Package Health

bannerstop/keycloak-bundle

Symfony integration of bannerstop/keycloak: Keycloak single sign-on, bearer tokens, role mapping and logout for the security component

Latest v10.2.0PackagistPackagist

72%

Total Score

caution

Strong project documentation and backing are offset by unpinned workflow actions and an unproven maintenance track record.

Health Score Breakdown

Release historycaution

release_history reports 40 releases, but all releases and the package age are recorded within the same day with a zero-day median interval, so this dataset does not establish a durable release history.

Repo commit activitycaution

repo_commit_activity reports zero commits and zero active maintainers in the last three months. The recent push recorded by repository_archived is encouraging, but it does not demonstrate sustained activity over time.

Repo popularitycaution

repo_popularity reports zero stars, forks, and watchers. This is weak supporting evidence, but the repository appears newly observed, so it does not independently indicate poor health.

Repo toolingcaution

repo_tooling confirms Composer build tooling, but reports no security scanning tools. That is a modest transparency and maintenance gap, not a severe risk by itself.

Workflow auditcaution

workflow_audit analyzed the single workflow completely, found read-only permissions and no untrusted checkout or injection sinks, but both of its two action references are unpinned. That weakens build reproducibility without indicating an active dangerous workflow.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

bannerstop GmbH

Direct Dependencies

DependencyLast ReleaseScore
symfony/config
Version ^7.4 || ^8.0
—
—
symfony/routing
Version ^7.4 || ^8.0
—
—
bannerstop/keycloak
Version ^10.0
—
—
symfony/http-kernel
Version ^7.4 || ^8.0
—
—
symfony/http-foundation
Version ^7.4 || ^8.0
—
—

Weekly Downloads

Info

Last Published
2 hours ago
Created
4 hours ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform