The repository has no security policy, and its two-file source tree offers little evidence of testing or documentation. The package is not archived and has a stable release, but its maintenance maturity remains unproven.
55%
Total Score
50
78
50
One registry maintainer is consistent with a user-owned project, but it provides limited demonstrated publishing capacity and no broader maintainer redundancy.
Both the package and repository contain only composer.json and src/ServiceProvider.php, leaving little visible implementation, documentation, or maintenance structure to assess.
The published artifact has no README, tests, or changelog. Missing tests and changelogs are normal for published artifacts, but the absent README is a transparency and integration gap for a Laravel library.
Only one release exists, published 105 days ago, so there is not yet enough release history to demonstrate sustained maintenance. Its recent age partly limits how strongly this should count against the package.
The repository has zero stars, forks, and watchers. Popularity is only supporting evidence, but these counters provide no external adoption signal to offset the thin project history.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version ^10.0|^11.0|^12.0|^13.0 | — | — |
felixmuhoro/laravel-mpesa Version ^1.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.