Package Health

bamboohr/api

Clear documentation, tests, changelog, and MIT licensing reduce adoption friction. Workflow references are unpinned and no security policy is published, so supply-chain hygiene is not perfect.

Latest 2.0.1PackagistPackagist

82%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

100

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Are you affected? Scan for Free

Health Score Breakdown

Lifecycle scriptscaution

The package runs post-install and post-update Composer scripts. These are not necessarily unsafe, but install-time behavior adds dependency and review surface for consumers.

Security policycaution

No repository security policy was found. That weakens vulnerability-reporting transparency, although the repository does use security scanning.

Workflow auditcaution

Both workflows were analyzed without failed files or high-confidence findings, and no untrusted checkout or script-injection paths were found. All seven action references are unpinned, which leaves workflow dependencies less reproducible and earns a modest caution.

Vulnerabilities

TitleVersionsSeverity
AIKIDO-2025-10901 Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
bamboohr/api is vulnerable to Generation of Error Message Containing Sensitive Information in versions 1.0.0 - 1.2.0.
1.0.0 - 1.2.0
Low

Package versions

Maintainers

BambooHR

Direct Dependencies

DependencyLast ReleaseScore
guzzlehttp/psr7
Version ^1.7 || ^2.0
—
—
guzzlehttp/guzzle
Version ^7.3
—
—
mustache/mustache
Version ^2.14
—
—

Weekly Downloads

Info

Last Published
9 months ago
Created
10 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform