keycloak.org scored 62/100, meeting baseline requirements but with 3 findings that require attention. The vendor can proceed with a remediation timeline agreement.
Critical gaps in: HSTS Header, Security Headers, DMARC / Email Security. Positive signals: MX Records & Mail Provider, TLS Configuration, TLS Protocol Support all passed.
4 action items identified, including 1 critical. The issues are configuration gaps, not architectural problems. A focused remediation effort of 2–5 days could address all findings.
Grade distribution across 2445 companies we've scanned. keycloak.org scores better than 25% of them.
Each check inspects a different part of keycloak.org's public security setup. Green means healthy, yellow needs attention, red is a problem.
Steps to improve keycloak.org's security grade, ranked by impact.
Key data points from the scan.