The dependency list is small, and the repository is not archived. There is no security policy or automated security scanning, making future maintenance harder to verify.
58%
Total Score
70
50
Both the package and repository contain only composer.json and src/ServiceProvider.php. This very small surface may be intentional, but it provides little evidence of documentation, tests, or implementation maturity.
The artifact has no README, tests, or changelog. Missing tests and changelog are normal for published artifacts, but the missing README is a real documentation gap for a Laravel integration package.
This is a young package with one release, published 108 days ago, so there is not enough release history to demonstrate sustained maintenance. Its recent initial release is less concerning than a long-abandoned mature package.
Composer is used for the build, which fits the ecosystem, but no security scanning tools are configured. That leaves dependency and source-health checks unverified.
The repository has no security policy. For a package handling M-Pesa processing, this reduces transparency about vulnerability reporting and maintenance response.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version ^10.0|^11.0|^12.0|^13.0 | — | — |
felixmuhoro/laravel-mpesa Version ^1.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.