Package Health

felixmuhoro/laravel-mpesa-donations

Its MIT license and small Composer dependency set reduce adoption friction. The project has only one release and a two-file source tree, with no tests, README, security policy, or recent development activity shown.

Latest v1.0.0PackagistPackagist

55%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

79

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Package file treecaution

Both the artifact and repository contain only composer.json and src/ServiceProvider.php, leaving little visible implementation or documentation to establish maturity.

Package scaffoldingcaution

The published artifact has no README, tests, or changelog, and the repository also reports no tests or changelog. The missing README reduces consumer transparency for a Laravel integration package.

Release historycaution

The package is 107 days old with only one release and no established release interval, so maintenance maturity is not yet demonstrated.

Repo issue activitycaution

The repository shows no issues or pull requests and no activity in the last month; combined with the single release, this provides little evidence of active maintenance.

Repo toolingcaution

Composer is used as the build tool, which fits the package ecosystem, but no security scanning tools are reported. This is a minor transparency gap rather than a severe risk.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Felix Muhoro

Direct Dependencies

DependencyLast ReleaseScore
illuminate/support
Version ^10.0|^11.0|^12.0|^13.0
—
—
felixmuhoro/laravel-mpesa
Version ^1.2
—
—

Weekly Downloads

Info

Last Published
3 months ago
Created
3 months ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform