The MIT declaration and matching repository make its provenance clear. Zero stars and no security policy provide little evidence of broader review, while its tiny two-file tree limits confidence in maturity.
60%
Total Score
78
50
The artifact and repository each contain only composer.json and src/ServiceProvider.php, leaving little visible implementation or documentation to demonstrate maturity.
The package has no README, which makes a small integration library harder to adopt; absent tests and a changelog are normal for published artifacts and do not add a concern by themselves.
This package has only one release, published 107 days ago, so there is no established release track or demonstrated follow-up maintenance yet.
The repository has zero stars, forks, and watchers. Popularity is not required for a healthy small package, but these counters provide no supporting evidence of review or adoption.
Composer is used for the build, but no security scanning tool is present. For this very small package that is a modest transparency gap rather than a severe risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version ^10.0|^11.0|^12.0|^13.0 | — | — |
felixmuhoro/laravel-mpesa Version ^1.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.