Plugin Install Ecosystem Report
Installs cleanly isn't the finish line — two of five installable plugins never reach the loader
Every dsh version that ran a real batch, on one ladder — 0.1.2-α.1 → 0.1.2-rc.1 → 0.1.3-α.1 → 0.1.3-α.2 → 0.1.5-rc.2. Runtime-verified by version: 5,536 → 6,247 → 6,444 → 7,171 → 7,799.
Every percentage in this volume is computed over 14,910 installable plugins — the 15,132 registry entries minus222 ecosystem apps (1.5%, kind:'app': desktop/web shells that bundle dsh and cannot be installed withdsh plugin add, so they carry no place in an install rate). Counts still include them, and every component is numbered, so the layers reconcile: 14,910 + 222 = 15,132.
- Install rates exclude ecosystem apps — all percentages are over installable plugins (14,910); the 222 ecosystem apps are counted in the registry total and shown separately, never in a rate.
- L5 wins — "runtime verified" requires a passing L5 (web boot · HTTP · loader inventory); L4 alone means installed, not running.
- Version-scoped and frozen — a verdict is valid only for the dsh version it was measured on; every figure here was derived once at publish and never re-aggregated, so newer records cannot move it.
- Gray is not broken — unknown = installed but declaring no dsh.bundle: dsh installs it as a plain dependency and does not mount it. Neither a pass nor a failure.
A Verdicts per dsh versionstack height = tested plugins
B L4 installed vs L5 runsdecided pass rate · current 0.1.5-rc.2
C Registry mix · 0.1.5-rc.2rate base 14,910 of 15,132
D From installable to running · 0.1.5-rc.2one denominator throughout
Every bar uses the same 14,910 denominator, so the rows reconcile: 14,908 tested + 2 untested = 14,910; of the tested, 7,799 run · 3,964 are unmounted · 3,145 fail. The L4 column is a separate funnel (see chart F): 14,123 of 14,910 install cleanly in the sandbox, and 7,799 of those also pass the web runtime gate.
E The ecosystem accountverified per release
+628 runtime-verified plugins versus the version Vol.2 closed on (0.1.3-α.2); +1,355 (+21%) versus the version Vol.1 closed on (0.1.3-α.1). Same-version comparison: earlier volumes published different registry denominators, so their headline shares are not directly comparable with this volume's.
F Install ladder L1 → L5 · 0.1.5-rc.2bar = pass rate
L1–L3 are version-independent static checks (denominator: 14,908 entries). L4/L5 count real verdicts on 0.1.5-rc.2 only and share the 14,910 installable denominator; older-version verdicts are listed separately and never counted (L4 0 · L5 129).
G Channel duel · 0.1.5-rc.2delta 25.7%pp
H Runtime failure profile · 0.1.5-rc.2records verbatim
I What this volume actually saysreading the same numbers
01 What the numbers say
An editorial read, not a second data source: every claim below points at a figure already shown above, and nothing new is introduced here.
Two out of five installable plugins never reach the loader
Of 14,910 installable plugins, 14,123 complete a clean sandbox install (94.7%) — but only 7,799 (52.3%) pass the L5 runtime gate and appear active in the loader inventory. 3,964 (26.6%) install as plain dependencies and declare no dsh.bundle; 3,145 (21.1%) actually fail. "Installed" and "runs" differ by 42.4% on this batch.
Scope. Install rate = L5-wins verdicts on 0.1.5-rc.2 over installable plugins only (14,910 = 15,132 registry entries minus 222 ecosystem apps, which cannot be installed with dsh plugin add). Limitation. A plain dependency is not a broken plugin: dsh installs it and simply does not mount it as a plugin. Only 3,145 of 14,908 tested plugins record an actual failure.
Coverage is complete — the loss moved into two verdicts
14,908 of 14,910 installable plugins carry a real verdict on 0.1.5-rc.2 (99.99% coverage, 2 never tested). The gap is no longer reach: it is 3,145 failures + 3,964 unmounted plain dependencies = 7,109 plugins that do not run.
Scope. The 0.1.5-rc.2 batch is a full-registry L5 sweep; the 14,908 tested plugins are accounted for as 7,799 running, 3,145 failed and 3,964 unmounted. Limitation. Untested is not failing — and here untested is 2. Coverage is a property of the verification queue, not of ecosystem quality.
The install floor held while the current version moved four times
L4 install pass rate, version by version: 99% → 99.2% → 99.2% → 99.2% → 99.2% across 0.1.2-α.1 → 0.1.2-rc.1 → 0.1.3-α.1 → 0.1.3-α.2 → 0.1.5-rc.2. The floor barely moves between 0.1.2-alpha.1 and 0.1.5-rc.2; what moves is how much of the registry has been re-tested on the newest version.
Scope. L4 rate = passed / (passed + failed) inside each version, so the untested remainder never flatters it. Same numbers as chart B. Limitation. A high install rate is not a quality score: it says the artifact was fetchable and its dependency graph resolved in a sandbox — nothing about what the plugin does.
The channel gap is packaging discipline, not breakage
npm-pinned installs verify at 73.1% versus 47.4% for source installs (25.7%pp gap). Failure rates are close (18.6% npm vs 21.7% source) — the real split is the gray bucket: 30.9% of source installs declare no dsh.bundle versus 8.4% of npm ones.
Scope. Channel is the winning record's evidence.parsed.channel, with a same-version fallback; the "other" bucket is empty in this window. Limitation. Declaring dsh.bundle is a packaging choice, not a quality score: an unmounted dependency is not a broken plugin.
