Symfony integration of bannerstop/keycloak: Keycloak single sign-on, bearer tokens, role mapping and logout for the security component
72%
Total Score
caution
Strong project documentation and backing are offset by unpinned workflow actions and an unproven maintenance track record.
release_history reports 40 releases, but all releases and the package age are recorded within the same day with a zero-day median interval, so this dataset does not establish a durable release history.
repo_commit_activity reports zero commits and zero active maintainers in the last three months. The recent push recorded by repository_archived is encouraging, but it does not demonstrate sustained activity over time.
repo_popularity reports zero stars, forks, and watchers. This is weak supporting evidence, but the repository appears newly observed, so it does not independently indicate poor health.
repo_tooling confirms Composer build tooling, but reports no security scanning tools. That is a modest transparency and maintenance gap, not a severe risk by itself.
workflow_audit analyzed the single workflow completely, found read-only permissions and no untrusted checkout or injection sinks, but both of its two action references are unpinned. That weakens build reproducibility without indicating an active dangerous workflow.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/config Version ^7.4 || ^8.0 | — | — |
symfony/routing Version ^7.4 || ^8.0 | — | — |
bannerstop/keycloak Version ^10.0 | — | — |
symfony/http-kernel Version ^7.4 || ^8.0 | — | — |
symfony/http-foundation Version ^7.4 || ^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.