2026-W35

Published 2026-08-24

← All reports
11579
scanned
7
critical
863
need review
10475
low risk

Critical-risk plugins

7 plugins rated critical — vet-critical or blocking patterns (secrets / exfiltration / destructive / mining)

PluginRisk
dsh-plugin-security-review ★ 2Critical
dsh-prompt-templates ★ 3Critical
dsh-lmstudio-router ★ 0Critical
dsh-report-studio ★ 2Critical
DSH_VsCodeMode ★ 3Critical
dsh-themes ★ 2Critical
plugin-manager ★ 1Critical

Needs review (medium)

863 plugins rated medium — vet suspicious, or retired "high" hits like code execution / shell

PluginRisk
dsh-web-open ★ 0Medium
dsh-doctor ★ 2Medium
DeepSeek-Harness-Desktop ★ 7Medium
dsh-deepseek-web-adapter ★ 4Medium
dsh-flowglass ★ 12Medium
dsh-plugin-gate ★ 1Medium
MakoCode ★ 146Medium
dsh-vscode ★ 5Medium
dsh-raw-html ★ 16Medium
dsh-remote-access ★ 0Medium
dsh-witness ★ 1Medium
dsh-desktop-electron ★ 5Medium
DSH-Desktop ★ 0Medium
deepseek-harness-desktop ★ 2Medium
dsh-vision ★ 8Medium
crossplug ★ 1Medium
chromex-browser ★ 0Medium
dsh-shield ★ 1Medium
dsh-sim-restart ★ 0Medium
dsh-upgrade-kit ★ 1Medium

Showing the 20 most severe.

Automated heuristic scan — may produce false positives. Not a manual review, never an endorsement.

Weekly report archive

3 reports

What does this weekly report measure?

This report measures the automated static scan state of the dsh.so plugin registry during 2026-W35: the number of scanned plugins, the distribution across three tiers (low, medium, critical), and the plugins whose risk tier changed since the previous archive.

Why isn't this report an endorsement?

A report row reflects public repository metadata and heuristic rule matches, not a manual audit or runtime verification. False positives and false negatives are possible, so risk flags are a reason to inspect a plugin before install rather than a substitute for that inspection.

Source: dsh.so security standards · Maintained by dsh.so · Published

Was this page helpful?