The dependency set is small and install-time scripts are absent. The repository is unarchived, but its single maintainer and minimal two-file tree provide limited evidence for long-term support.
58%
Total Score
50
100
81
75
One registry maintainer is consistent with a user-owned project, but it also indicates a thin publishing and support base.
Both the package and repository contain only composer.json and src/ServiceProvider.php, leaving very little visible implementation or project documentation to assess.
The package artifact has no README, tests, or changelog. Missing tests and changelog are normal for published artifacts, but missing consumer documentation is a real gap for a Laravel component package.
This package has only one release, published 113 days ago, so there is too little release history to demonstrate sustained maintenance.
Composer is used for builds, but no security scanning tooling is present. That is a modest transparency and maintenance gap rather than a severe risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version ^10.0|^11.0|^12.0|^13.0 | — | — |
felixmuhoro/laravel-mpesa Version ^1.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.