The MIT declaration and absence of install scripts reduce avoidable adoption friction. A single release after 106 days, with no tests or consumer README, leaves maintenance and integration confidence limited.
55%
Total Score
50
100
81
67
Both the artifact and repository contain only composer.json and src/ServiceProvider.php, which is unusually minimal and provides limited evidence of project completeness.
The package contains no README, tests, changelog, or release notes, leaving consumers with little integration guidance and little evidence of verification for this Laravel library.
The package and repository are owned by the same individual account, which is coherent ownership but offers less visible organizational backing than a maintained team project.
This package has only one release, published 106 days ago, so there is not enough history to demonstrate sustained maintenance or release reliability.
Composer is used as the build tool, but no security scanning tooling is present. That is a modest transparency gap, not a severe adoption risk on its own.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version ^10.0|^11.0|^12.0|^13.0 | — | — |
felixmuhoro/laravel-mpesa Version ^1.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.