Package Health

@videojs/http-streaming

Play back HLS and DASH with Video.js, even where it's not natively supported

Latest 3.17.5NPMNPM

68%

Total Score

caution

Usable with caveats: no commits in the last three months raises maintenance risk.

Health Score Breakdown

Build provenancecaution

The release has no build attestation or trusted-publisher provenance. This weakens publication transparency, though it is not evidence that the package is unsafe by itself.

Licensecaution

The artifact includes a license file and declares Apache-2.0, so the release is licensed. The detected text also includes BSD-2-Clause, creating a license-coverage mismatch that warrants checking.

Repo commit activitycaution

The repository recorded 0 commits and 0 active maintainers in the last 3 months. That is a concrete recent-maintenance gap, although the recent release and push history provide some counterevidence.

Repo issue activitycaution

There were no new or closed issues in the last month and no merged pull requests, with 190 issues still open. Combined with zero recent commits, this suggests limited current maintenance activity.

Repo toolingcaution

The project uses npm scripts, Rollup, and Babel, showing an established build process. It has no detected security-scanning tools, leaving a modest assurance gap.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Direct Dependencies

DependencyLast ReleaseScore
global
Version ^4.4.0
—
—
mux.js
Version 7.1.0
—
—
video.js
Version ^7 || ^8
—
—
mpd-parser
Version ^1.4.0
—
—
m3u8-parser
Version ^7.2.0
—
—

Weekly Downloads

Info

Last Published
3 months ago
Created
8 years ago
Unpacked Size
6.6 MB

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform