Plugin Install Ecosystem Report

Installs cleanly isn't the finish line — two of five installable plugins never reach the loader

Runtime verified (L5)Installed only (L4)FailedPlain dep (unmounted)
Vol.3 published 2026-09-15Frozen 0.1.5-rc.2 · 5 dsh versionsVerification batch 2026-09-11 12:47:29 (UTC+8)

Every dsh version that ran a real batch, on one ladder — 0.1.2-α.1 → 0.1.2-rc.1 → 0.1.3-α.1 → 0.1.3-α.2 → 0.1.5-rc.2. Runtime-verified by version: 5,536 → 6,247 → 6,444 → 7,171 → 7,799.

Install-rate scope

Every percentage in this volume is computed over 14,910 installable plugins — the 15,132 registry entries minus222 ecosystem apps (1.5%, kind:'app': desktop/web shells that bundle dsh and cannot be installed withdsh plugin add, so they carry no place in an install rate). Counts still include them, and every component is numbered, so the layers reconcile: 14,910 + 222 = 15,132.

At a glance
The queue is done — the loss is in the verdicts14,908 of 14,910 installable plugins carry a real verdict on 0.1.5-rc.2 (99.99%); 2 were never tested.
Unmounted is the biggest single bucket3,964 plugins install cleanly yet declare no dsh.bundle, so dsh never mounts them; 3,145 actually fail.
Failure is still one shape3,036 runtime failures — 2,752 of them (90.6%) record the same text on the same check.
15,132
Registry entries
14,910 installable + 222 ecosystem apps
7,799
Runtime verified · L5
52.3% of installable plugins
14,123
Installed · L4
94.7% of installable plugins
3,964
Plain deps (unmounted)
26.6% · no dsh.bundle
3,145
Failed
runtime 3,036 · install 109
7,109
Not runtime-verified
failed 3,145 + plain deps 3,964
14,910
Install-rate denominator
apps excluded · 99.99% tested
How to read this
  1. Install rates exclude ecosystem apps — all percentages are over installable plugins (14,910); the 222 ecosystem apps are counted in the registry total and shown separately, never in a rate.
  2. L5 wins — "runtime verified" requires a passing L5 (web boot · HTTP · loader inventory); L4 alone means installed, not running.
  3. Version-scoped and frozen — a verdict is valid only for the dsh version it was measured on; every figure here was derived once at publish and never re-aggregated, so newer records cannot move it.
  4. Gray is not broken — unknown = installed but declaring no dsh.bundle: dsh installs it as a plain dependency and does not mount it. Neither a pass nor a failure.

A Verdicts per dsh versionstack height = tested plugins

0.1.2-α.1
5,536
2,477
4,003
516
runs 5,536 · tested 12,532 · 08-28
0.1.2-rc.1
6,247
2,943
2,938
707
runs 6,247 · tested 12,835 · 09-03
0.1.3-α.1
6,444
2,999
2,929
717
runs 6,444 · tested 13,089 · 09-04
0.1.3-α.2
7,171
3,190
3,215
705
runs 7,171 · tested 14,281 · 09-07
0.1.5-rc.2
7,799
3,145
3,288
676
runs 7,799 · tested 14,908 · 09-10

B L4 installed vs L5 runsdecided pass rate · current 0.1.5-rc.2

99%L4installed
70%L5runs
0.1.2-α.1
99.2%L4installed
68.7%L5runs
0.1.2-rc.1
99.2%L4installed
69%L5runs
0.1.3-α.1
99.2%L4installed
69.9%L5runs
0.1.3-α.2
99.2%L4installed
72%L5runs
0.1.5-rc.2

C Registry mix · 0.1.5-rc.2rate base 14,910 of 15,132

14,910
installable
Runtime verified (L5)7,799Failed3,145Plain dependency (no dsh.bundle)3,964Not tested2Ecosystem apps (excluded from install rates)222Install rates use the 14,910 installable plugins only; the 222 ecosystem apps are shown for reconciliation (14,910 + 222 = 15,132). Not tested among installable: 2 · 99.99% coverage.

D From installable to running · 0.1.5-rc.2one denominator throughout

Installable pluginsregistry minus apps14,910 · 100%
Carry a real verdictcoverage on 0.1.5-rc.214,908 · 99.99%
Install cleanly, then runL4 pass → L5 pass7,799 · 52.3%
Install but never mountplain dependency3,964 · 26.6%
Fail an install or run gateL4/L5 failure3,145 · 21.1%
Never testedno verdict on 0.1.5-rc.22 · 0%

Every bar uses the same 14,910 denominator, so the rows reconcile: 14,908 tested + 2 untested = 14,910; of the tested, 7,799 run · 3,964 are unmounted · 3,145 fail. The L4 column is a separate funnel (see chart F): 14,123 of 14,910 install cleanly in the sandbox, and 7,799 of those also pass the web runtime gate.

