The release includes tests, a useful README, MIT licensing, and release notes explaining its transition into Leaf core. Its small dependency set and inactive security tooling add little protection for a standalone dependency.
18%
Total Score
50
100
58
67
Packagist marks the package abandoned at package scope and names leafs/leaf as its replacement, indicating this release should not be adopted as an ongoing dependency.
There were no commits and no active maintainers in the last three months, reinforcing that standalone development has stopped.
The linked repository is archived, with the last push on October 2, 2024, so fixes and maintenance should not be expected there.
The package had 20 releases over nearly five years, but none in the last 12 months; this is consistent with the project's stated transition rather than active standalone maintenance.
The repository has no security policy, which is a transparency gap for reporting vulnerabilities, especially given that the project is no longer actively maintained.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
leafs/http Version * | — | — |
leafs/anchor Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.