The package is clearly identified, licensed, and backed by an organization, with a small runtime dependency set and security scanning. Its limited recent activity and missing security policy leave less evidence of ongoing maintenance.
68%
Total Score
67
100
100
83
All recent commits came from one contributor, giving the project a concentrated short-term bus factor. Organization backing partly offsets handoff risk, but no second active contributor is shown.
Only 1 commit from 1 active maintainer was recorded in the last 3 months. That demonstrates some recent maintenance but provides weak evidence of sustained activity.
No repository security policy was found. For an authentication and Keycloak integration package, this reduces disclosure transparency and is a genuine hygiene concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^6.5|^7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.