Maintenance status, plainly. TeamPass is actively developed. Version 3.2.1.7 shipped on 18 August 2026, with six releases in the three weeks before it, several of them security fixes for stored cross-site scripting and authorisation bypasses. That cuts both ways: an application receiving frequent security releases is one you have to keep updated. Its CVE history is real, including CVE-2024-50703, scored 9.3, where a user could act with another user's privileges, fixed in 3.1.3.1. None of that is unusual for a PHP application of this age. A vault just isn't a blog.
What it asks of the server. PHP 8.2 or newer with bcmath, gd, iconv, mbstring, mysqli, openssl and xml, plus an InnoDB database. All standard on our web hosting plans, with the PHP version selectable per package in the My365i control panel. The installer asks where to store its encryption key file, and the answer is always a directory above the web root.
Not for you if the vault would hold credentials whose loss would end the organisation, or if nobody owns the job of applying updates within days of release. Buy Bitwarden or 1Password instead. That's not a recommendation against ourselves, it's the honest answer.