2026-W35

Published 2026-08-29

← All reports
12371
scanned
11
critical
892
need review
11251
low risk

This week

Critical-risk plugins

11 plugins rated critical — vet-critical or blocking patterns (secrets / exfiltration / destructive / mining)

PluginRisk
dsh-plugin-security-review ★ 2Critical
dsh-qrcode-hassle-free ★ 2Critical
dsh-lmstudio-router ★ 0Critical
DSH-FormatForge ★ 10Critical
dsh-prompt-templates ★ 2Critical
DSH_VsCodeMode ★ 16Critical
dsh-report-studio ★ 2Critical
dsh-themes ★ 1Critical
plugin-manager ★ 1Critical
dsh-tool-plus ★ 8Critical
meww ★ 1Critical

Needs review (medium)

892 plugins rated medium — vet suspicious, or retired "high" hits like code execution / shell

PluginRisk
dsh-web-open ★ 0Medium
dsh-doctor ★ 6Medium
DeepSeek-Harness-Desktop ★ 6Medium
dsh-deepseek-web-adapter ★ 15Medium
dsh-flowglass ★ 24Medium
dsh-wallpaper-bridge ★ 2Medium
dsh-plugin-gate ★ 0Medium
MakoCode ★ 155Medium
dsh-vscode ★ 4Medium
dsh-remote-access ★ 0Medium
dsh-witness ★ 0Medium
dsh-pet-remielle ★ 51Medium
dsh-desktop-electron ★ 4Medium
dsh-vision ★ 7Medium
crossplug ★ 1Medium
dsh-reasonix-desktop ★ 1Medium
dsh-shield ★ 1Medium
dsh-sim-restart ★ 0Medium
DeepSeek-Harness-Desktop ★ 2Medium
dsh-raw-html ★ 76Medium

Showing the 20 most severe.

Automated heuristic scan (static analysis) — a scalable first line of defense; may produce false positives. Not a manual review.

Weekly report archive

9 reports

What does this weekly report measure?

This report measures the automated static scan state of the dsh.so plugin registry during 2026-W35: the number of scanned plugins, the distribution across three tiers (low, medium, critical), and the plugins whose risk tier changed since the previous archive.

Why isn't this report an endorsement?

A report row reflects public repository metadata and heuristic rule matches, not a manual audit or runtime verification. False positives and false negatives are possible, so risk flags are a reason to inspect a plugin before install rather than a substitute for that inspection.

Source: dsh.so security standards · Maintained by dsh.so · Published

Was this page helpful?