Stable versioning and no deprecation notice add confidence for adoption. The artifact has no runtime dependencies, and Maven PGP signing provides useful publication integrity; source and license checks remain incomplete.
88%
Total Score
100
100
100
100
All health scores are okay.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-201368 keycloak-services is vulnerable to Improper Access Control in versions 26.5.0 - 26.5.2. | 26.5.0 - 26.5.2 | High |
AIKIDO-2026-61094 keycloak-services is vulnerable to Information Disclosure in versions 26.0.0 - 26.7.1. | 26.0.0 - 26.7.1 | Medium |
AIKIDO-2026-410326 keycloak-services is vulnerable to Authorization Bypass in versions 26.2.0 - 26.7.1. | 26.2.0 - 26.7.1 | Medium |
AIKIDO-2026-609840 keycloak-services is vulnerable to Authorization Bypass in versions 26.2.0 - 26.7.1. | 26.2.0 - 26.7.1 | Medium |
AIKIDO-2026-89054 keycloak-services is vulnerable to Authentication Bypass in versions 26.0.0 - 26.7.1. | 26.0.0 - 26.7.1 | Critical |
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
org.keycloak:keycloak-core Version * | — | — |
jakarta.mail:jakarta.mail-api Version * | — | — |
org.eclipse.angus:angus-mail Version * | — | — |
org.keycloak:keycloak-common Version * | — | — |
org.twitter4j:twitter4j-core Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.