The MIT license and matching source repository help, but the package has only one release and a very small two-file tree. Documentation and repository security practices are limited, so pin this version until maintenance evidence grows.
60%
Total Score
81
50
Both the artifact and repository contain only composer.json and src/ServiceProvider.php. That may fit a small integration package, but it provides limited evidence of maturity and supporting project content.
The package has no README, while the absence of tests and a changelog is normal for published artifacts and is not itself a concern. Missing consumer documentation is a genuine transparency gap for a Laravel package.
The package is only 108 days old and has one release, leaving little evidence of sustained maintenance or release stability.
Composer build tooling is present, but no security scanning tooling is reported, leaving a modest repository-hygiene gap.
The linked repository has no security policy, reducing transparency about how vulnerabilities would be reported and handled.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version ^10.0|^11.0|^12.0|^13.0 | — | — |
felixmuhoro/laravel-mpesa Version ^1.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.