Package Health

nilsteampassnet/teampass

This release appears healthy and suitable for dependency consideration: it is a mature package first released over 11 years ago, has a recent stable release, an active and unarchived repository, substantial recent commit and pull-request activity, tests, a changelog, licensing, security scanning, and a security policy. The main concerns are a relatively slow release cadence, a large runtime dependency surface, a single registry publisher, and workflows that do not consistently declare top-level permissions. These are meaningful areas for review, but the strong repository activity and project hygiene substantially reduce abandonment and transparency risk.

Latest 3.2.2.0PackagistPackagist

88%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

90

Dependencies
Dependencies
Evaluates the health and security of package dependencies

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

90

Are you affected? Scan for Free

Health Score Breakdown

Dependency profilecaution

The package declares 60 runtime dependencies and only 3 development dependencies. The broad runtime surface increases transitive maintenance and update exposure, although it is plausible for a full PHP password-management application.

Maintainerscaution

Only one account, Nils Laumaillé, has registry publish access. This is a publishing concentration risk, but registry access does not measure development activity and the repository shows five active maintainers in the last three months.

Release historycaution

The package has existed since September 2014 and has 11 releases, including two in the last 12 months, but its median release interval is about 371 days. The long history is positive, while the slow cadence warrants some caution for users needing frequent fixes or updates.

Token permissionscaution

Two of three workflows lack top-level permissions declarations, although none declares top-level write permissions and one has read-only permissions. The absence of explicit defaults is a workflow-hardening gap, but the observed permissions do not show an excessive write configuration.

Vulnerabilities

TitleVersionsSeverity
CVE-2024-50703
nilsteampassnet/teampass is vulnerable to External Control of Assumed-Immutable Web Parameter in versions 0.0.0 - 3.1.3.1.
0.0.0 - 3.1.3.1
Medium
CVE-2024-50702
nilsteampassnet/teampass is vulnerable to Incorrect Privilege Assignment in versions 0.0.0 - 3.1.3.1.
0.0.0 - 3.1.3.1
Medium
CVE-2024-50701
nilsteampassnet/teampass is vulnerable to Incorrect Privilege Assignment in versions 0.0.0 - 3.1.3.1.
0.0.0 - 3.1.3.1
Medium
CVE-2023-3565
nilsteampassnet/teampass is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 0.0.0 - 3.0.10.
0.0.0 - 3.0.10
Medium
CVE-2023-3551
nilsteampassnet/teampass is vulnerable to Improper Control of Generation of Code ('Code Injection') in versions 0.0.0 - 3.0.10.
0.0.0 - 3.0.10
Critical

Package versions

Maintainers

Nils Laumaillé

Direct Dependencies

DependencyLast ReleaseScore
goodby/csv
Version ^1.3
nesbot/carbon
Version ^2.71
voku/anti-xss
Version ^4.1
cboden/ratchet
Version ^0.4.4
symfony/finder
Version ^6.3

Weekly Downloads

Info

Last Published
1 month ago
Created
12 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform