DSH Quality

About DSH Quality

Why we built this

The DSH plugin ecosystem exploded — over 4,300 plugins in 3 days, yet only about 2% are high quality. With 216 tag-baiting projects capturing 23% of all stars and 4 high-severity vulnerabilities found within 45 hours, users had no independent way to tell what was worth installing.

What we do

We compute an independent health score from public GitHub and npm metadata, and surface security flags for risky install patterns. We never recommend and never install — we only measure.

Data sources

GitHub API and npm registry, refreshed weekly. Scores are heuristic estimates, not guarantees.

Limitations

Heuristic detection, not a substitute for code review. A clean flag does not mean a plugin is safe — always inspect the code you run.

Get involved

Questions or feedback? Open an issue on GitHub.

GitHub repository