E The ecosystem accountverified per release

7,799installable plugins pass L5 on 0.1.5-rc.2 — 52.3% of 14,910, 52.3% of those tested
Vol.1 closed0.1.3-α.1α.1 on that version6,444
Vol.2 closed0.1.3-α.2α.2 on that version7,171
This volume0.1.5-rc.2rc.2, full-registry sweep7,799

+628 runtime-verified plugins versus the version Vol.2 closed on (0.1.3-α.2); +1,355 (+21%) versus the version Vol.1 closed on (0.1.3-α.1). Same-version comparison: earlier volumes published different registry denominators, so their headline shares are not directly comparable with this volume's.

F Install ladder L1 → L5 · 0.1.5-rc.2bar = pass rate

L1 Foundrepo reachable · README14,625 · 98.1%
L2 Structuredmanifest valid & complete14,101 · 94.6%
L3 Install specparseable install command14,619 · 98.1%
L4 Install testedinstalls cleanly in sandbox14,123 · 94.7%
L5 Runtime verifiedweb boots · HTTP · inventory active7,799 · 52.8%

L1–L3 are version-independent static checks (denominator: 14,908 entries). L4/L5 count real verdicts on 0.1.5-rc.2 only and share the 14,910 installable denominator; older-version verdicts are listed separately and never counted (L4 0 · L5 129).

G Channel duel · 0.1.5-rc.2delta 25.7%pp

npm · pinned tarball2,860 tested
73.1%18.6%8.4%
verified 2,090 · failed 531 · plain dep 239
source · tag / commit12,048 tested · 80.8% of verdicts
47.4%21.7%30.9%
verified 5,709 · failed 2,614 · plain dep 3,725
The gap is packaging, not breakage: failure rates sit close together, but 30.9% of source installs declare no dsh.bundle versus 8.4% of npm ones. other channel: 0.

H Runtime failure profile · 0.1.5-rc.2records verbatim

109install failed · L43,036runtime failed · L521.1%of installable plugins fail one of the two gates
plugin tree failed to load2,752
boot failed113
L5.4_PLUGIN_INVENTORY_ACTIVE70
duplicate loader entry id49
L5.3_HTTP_SERVED39
other recorded forms (3)13
buckets = the failing check's own recorded text; the head form is 90.6% of runtime failures, the other 284 spread over 7 recorded forms

I What this volume actually saysreading the same numbers

Installing stopped being the questionL4 has held at 94.7% of installable plugins on 0.1.5-rc.2, and the coverage is complete: 2 untested. The install path works; the mounting path is what splits the ecosystem.
Unmounted, not broken (3,964)These install and simply declare no dsh.bundle, so dsh treats them as plain dependencies. Calling them failures would overstate the damage by 55.8% of the non-running bucket.
Failures cluster on one gate (3,145)3,036 of them are web-runtime failures, 90.6% of those with the identical recorded text — a shared gate symptom rather than thousands of independent plugin defects.
The verified set grew with the registry (7,799)+628 versus the version Vol.2 closed on. Shares move slowly because the numerator and the registry grow together — the count is the honest signal.

01 What the numbers say

An editorial read, not a second data source: every claim below points at a figure already shown above, and nothing new is introduced here.

Two out of five installable plugins never reach the loader

Of 14,910 installable plugins, 14,123 complete a clean sandbox install (94.7%) — but only 7,799 (52.3%) pass the L5 runtime gate and appear active in the loader inventory. 3,964 (26.6%) install as plain dependencies and declare no dsh.bundle; 3,145 (21.1%) actually fail. "Installed" and "runs" differ by 42.4% on this batch.

Scope. Install rate = L5-wins verdicts on 0.1.5-rc.2 over installable plugins only (14,910 = 15,132 registry entries minus 222 ecosystem apps, which cannot be installed with dsh plugin add). Limitation. A plain dependency is not a broken plugin: dsh installs it and simply does not mount it as a plugin. Only 3,145 of 14,908 tested plugins record an actual failure.

Coverage is complete — the loss moved into two verdicts

14,908 of 14,910 installable plugins carry a real verdict on 0.1.5-rc.2 (99.99% coverage, 2 never tested). The gap is no longer reach: it is 3,145 failures + 3,964 unmounted plain dependencies = 7,109 plugins that do not run.

