Consumer documentation and independent maintenance evidence are limited. The repository is active and correctly named, but this release has only two source files, no tests, no security policy, and no follow-up releases after 111 days.
58%
Total Score
100
81
67
The artifact and repository each contain only composer.json and src/ServiceProvider.php, leaving very little visible implementation or project documentation.
The package has no README, tests, or changelog. Missing tests and changelog are normal for published artifacts, but the absent README reduces consumer transparency for a library.
This is the sole release, published 111 days ago, so there is little release history from which to judge sustained maintenance.
Composer is used for builds, but no repository security-scanning tool is configured, leaving a modest tooling gap.
The linked repository has no security policy, which is a transparency gap for a package handling payment-event integration.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version ^10.0|^11.0|^12.0|^13.0 | — | — |
felixmuhoro/laravel-mpesa Version ^1.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.