Security reports

We periodically re-scan the plugin ecosystem and record the changes: which plugins became critical or need review, which issues got fixed. Risk is shown across three tiers (low / medium / critical).

Latest report · 2026-W40

Published 2026-09-28

View report →
16418
scanned
0
critical
106
need review
16056
low risk
▲ new needing review: 1

Daily reports

Generated daily 01:10 Beijing (17:10 UTC) — security scan of newly added plugins

Latest daily · 2026-09-28

Security scan of newly added plugins

View report →
64 added0 critical2 medium

Full archive is at the bottom of the daily report page.

Archives

Full archives live at the bottom of each report page: the daily report page lists every past day, the weekly report page lists every past week.

What does the weekly security report measure?

The weekly report measures changes in the dsh.so plugin registry across automated security scans: how many plugins are scanned, how many are low, medium, or critical risk, and which plugins newly entered or cleared a critical or medium tier. It is a trend and triage tool, not a certification.

Why is this not an endorsement of the plugins listed?

Because the scans are static heuristics and can both miss context and produce false positives. dsh.so records publicly visible signals from each repository and makes them comparable, but the final decision to install a third-party plugin remains with the user.

Source: dsh.so security standards and public repository metadata · Maintained by dsh.so · Last updated

Was this page helpful?