The package is very small and offers little documentation or verification for a payment integration. Its MIT declaration, non-deprecated status, and matching source repository provide some reassurance, but maintenance depth remains unproven.
52%
Total Score
50
100
83
50
One registry maintainer is consistent with an independently owned package, but it leaves little demonstrated maintainer redundancy for a payment-related dependency.
The package and repository each contain only composer.json and src/ServiceProvider.php, indicating a minimal implementation with little surrounding documentation or verification material.
The artifact has no README, tests, or changelog. Missing tests and changelog are normal for published artifacts, but the missing README matters for a Laravel integration that consumers must configure and use.
This package has only one release over 108 days, so there is little evidence of an established release or maintenance cadence. Its young age partly explains the limited history, but does not establish ongoing support.
The linked repository has no security policy, leaving no documented channel or process for reporting vulnerabilities. This is a transparency gap, though not evidence of an active defect.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version ^10.0|^11.0|^12.0|^13.0 | — | — |
felixmuhoro/laravel-mpesa Version ^1.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.