Package Health

felixmuhoro/laravel-mpesa-api

The MIT license and three declared runtime dependencies are straightforward, and the repository is not archived. There is no security scanning or security policy, so transparency remains limited.

Latest v1.0.0PackagistPackagist

57%

Total Score

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

79

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

75

Health Score Breakdown

Package file treecaution

The artifact and linked repository each contain only composer.json and src/ServiceProvider.php, indicating a very small implementation with limited visible project documentation or scaffolding. The narrow scope may explain the small tree, but it leaves maturity harder to verify.

Package scaffoldingcaution

The package has no README, while consumers of a Laravel library generally need installation and integration guidance. Missing tests and changelog files are normal for a published artifact and do not add concern here.

Release historycaution

This package has only one release, published 111 days ago, so there is little release history to demonstrate sustained maintenance. Its recent age avoids making this an abandonment finding on its own.

Repo toolingcaution

Composer is used for the build, which is appropriate, but no security-scanning tooling is present. This is a transparency and maintenance weakness rather than evidence that the package is unsafe.

Security policycaution

The linked repository has no security policy, reducing the documented path for reporting vulnerabilities. The small project size limits how severe this gap is.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Felix Muhoro

Direct Dependencies

DependencyLast ReleaseScore
illuminate/support
Version ^10.0|^11.0|^12.0|^13.0
—
—
felixmuhoro/laravel-mpesa
Version ^1.2
—
—

Weekly Downloads

Info

Last Published
3 months ago
Created
3 months ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform