The MIT license and three declared runtime dependencies are straightforward, and the repository is not archived. There is no security scanning or security policy, so transparency remains limited.
57%
Total Score
100
79
75
The artifact and linked repository each contain only composer.json and src/ServiceProvider.php, indicating a very small implementation with limited visible project documentation or scaffolding. The narrow scope may explain the small tree, but it leaves maturity harder to verify.
The package has no README, while consumers of a Laravel library generally need installation and integration guidance. Missing tests and changelog files are normal for a published artifact and do not add concern here.
This package has only one release, published 111 days ago, so there is little release history to demonstrate sustained maintenance. Its recent age avoids making this an abandonment finding on its own.
Composer is used for the build, which is appropriate, but no security-scanning tooling is present. This is a transparency and maintenance weakness rather than evidence that the package is unsafe.
The linked repository has no security policy, reducing the documented path for reporting vulnerabilities. The small project size limits how severe this gap is.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version ^10.0|^11.0|^12.0|^13.0 | — | — |
felixmuhoro/laravel-mpesa Version ^1.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.