SDK for Superdesk Publisher Content Push and API
40%
Total Score
unhealthy
No releases since 2019 and no repository commits in over six years make this a strong abandonment risk.
The package has had 5 releases, but none in the last 12 months; its latest release was on November 4, 2019, more than six years ago. This is strong evidence of abandonment risk despite the short early release interval.
The repository recorded 0 commits and 0 active maintainers in the last 3 months, consistent with the package's long release gap. This leaves no recent evidence of ongoing maintenance.
Only one registry account has publish access, and the project is backed by an individual repository owner rather than an organization. This creates a thin publishing and continuity base, though it is supporting evidence rather than the main concern.
The artifact has no README, tests, or changelog, and the repository also reports no tests or changelog. Missing tests and changelog can be normal for published artifacts, but the absent README makes integration and consumer review harder for this SDK.
Composer is used for the build, but no security scanning tools are present. That weakens supply-chain hygiene evidence without proving the release is unsafe.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
hoa/mime Version ^3.0 | — | — |
ahs/ninjs-php Version ^v1.1 | — | — |
symfony/filesystem Version ^4.1 | — | — |
behat/transliterator Version ^1.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.