Runtime failure is still one shape, with a small tail behind it
3,145 failures = 109 sandbox install failures (L4) + 3,036 web-runtime failures (L5). 2,752 of the runtime failures (90.6%) carry the identical record text "plugin tree failed to load" on check L5.2_WEB_BOOT_READY; the remaining 284 spread over 7 other recorded forms.
Scope. Buckets are the failing check's own summary text, verbatim; nothing is reclassified or renamed into a taxonomy. Limitation. One shared shape points at a common gate or cause, not at 3,036 independent plugin defects — this is a symptom tally, not a root-cause analysis.
02 Methodology
- Install-rate scope (new in Vol.3): every percentage uses 14,910 installable plugins as its denominator — the 15,132 registry entries minus 222 ecosystem apps (
kind:'app': desktop/web shells that bundle dsh and cannot be installed withdsh plugin add, and therefore never enter the L1–L5 ladder). Registry counts and the composition chart still include them, so the two layers reconcile. The excluded id set is recorded in the frozen snapshot (ratioScope), not recomputed at render time. - Verdict rule (L5 wins): newest real L5 verdict per version wins; no L5 → newest L4. Only an L5 pass counts as "runtime verified".
- State layers (record layer unchanged): Failed = install/boot/HTTP failure. Gray = installed but no dsh.bundle — dsh installs it as a plain dependency, unmounted as a plugin (the web runtime gate does not apply). The record layer calls it unknown (neither pass nor fail); this report names it by its semantics, never as failure.
- Failure profile: the current version's failed verdicts split into L4 sandbox install failures and L5 web-runtime failures; the latter are bucketed by the failing check's own summary text (check id when a record carries no summary). No taxonomy is invented over the records.
- Window / version scope: the window is every dsh version that ran a real batch — 0.1.2-alpha.1 → 0.1.2-rc.1 → 0.1.3-alpha.1 → 0.1.3-alpha.2 → 0.1.5-rc.2 — derived from the records at publish and then pinned inside the snapshot. 0.1.5-rc.1 carries records but no batch (one evening's partial run), so it sits with 0.1.1-rc.2 as an older-version record set that never enters the window. A verdict holds only for the version it was tested on.
- Frozen at publish: this volume's figures were derived once, on the publish build, and written to
install-vol3-data.json. Later builds read that file only: new records, new registry entries and new dsh releases cannot move a published volume. Vol.1 and Vol.2 keep the figures they were published with.
Q Why are the percentages not shares of the whole registry?
Because 222 registry entries are ecosystem apps, not plugins: they cannot be installed with dsh plugin add and never enter the L1–L5 ladder. Counting them in an install rate would answer a question nobody asked — "what fraction of everything we list installs" instead of "what fraction of installable plugins installs and runs". They are still counted in the registry total, broken out by id in the snapshot, and shown in the composition chart.
Q Is "installed" (L4) the same as "runtime verified"?
No. L4 means the sandbox install completed; L5 means the web runtime boots, serves HTTP and lists the plugin in the loader inventory. Only an L5 pass counts as runtime-verified — on 0.1.5-rc.2, 14,123 plugins install and 7,799 run.
Q Why does the window start at 0.1.2-alpha.1?
Because that is the first dsh version with a real run record. 0.1.1-rc.2 has L4-only batch records and no L5 run at all, so it is not a version anything was "run on" and stays out of the window — as does version-less history.
03 More
- Where a number comes from: every figure is derived once from 14,908 scoped verification records and frozen into the volume snapshot. Per plugin: GET /data/install/<id>.json.
- Live view: /verification/ applies the same verdict rule to the current dsh version and refreshes every build.
- Earlier volumes: Vol.1 (0.1.2-alpha.1 → 0.1.3-alpha.1) and Vol.2 (0.1.2-alpha.1 → 0.1.3-alpha.2), kept as published.
- Independence: dsh.so is an independent project, not affiliated with DeepSeek; a verdict is an observation over sandbox records, never an endorsement.
Q How should I read 3,145 failures?
As two different events. 109 never installed in the sandbox; 3,036 installed but failed the web runtime gate — 90.6% of them with the identical recorded text "plugin tree failed to load". Treat that as a shared gate symptom, not 3,036 independent plugin quality verdicts.
Q Is a runtime-verified plugin a safe plugin?
No — verification and security are independent axes. Runtime verification says the plugin installs and runs; it says nothing about what it does. Security is reported separately on each plugin page.
Q What changed since Vol.2?
Two things. The window gained 0.1.5-rc.2, a full-registry sweep — 0.1.5-rc.1 is deliberately not a window version: its runs are one evening's partial batch, so its records stay on file without a column — and the install-rate scope changed: ecosystem apps no longer enter any percentage. Of the 15,132 registry entries, 222 are apps (1.5%); all rates here are computed over the remaining 14,910.
Cite this report
dsh.so — DeepSeek Harness Plugin Install Ecosystem Report, Vol.3 (published 2026-09-15). Window: 0.1.2-alpha.1 -> 0.1.2-rc.1 -> 0.1.3-alpha.1 -> 0.1.3-alpha.2 -> 0.1.5-rc.2 · verification batch started 2026-09-11 12:47:29 (UTC+8) Scope: install rates are computed over 14,910 installable plugins (15,132 registry entries minus 222 ecosystem apps). Runtime verified (L5) 7,799 (52.3%) · installed (L4) 14,123 (94.7%) · failed 3,145 (21.1%) · plain deps 3,964 (26.6%) https://dsh.so/reports/install-vol3/