Security reports
We periodically re-scan the plugin ecosystem and record the changes: which plugins became critical or need review, which issues got fixed. Risk is shown across three tiers (low / medium / critical).
Latest report · 2026-W40
Published 2026-09-28
Daily reports
Generated daily 01:10 Beijing (17:10 UTC) — security scan of newly added pluginsLatest daily · 2026-09-28
Security scan of newly added plugins
Full archive is at the bottom of the daily report page.
Archives
Full archives live at the bottom of each report page: the daily report page lists every past day, the weekly report page lists every past week.
What does the weekly security report measure?
The weekly report measures changes in the dsh.so plugin registry across automated security scans: how many plugins are scanned, how many are low, medium, or critical risk, and which plugins newly entered or cleared a critical or medium tier. It is a trend and triage tool, not a certification.
Why is this not an endorsement of the plugins listed?
Because the scans are static heuristics and can both miss context and produce false positives. dsh.so records publicly visible signals from each repository and makes them comparable, but the final decision to install a third-party plugin remains with the user.
Source: dsh.so security standards and public repository metadata · Maintained by dsh.so · Last updated