A simple dependency graph and no install-time scripts keep integration risk contained. The project is young and lightly supported, with limited documentation and no visible testing or security process, so future fixes may be uncertain.
58%
Total Score
50
100
78
67
Only one registry maintainer is listed, and the project backing is an individual account rather than an organization, so continuity depends heavily on one person.
The artifact and repository each contain only composer.json and src/ServiceProvider.php, leaving little visible project material for documentation, testing, or maintenance review.
The package has no README, tests, changelog, or release notes. Missing tests and changelog are normal for published artifacts, but the missing README is a real documentation gap for a Laravel integration library.
The registry namespace and repository owner match, which supports ownership continuity, but the owner is an individual rather than an organization and does not offset the thin maintainer base.
The package has only one release, published 106 days ago, so there is little release history to demonstrate sustained maintenance.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version ^10.0|^11.0|^12.0|^13.0 | — | — |
felixmuhoro/laravel-mpesa Version ^1.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.