Package Health

1-0-0-1/laravel-keycloak-extended-guard

Usable with caveats: the repository is active enough to remain available and is not archived, but the package has had no registry release for over four years and no commits in the last three months. Its single-maintainer base, minimal adoption, and lack of security tooling increase maintenance risk.

Latest 1.3.0PackagistPackagist

52%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

33

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

69

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Release historydanger

The package has only three releases, all clustered in February 2022, with no release in the last 12 months despite being over four years old. This is a substantial freshness and maintenance concern.

Repo commit activitydanger

There were no commits and no active maintainers in the last three months, indicating that current maintenance has effectively stopped even though the repository is not archived.

Licensecaution

A proprietary license is declared in the manifest, so the release is licensed, but this is less transparent and may restrict use compared with a conventional open-source license.

Maintainerscaution

Only one registry account has publishing access. That is not itself a verdict, but it leaves little apparent publishing redundancy when combined with the lack of recent release activity.

Project backingcaution

The repository is owned by an individual user rather than an organization, so there is no visible organizational backing to compensate for the small maintainer base.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Alexey Shchetkin

Direct Dependencies

DependencyLast ReleaseScore
firebase/php-jwt
Version ^6.0
laravel/framework
Version ^8

Weekly Downloads

Info

Last Published
4 years ago
Created
4 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform