Clear documentation, tests, changelog, and MIT licensing reduce adoption friction. Workflow references are unpinned and no security policy is published, so supply-chain hygiene is not perfect.
82%
Total Score
100
100
50
The package runs post-install and post-update Composer scripts. These are not necessarily unsafe, but install-time behavior adds dependency and review surface for consumers.
No repository security policy was found. That weakens vulnerability-reporting transparency, although the repository does use security scanning.
Both workflows were analyzed without failed files or high-confidence findings, and no untrusted checkout or script-injection paths were found. All seven action references are unpinned, which leaves workflow dependencies less reproducible and earns a modest caution.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2025-10901 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. bamboohr/api is vulnerable to Generation of Error Message Containing Sensitive Information in versions 1.0.0 - 1.2.0. | 1.0.0 - 1.2.0 | Low |
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/psr7 Version ^1.7 || ^2.0 | — | — |
guzzlehttp/guzzle Version ^7.3 | — | — |
mustache/mustache Version ^2.14 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.