The package is licensed and has no deprecation, install scripts, or workflow findings. Its documentation and source footprint are very thin, while the single-release history leaves limited evidence of long-term maintenance.
52%
Total Score
75
50
Both the artifact and repository contain only composer.json and src/ServiceProvider.php, leaving little visible implementation or project documentation to establish maturity.
The package has no README, tests, or changelog. Missing tests and changelog are normal for published artifacts, but the absent README is a documentation gap for a Laravel integration package.
Only one release exists, published 105 days ago, so there is limited evidence of sustained maintenance; the package is still relatively young, which partly explains the short history.
Composer is used as the build tool, which fits the package ecosystem, but no security scanning tooling is present; this is a modest transparency gap rather than a severe risk.
The repository has no security policy. That weakens disclosure transparency for a package handling recurring payment integration, although it does not by itself show unsafe code.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version ^10.0|^11.0|^12.0|^13.0 | — | — |
felixmuhoro/laravel-mpesa Version ^1.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.