the next nightly invocation. Use file locks or check for in-progress execution.
- **Not redirecting stdout/stderr.** Cron-failure output goes to email by default; without redirection, it spams the operator. `>> log_file 2>&1` solves this.
- **Not monitoring cron failures.** Silent cron failures produce silent feature degradation. Alert on `cron_history` gaps and `error`-level cron log entries.
- **Disabling cron during maintenance and forgetting to re-enable.** Backup jobs stop; notifications stop; queues fill. Restore the cron after maintenance.
- **Running `cron_queue_worker` from cron without locking.** Multiple instances racing for the same job. Use a single continuous worker or proper locking.

## Related

- [The Cron Jobs](https://support.simplerisk.com/kb/02-07-the-cron-jobs?hsLang=en)
- [Settings Reference](https://support.simplerisk.com/kb/13-01-config-settings-reference?hsLang=en)
- [Database Schema Overview](https://support.simplerisk.com/kb/13-02-database-schema-overview?hsLang=en)
- [Default Roles and Permissions](https://support.simplerisk.com/kb/13-04-default-roles-and-permissions?hsLang=en)
- [Known Limitations](https://support.simplerisk.com/kb/13-05-known-limitations?hsLang=en)
- [Monitoring SimpleRisk](https://support.simplerisk.com/kb/12-01-monitoring-simplerisk?hsLang=en)
- [Troubleshooting Common Issues](https://support.simplerisk.com/kb/12-04-troubleshooting-common-issues?hsLang=en)
- [Email and the Notification Extra](https://support.simplerisk.com/kb/07-02-email-and-the-notification-extra?hsLang=en)

- [FAQs](https://support.simplerisk.com/kb/faqs?hsLang=en)
- [SimpleRisk Extras](https://support.simplerisk.com/kb/simplerisk-extras?hsLang=en#main-content)

    - [Vulnerability Management Extra](https://support.simplerisk.com/kb/simplerisk-extras?hsLang=en#vulnerability-management-extra)
    - [Team Separation Extra](https://support.simplerisk.com/kb/simplerisk-extras?hsLang=en#team-separation-extra)
    - [Import-Export Extra](https://support.simplerisk.com/kb/simplerisk-extras?hsLang=en#import-export-extra)
- [Administrator Guide](https://support.simplerisk.com/kb/administrator-guide?hsLang=en#main-content)

    - [00 About This Guide](https://support.simplerisk.com/kb/administrator-guide?hsLang=en#00-about-this-guide)
    - [01 Installation and Deployment](https://support.simplerisk.com/kb/administrator-guide?hsLang=en#01-installation-and-deployment)
    - [02 Upgrades and Maintenance](https://support.simplerisk.com/kb/administrator-guide?hsLang=en#02-upgrades-and-maintenance)
    - [03 Users and Permissions](https://support.simplerisk.com/kb/administrator-guide?hsLang=en#03-users-and-permissions)
    - [04 Authentication](https://support.simplerisk.com/kb/administrator-guide?hsLang=en#04-authentication)
    - [05 Customization](https://support.simplerisk.com/kb/administrator-guide?hsLang=en#05-customization)
    - [06 Configuring Risk and Compliance](https://support.simplerisk.com/kb/administrator-guide?hsLang=en#06-configuring-risk-and-compliance)
    - [07 Integrations](https://support.simplerisk.com/kb/administrator-guide?hsLang=en#07-integrations)
    - [08 The API](https://support.simplerisk.com/kb/administrator-guide?hsLang=en#08-the-api)
    - [09 Encryption and Data Security](https://support.simplerisk.com/kb/administrator-guide?hsLang=en#09-encryption-and-data-security)
    - [10 Workflows and Automation](https://support.simplerisk.com/kb/administrator-guide?hsLang=en#10-workflows-and-automation)
    - [11 Reporting and Auditing](https://support.simplerisk.com/kb/administrator-guide?hsLang=en#11-reporting-and-auditing)
    - [12 Operations](https://support.simplerisk.com/kb/administrator-guide?hsLang=en#12-operations)
    - [13 Reference](https://support.simplerisk.com/kb/administrator-guide?hsLang=en#13-reference)
- [User Guide](https://support.simplerisk.com/kb/user-guide?hsLang=en#main-content)

    - [00 Foundations of GRC](https://support.simplerisk.com/kb/user-guide?hsLang=en#00-foundations-of-grc)
    - [01 Risk Management](https://support.simplerisk.com/kb/user-guide?hsLang=en#01-risk-management)
    - [02 Compliance Management](https://support.simplerisk.com/kb/user-guide?hsLang=en#02-compliance-management)
    - [03 Governance](https://support.simplerisk.com/kb/user-guide?hsLang=en#03-governance)
    - [04 Asset and Data Inventory](https://support.simplerisk.com/kb/user-guide?hsLang=en#04-asset-and-data-inventory)
    - [05 Threat and Vulnerability Management](https://support.simplerisk.com/kb/user-guide?hsLang=en#05-threat-and-vulnerability-management)
    - [06 Assessments](https://support.simplerisk.com/kb/user-guide?hsLang=en#06-assessments)
    - [07 Incident Management](https://support.simplerisk.com/kb/user-guide?hsLang=en#07-incident-management)
    - [08 Audit and Reporting](https://support.simplerisk.com/kb/user-guide?hsLang=en#08-audit-and-reporting)
    - [09 Day-to-Day SimpleRisk](https://support.simplerisk.com/kb/user-guide?hsLang=en#09-day-to-day-simplerisk)
    - [10 Continuous Improvement](https://support.simplerisk.com/kb/user-guide?hsLang=en#10-continuous-improvement)
- [SimpleRisk User Guides](https://support.simplerisk.com/kb/simplerisk-user-guides?hsLang=en)
- [Troubleshooting](https://support.simplerisk.com/kb/troubleshooting?hsLang=en)
- [SimpleRisk Hosted](https://support.simplerisk.com/kb/simplerisk-hosted?hsLang=en)
- [How To videos](https://support.simplerisk.com/kb/how-to-videos?hsLang=en)

[![favicon-1](https://support.simplerisk.com/hs-fs/hubfs/favicon-1.png?width=35&height=35&name=favicon-1.png "favicon-1")](https://www.simplerisk.com)

<https://www.facebook.com/simplerisk/> <https://www.twitter.com/simpleriskfree/> <https://www.linkedin.com/company/simplerisk/>

Copyright © 2026, SimpleRisk, Inc.