Native FFmpeg/FFI requirements and install-time hooks raise integration and upgrade friction. Tests, release notes, a security policy, and read-only workflow permissions provide useful safeguards despite the small public footprint.
64%
Total Score
100
50
88
75
Seven runtime dependencies include PHP FFI and native codec-related packages, creating meaningful environment and compatibility requirements beyond ordinary PHP libraries.
Composer pre-install-cmd and pre-update-cmd scripts add install and update-time behavior that consumers must understand and trust, increasing operational risk compared with a package without lifecycle hooks.
This is the package's only release, published about 16 months ago, with no releases in the last 12 months. That leaves maintenance and compatibility uncertain for a package with substantial native-library requirements.
Composer is used as a build tool, but no security scanning tools are reported. That is a transparency and maintenance gap, though it is not severe on its own.
The single workflow was fully analyzed, uses read-only permissions, and has no untrusted checkouts or injection findings. However, all 3 action references are unpinned, leaving avoidable build-reproducibility and action-update risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
quasarstream/av Version ^1.0 | — | — |
quasarstream/vpx Version ^1.0 | — | — |
quasarstream/opus Version ^1.0 | — | — |
quasarstream/exception Version ^1.0 | — | — |
quasarstream/rtp-parameter Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.