The implementation is narrowly scoped and installation has no lifecycle hooks. The license and repository remain in place, but the project offers limited evidence of long-term care.
62%
Total Score
50
100
81
75
One registry maintainer is consistent with a user-owned project, but it provides a thin contributor base and limited redundancy if maintenance stops.
Both the published artifact and repository contain only composer.json and ServiceProvider.php. That may be appropriate for a small helper package, but leaves little visible project substance.
The artifact has no README, while tests and changelog absence are normal for published packages. Missing consumer documentation is a modest transparency and integration gap for a Laravel helper library.
The package is 108 days old with only one release, so there is not yet evidence of sustained maintenance or release continuity.
Composer is used for the build, but no security-scanning tool is present. This is a hygiene gap rather than evidence that the release is unsafe.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/support Version ^10.0|^11.0|^12.0|^13.0 | — | — |
felixmuhoro/laravel-mpesa Version ^1.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.