
Security News
The Hidden Blast Radius of the Axios Compromise
The Axios compromise shows how time-dependent dependency resolution makes exposure harder to detect and contain.
@modified/shaka-player
Advanced tools

Shaka Player is an open-source JavaScript library for adaptive media. It plays adaptive media formats (such as DASH and HLS) in a browser, without using plugins or Flash. Instead, Shaka Player uses the open web standards MediaSource Extensions and Encrypted Media Extensions.
Shaka Player also supports offline storage and playback of media using IndexedDB. Content can be stored on any browser. Storage of licenses depends on browser support.
Our main goal is to make it as easy as possible to stream adaptive bitrate video and audio using modern browser technologies. We try to keep the library light, simple, and free from third-party dependencies. Everything you need to build and deploy is in the sources.
For details on what's coming next, see our development roadmap.
| Browser | Windows | Mac | Linux | Android | iOS >= 12 | ChromeOS | Other |
|---|---|---|---|---|---|---|---|
| Chrome¹ | Y | Y | Y | Y | Native | Y | - |
| Firefox¹ | Y | Y | Y | untested⁵ | Native | - | - |
| Edge¹ | Y | - | - | - | - | - | - |
| IE ≤ 10 | N | - | - | - | - | - | - |
| IE 11 | Y ⁴ | - | - | - | - | - | - |
| Safari¹ | - | Y | - | - | iPadOS 13 Native | - | - |
| Opera¹ | untested⁵ | untested⁵ | untested⁵ | untested⁵ | Native | - | - |
| Chromecast² | - | - | - | - | - | - | Y |
| Tizen TV³ | - | - | - | - | - | - | Y |
NOTES:
We support iOS 12+ through Apple's native HLS player. We provide the same
top-level API, but we just set the video's src element to the manifest/media.
So we are dependent on the browser supporting the manifests.
We have another project called Shaka Player Embedded that offers the same features and similar APIs for native apps on iOS. This project uses its own media stack, which allows it to play content that would otherwise not be supported. This supports both DASH and HLS manifests.
| Format | Video On-Demand | Live | Event | In-Progress Recording |
|---|---|---|---|---|
| DASH | Y | Y | - | Y |
| HLS | Y | Y | Y | - |
You can also create a manifest parser plugin to support custom manifest formats.
DASH features supported:
DASH features not supported:
HLS features supported:
HLS features not supported:
| Browser | Widevine | PlayReady | FairPlay | ClearKey⁶ |
|---|---|---|---|---|
| Chrome¹ | Y | - | - | Y |
| Firefox² | Y | - | - | Y |
| Edge³ | - | Y | - | - |
| IE 11⁴ | - | Y | - | - |
| Safari | - | - | Y | - |
| Opera | untested⁵ | - | - | untested⁵ |
| Chromecast | Y | Y | - | untested⁵ |
| Tizen TV | Y | Y | - | untested⁵ |
Other DRM systems should work out of the box if they are interoperable and compliant to the EME spec.
NOTES:
Shaka Player supports:
Subtitles are rendered by the browser by default. Applications can create a text display plugin for customer rendering to go beyond browser-supported attributes.
For general help and before filing any bugs, please read the FAQ.
If you have improvements or fixes, we would love to have your contributions. Please read CONTRIBUTING.md for more information on the process we would like contributors to follow.
The Shaka team doesn't have the bandwidth and experience to provide guidance and support for integrating Shaka Player with specific frameworks, but some of our users have sucessfully done so and created tutorials to help other beginners.
Shaka + ReactJS integrations:
Shaka + Next.js integration:
If you have published Shaka Integration code/tutorials, please feel free to submit PRs to add them to this list, we will gladly approve!
FAQs
DASH/EME video player library
We found that @modified/shaka-player demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
The Axios compromise shows how time-dependent dependency resolution makes exposure harder to detect and contain.

Research
A supply chain attack on Axios introduced a malicious dependency, plain-crypto-js@4.2.1, published minutes earlier and absent from the project’s GitHub releases.

Research
Malicious versions of the Telnyx Python SDK on PyPI delivered credential-stealing malware via a multi-stage supply chain attack.