generated: '2026-08-13'
method: searched
source:
- https://registry.npmjs.org/@getcello/cello-react-native
- https://repo1.maven.org/maven2/so/cello/android/cello-sdk/maven-metadata.xml
- https://trunk.cocoapods.org/api/v1/pods/CelloSDK
- https://pub.dev/api/packages/cello_sdk
- https://github.com/getcello
- https://docs.cello.so/sdk/introduction
note: >-
First-party Cello client libraries. Every mobile SDK is published to a real registry — npm for
React Native, Maven Central for Android, CocoaPods and Swift Package Manager for iOS, pub.dev for
Flutter — which a previous round missed. The two web SDKs (Cello JS and Attribution JS) are not
registry packages: they load from the assets.cello.so CDN at an unpinned /latest/ path, so a
consumer cannot pin or identify a version.
currency_summary: >-
The Android SDK is the release train: so.cello.android:cello-sdk shipped 0.14.0 on 2026-08-07,
and getcello/cello-ios-sp carries a matching 0.14.0 Swift Package tag. Two distributions of the
same SDK have fallen behind that train — the CocoaPods pod CelloSDK is still 0.9.0 from
2025-09-08 (five minor releases and eleven months stale), and the npm React Native wrapper is
0.13.0 from 2026-04-25 while its repo already tags v0.14.0-rc.0. The Flutter plugin is a single
0.0.1 release from 2025-12-16 and is labelled Beta in the docs. Cello's own Android install
snippet still pins 0.9.1 (2025-09-09), five releases behind what it publishes.
packages:
- language: kotlin
registry: maven-central
name: so.cello.android:cello-sdk
version: 0.14.0
published: '2026-08-07'
url: https://repo1.maven.org/maven2/so/cello/android/cello-sdk/
source: https://github.com/getcello/cello-android
install: 'implementation("so.cello.android:cello-sdk:0.14.0")'
official: true
release_count: 24
first_published: '2024-04-23'
note: >-
The most current Cello distribution. Cello's own install snippet at
https://docs.cello.so/sdk/mobile/android still pins 0.9.1 (published 2025-09-09) — five minor
releases behind the artifact Cello ships.
- language: swift
registry: swift-package-manager
name: cello-ios-sp
version: 0.14.0
published: null
url: https://github.com/getcello/cello-ios-sp
install: 'Add https://github.com/getcello/cello-ios-sp as a Swift Package dependency'
official: true
version_source: git tag (git ls-remote --tags), tags 0.1.0 through 0.14.0
note: >-
Swift Package Manager has no registry metadata endpoint, so the version is read from the repo
tags and the publish date is unavailable without the GitHub API (rate-limited at probe time);
recorded as null rather than guessed. Tag 0.14.0 matches the Maven Central release, so the SPM
channel is current.
- language: swift
registry: cocoapods
name: CelloSDK
version: 0.9.0
published: '2025-09-08'
url: https://cocoapods.org/pods/CelloSDK
install: "pod 'CelloSDK'"
official: true
release_count: 24
note: >-
STALE. The pod trunk's newest version is 0.9.0 from 2025-09-08, while the same iOS SDK is at
0.14.0 on Swift Package Manager and the Android twin shipped 0.14.0 on 2026-08-07. An iOS
developer following Cello's CocoaPods option gets an eleven-month-old build; the Swift Package
Manager option gets current code. Cello documents both without noting the difference.
- language: typescript
registry: npm
name: '@getcello/cello-react-native'
version: 0.13.0
published: '2026-04-25'
url: https://www.npmjs.com/package/@getcello/cello-react-native
source: https://github.com/getcello/cello-react-native
install: 'npm install @getcello/cello-react-native'
official: true
release_count: 45
first_published: '2024-04-27'
note: >-
React Native wrapper bridging the iOS and Android SDKs. One minor release behind the native
SDKs; the repo already carries a v0.14.0-rc.0 tag that has not been published to npm.
- language: dart
registry: pub.dev
name: cello_sdk
version: 0.0.1
published: '2025-12-16'
url: https://pub.dev/packages/cello_sdk
install: 'flutter pub add cello_sdk'
official: true
release_count: 1
status: beta
note: >-
Flutter plugin wrapper for the Cello iOS and Android SDKs. Marked Beta in Cello's docs, and
the registry confirms it: one release, 0.0.1, unchanged since 2025-12-16.
- language: javascript
registry: cdn
name: cello.js
version: null
published: null
url: https://assets.cello.so/app/latest/cello.js
sandbox_url: https://assets.sandbox.cello.so/app/latest/cello.js
install: ''
official: true
last_modified: '2026-08-12'
http_status: 200
bytes: 456493
note: >-
Cello JS, the embeddable Referral Component. Distribution is an UNPINNED CDN path — /latest/
floats, there is no versioned URL and no registry metadata endpoint, so neither we nor a
consumer can tell which build is being served. The only currency signal is the Last-Modified
header, 2026-08-12, which shows the bundle is actively shipping. version recorded as null
because there is nothing to read, not because it was not checked.
- language: javascript
registry: cdn
name: cello-attribution.js
version: null
published: null
url: https://assets.cello.so/attribution/latest/cello-attribution.js
sandbox_url: https://assets.sandbox.cello.so/attribution/latest/cello-attribution.js
install: ''
official: true
last_modified: '2026-08-12'
http_status: 200
bytes: 55587
note: >-
Attribution JS, the referral-code capture library. Same unpinned /latest/ CDN distribution as
cello.js — no version to read, Last-Modified 2026-08-12. See findings: Cello's own published
Agent Skill hands agents a different filename for this file, and that filename 403s.
findings:
- id: agent-skill-serves-a-403-script-url
severity: high
detail: >-
Cello's published Agent Skill at
https://docs.cello.so/.well-known/agent-skills/cello/skill.md tells agents to install
Attribution JS from https://assets.cello.so/attribution/latest/attribution.js (and the sandbox
equivalent). That URL returns 403. The working file, and the one Cello's human docs use at
https://docs.cello.so/sdk/client-side/embedded-script-tag, is cello-attribution.js. An agent
following Cello's own machine-readable skill writes a broken script tag.
evidence:
- url: https://assets.cello.so/attribution/latest/attribution.js
status: 403
- url: https://assets.cello.so/attribution/latest/cello-attribution.js
status: 200
- id: cocoapods-channel-abandoned
severity: medium
detail: >-
CelloSDK on CocoaPods last shipped 0.9.0 on 2025-09-08; the same SDK is 0.14.0 on Swift Package
Manager and Maven Central. Cello documents CocoaPods as install Option 1 for iOS, ahead of
Swift Package Manager, with no note that the pod is behind.
evidence:
- url: https://trunk.cocoapods.org/api/v1/pods/CelloSDK
status: 200
- id: install-snippet-behind-published-artifact
severity: low
detail: >-
The Android install snippet pins so.cello.android:cello-sdk:0.9.1 (2025-09-09) while Maven
Central serves 0.14.0 (2026-08-07).
evidence:
- url: https://docs.cello.so/sdk/mobile/android
status: 200
- url: https://repo1.maven.org/maven2/so/cello/android/cello-sdk/maven-metadata.xml
status: 200
- id: no-server-side-sdk
severity: info
detail: >-
Cello ships no server-side SDK in any language — no npm, PyPI, Maven, NuGet, Go, RubyGems,
Packagist or crates.io package wraps the REST API. Every first-party library is a client-side
or mobile referral component. Server integration is raw HTTP against api.cello.so.
x-evidence:
fetched: '2026-08-13'