Healthy and reasonable to adopt, with some early-project caveats. It has an MIT license, tests, a matching organization-backed repository, and two active contributors, but it is only 42 days old and has limited security-process evidence.
78%
Total Score
100
100
81
90
The package is only 42 days old with four releases, so its maintenance record is still short; the recent releases do provide evidence of active initial development.
Composer build tooling is present, but no security-scanning tool was detected; this is a modest transparency gap rather than evidence that the package is unsafe.
The repository has no security policy, leaving vulnerability-reporting expectations undocumented for consumers and maintainers.
Version 0.1.54 is not on a stable major version, indicating that the public API may still change even though it is not marked as a prerelease.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/config Version ^7.0|^8.0 | — | — |
runopencode/intent Version ^0.1.54 | — | — |
symfony/http-kernel Version ^7.0|^8.0 | — | — |
symfony/doctrine-bridge Version ^7.0|^8.0 | — | — |
symfony/dependency-injection Version ^7.0|^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.