This release appears healthy and suitable for dependency consideration: it is a mature package first released over 11 years ago, has a recent stable release, an active and unarchived repository, substantial recent commit and pull-request activity, tests, a changelog, licensing, security scanning, and a security policy. The main concerns are a relatively slow release cadence, a large runtime dependency surface, a single registry publisher, and workflows that do not consistently declare top-level permissions. These are meaningful areas for review, but the strong repository activity and project hygiene substantially reduce abandonment and transparency risk.
88%
Total Score
90
50
94
90
The package declares 60 runtime dependencies and only 3 development dependencies. The broad runtime surface increases transitive maintenance and update exposure, although it is plausible for a full PHP password-management application.
Only one account, Nils Laumaillé, has registry publish access. This is a publishing concentration risk, but registry access does not measure development activity and the repository shows five active maintainers in the last three months.
The package has existed since September 2014 and has 11 releases, including two in the last 12 months, but its median release interval is about 371 days. The long history is positive, while the slow cadence warrants some caution for users needing frequent fixes or updates.
Two of three workflows lack top-level permissions declarations, although none declares top-level write permissions and one has read-only permissions. The absence of explicit defaults is a workflow-hardening gap, but the observed permissions do not show an excessive write configuration.
| Title | Versions | Severity |
|---|---|---|
CVE-2024-50703 nilsteampassnet/teampass is vulnerable to External Control of Assumed-Immutable Web Parameter in versions 0.0.0 - 3.1.3.1. | 0.0.0 - 3.1.3.1 | Medium |
CVE-2024-50702 nilsteampassnet/teampass is vulnerable to Incorrect Privilege Assignment in versions 0.0.0 - 3.1.3.1. | 0.0.0 - 3.1.3.1 | Medium |
CVE-2024-50701 nilsteampassnet/teampass is vulnerable to Incorrect Privilege Assignment in versions 0.0.0 - 3.1.3.1. | 0.0.0 - 3.1.3.1 | Medium |
CVE-2023-3565 nilsteampassnet/teampass is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 0.0.0 - 3.0.10. | 0.0.0 - 3.0.10 | Medium |
CVE-2023-3551 nilsteampassnet/teampass is vulnerable to Improper Control of Generation of Code ('Code Injection') in versions 0.0.0 - 3.0.10. | 0.0.0 - 3.0.10 | Critical |
| Dependency | Last Release | Score |
|---|---|---|
goodby/csv Version ^1.3 | — | — |
nesbot/carbon Version ^2.71 | — | — |
voku/anti-xss Version ^4.1 | — | — |
cboden/ratchet Version ^0.4.4 | — | — |
symfony/finder Version ^6.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.