Scope. The 0.1.5-rc.2 batch is a full-registry L5 sweep; the 14,908 tested plugins are accounted for as 7,799 running, 3,145 failed and 3,964 unmounted. Limitation. Untested is not failing — and here untested is 2. Coverage is a property of the verification queue, not of ecosystem quality.

The install floor held while the current version moved four times

L4 install pass rate, version by version: 99% → 99.2% → 99.2% → 99.2% → 99.2% across 0.1.2-α.1 → 0.1.2-rc.1 → 0.1.3-α.1 → 0.1.3-α.2 → 0.1.5-rc.2. The floor barely moves between 0.1.2-alpha.1 and 0.1.5-rc.2; what moves is how much of the registry has been re-tested on the newest version.

Scope. L4 rate = passed / (passed + failed) inside each version, so the untested remainder never flatters it. Same numbers as chart B. Limitation. A high install rate is not a quality score: it says the artifact was fetchable and its dependency graph resolved in a sandbox — nothing about what the plugin does.

The channel gap is packaging discipline, not breakage

npm-pinned installs verify at 73.1% versus 47.4% for source installs (25.7%pp gap). Failure rates are close (18.6% npm vs 21.7% source) — the real split is the gray bucket: 30.9% of source installs declare no dsh.bundle versus 8.4% of npm ones.

Scope. Channel is the winning record's evidence.parsed.channel, with a same-version fallback; the "other" bucket is empty in this window. Limitation. Declaring dsh.bundle is a packaging choice, not a quality score: an unmounted dependency is not a broken plugin.

Runtime failure is still one shape, with a small tail behind it

3,145 failures = 109 sandbox install failures (L4) + 3,036 web-runtime failures (L5). 2,752 of the runtime failures (90.6%) carry the identical record text "plugin tree failed to load" on check L5.2_WEB_BOOT_READY; the remaining 284 spread over 7 other recorded forms.

Scope. Buckets are the failing check's own summary text, verbatim; nothing is reclassified or renamed into a taxonomy. Limitation. One shared shape points at a common gate or cause, not at 3,036 independent plugin defects — this is a symptom tally, not a root-cause analysis.

02 Methodology

Q Why are the percentages not shares of the whole registry?

Because 222 registry entries are ecosystem apps, not plugins: they cannot be installed with dsh plugin add and never enter the L1–L5 ladder. Counting them in an install rate would answer a question nobody asked — "what fraction of everything we list installs" instead of "what fraction of installable plugins installs and runs". They are still counted in the registry total, broken out by id in the snapshot, and shown in the composition chart.

Q Is "installed" (L4) the same as "runtime verified"?

No. L4 means the sandbox install completed; L5 means the web runtime boots, serves HTTP and lists the plugin in the loader inventory. Only an L5 pass counts as runtime-verified — on 0.1.5-rc.2, 14,123 plugins install and 7,799 run.

Q Why does the window start at 0.1.2-alpha.1?

Because that is the first dsh version with a real run record. 0.1.1-rc.2 has L4-only batch records and no L5 run at all, so it is not a version anything was "run on" and stays out of the window — as does version-less history.

03 More

Q How should I read 3,145 failures?

As two different events. 109 never installed in the sandbox; 3,036 installed but failed the web runtime gate — 90.6% of them with the identical recorded text "plugin tree failed to load". Treat that as a shared gate symptom, not 3,036 independent plugin quality verdicts.

Q Is a runtime-verified plugin a safe plugin?

No — verification and security are independent axes. Runtime verification says the plugin installs and runs; it says nothing about what it does. Security is reported separately on each plugin page.

Q What changed since Vol.2?

Two things. The window gained 0.1.5-rc.2, a full-registry sweep — 0.1.5-rc.1 is deliberately not a window version: its runs are one evening's partial batch, so its records stay on file without a column — and the install-rate scope changed: ecosystem apps no longer enter any percentage. Of the 15,132 registry entries, 222 are apps (1.5%); all rates here are computed over the remaining 14,910.

Cite this report

dsh.so — DeepSeek Harness Plugin Install Ecosystem Report, Vol.3 (published 2026-09-15).
Window: 0.1.2-alpha.1 -> 0.1.2-rc.1 -> 0.1.3-alpha.1 -> 0.1.3-alpha.2 -> 0.1.5-rc.2 · verification batch started 2026-09-11 12:47:29 (UTC+8)
Scope: install rates are computed over 14,910 installable plugins (15,132 registry entries minus 222 ecosystem apps).
Runtime verified (L5) 7,799 (52.3%) · installed (L4) 14,123 (94.7%) · failed 3,145 (21.1%) · plain deps 3,964 (26.6%)
https://dsh.so/reports/install-vol3/

Share

Post on X
Was this page helpful?