Is my OrangeHRM account affected by Heartbleed?
OrangeHRM's SSL certificate end point was not vulnerable to the Heartbleed bug when it was publicly disclosed on April 7th 2014.
Any secure communication with our servers was not affected by any attacks following the public disclosure of the Heartbleed bug.
The Heartbleed bug has had a profound impact on the transmission of secure data through the Internet.
It is for that reason we are encouraging our customers to reset their passwords at their earliest convenience as a matter of common password maintenance.
Please remember to always make your passwords unique, random, and periodically rotate them.