Package Health

passbolt/passbolt_api

Open source password manager for teams

Latest v5.16.0PackagistPackagist

91%

Total Score

healthy

Healthy release with active maintenance, strong project backing, and clear release documentation.

Are you affected? Scan for Free

Health Score Breakdown

Lifecycle scriptscaution

The package defines post-create-project-cmd and post-install-cmd Composer scripts, so installation performs additional actions beyond file extraction. This is a modest supply-chain and deployment-review concern, not evidence that the release is unfit.

Vulnerabilities

TitleVersionsSeverity
CVE-2024-33670
passbolt/passbolt_api is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 0.0.0 - 4.6.2.
0.0.0 - 4.6.2
Medium
CVE-2017-1000442
passbolt/passbolt_api is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 0.0.0 - 1.6.5.
0.0.0 - 1.6.5
Medium

Package versions

Maintainers

Passbolt Team

Direct Dependencies

DependencyLast ReleaseScore
ramsey/uuid
Version ^4.2.3
—
—
enygma/yubikey
Version ^3.8
—
—
cakephp/cakephp
Version ^5.4.1
—
—
imagine/imagine
Version ^1.5.1
—
—
firebase/php-jwt
Version ^7.0.0
—
—

Weekly Downloads

Info

Last Published
20 days ago
Created
10 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform