Play back HLS and DASH with Video.js, even where it's not natively supported
68%
Total Score
caution
Usable with caveats: no commits in the last three months raises maintenance risk.
The release has no build attestation or trusted-publisher provenance. This weakens publication transparency, though it is not evidence that the package is unsafe by itself.
The artifact includes a license file and declares Apache-2.0, so the release is licensed. The detected text also includes BSD-2-Clause, creating a license-coverage mismatch that warrants checking.
The repository recorded 0 commits and 0 active maintainers in the last 3 months. That is a concrete recent-maintenance gap, although the recent release and push history provide some counterevidence.
There were no new or closed issues in the last month and no merged pull requests, with 190 issues still open. Combined with zero recent commits, this suggests limited current maintenance activity.
The project uses npm scripts, Rollup, and Babel, showing an established build process. It has no detected security-scanning tools, leaving a modest assurance gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
global Version ^4.4.0 | — | — |
mux.js Version 7.1.0 | — | — |
video.js Version ^7 || ^8 | — | — |
mpd-parser Version ^1.4.0 | — | — |
m3u8-parser Version ^7.2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.