Package Health

bannerstop/keycloak

Framework-agnostic Keycloak / OpenID Connect client: login with PKCE, logout, token verification against JWKS, role mapping and the admin user directory

Latest v10.0.0PackagistPackagist

62%

Total Score

caution

A brand-new package with no demonstrated maintenance yet and four unpinned workflow actions merits caution.

Health Score Breakdown

Release historycaution

The package is 0 days old, with all 10 releases published on the same day and a median interval of 0 days, so it has not demonstrated sustained maintenance or release maturity.

Repo commit activitycaution

There were 0 commits and 0 active maintainers in the prior 3 months. Because the package and repository are only 0 days old, this is mainly a lack of demonstrated maintenance rather than evidence of a long-term collapse.

Repo toolingcaution

Composer build tooling is present, but no security scanning tools were detected. This is a modest transparency and assurance gap for a security-sensitive authentication client.

Workflow auditcaution

The workflow has read-only permissions, no untrusted checkouts, no script injection, and no audit findings. However, all 4 of 4 action references are unpinned, leaving workflow dependencies less reproducible and more exposed to upstream changes.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

bannerstop GmbH

Direct Dependencies

DependencyLast ReleaseScore
psr/clock
Version ^1.0
—
—
psr/http-client
Version ^1.0
—
—
psr/http-factory
Version ^1.1
—
—
psr/http-message
Version ^2.0
—
—
psr/simple-cache
Version ^2.0 || ^3.0
—
—

Weekly Downloads

Info

Last Published
4 hours ago
Created
4 hours ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform