It has clear documentation, tests, a changelog, and a small runtime dependency set. Choose an actively maintained Keycloak provider rather than adopting this release.
15%
Total Score
0
100
50
88
Packagist marks the entire package as abandoned, with no replacement specified. This is a severe adoption risk because future maintenance is not expected.
The package has 8 releases overall but none in the last 12 months; its latest release was on December 19, 2023. The long gap is consistent with the archived and abandoned status.
The repository recorded 0 commits and 0 active maintainers in the last 3 months. This reinforces the abandonment signal rather than showing merely slow development.
The linked repository is archived, and its last push was on December 19, 2023. Archived source is a strong indication that the package is no longer maintained.
The repository has no security policy. This is a transparency and vulnerability-reporting gap, although the stronger abandonment signals already determine the overall assessment.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
firebase/php-jwt Version ^4.0 || ^5.0 | — | — |
league/oauth2-client Version ^2.0 <2.3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.