The stable major version and minimal runtime dependency surface are positive. However, the package has had no release or repository activity for over seven years, and its source repository is archived; the license files also disagree with the manifest.
8%
Total Score
50
100
42
100
Packagist marks the entire package as abandoned, with no replacement identified. This is a severe adoption risk even though the package is not merely withdrawing one release.
The latest release was published over seven years ago, with zero releases in the last 12 months. The seven-release history shows the package was once established, but not that it remains maintained.
The repository recorded zero commits and zero active maintainers in the last three months. This confirms the abandonment indicated by the archived repository and stale release history.
The linked Mastercard repository is archived and was last pushed over five years ago, indicating the source is no longer maintained. Organizational ownership does not compensate for an explicitly archived project.
The artifact contains a recognized Apache-2.0 license file while the manifest declares BSD-2-Clause. Both provide licensing information, but the mismatch creates avoidable legal uncertainty.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
mastercard/mastercard-api-core Version >=1.4.0 <1.5.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.