This is the dsh plugin digest september 2026 edition, the monthly plugin digest we assemble from what the scanner actually flagged over the month. Eleven entries went up in September, and this plugin ecosystem recap groups them the way a team would read them: comparisons that settle arguments, habits worth copying, scoring signals, and the september plugin security recap half, which is mercifully short because nothing dangerous turned up in the index.
September by the numbers
Small numbers, but they say something about where the work went. Everything below counts only what landed on the site between 2026-09-02 and 2026-09-21.
| Metric | September 2026 |
|---|---|
| Entries published | 11 |
| Comparison posts (DSH vs other ecosystems) | 3 |
| Team and pipeline posts | 3 |
| Scoring and signal posts | 3 |
| Care and hygiene posts | 2 |
| New grade changes in the index | none flagged |
The last row is the useful one. A month with no movement on grades means the dangerous findings list stayed empty, which is a better outcome than a busy month.
Three comparisons that settled arguments
September spent most of its energy answering questions of the form is this ecosystem safer than that one. All three reached the same conclusion in different words: the install command looks identical, the protection underneath does not.
- /blog/dsh-vs-vscode-extensions compared permission models and sandboxing. A VS Code extension runs in the editor process with full filesystem access; DSH plugins run isolated with limited access by default, which is why the same sloppy code does less damage here.
- /blog/dsh-vs-homebrew-ecosystem-risk looked at both ecosystems installing third-party code with one command, and where review actually happens in each.
- /blog/compare-two-dsh-plugins-side-by-side gave teams a five-factor framework with weights, so the deciding conversation stops being a gut call.
Team and pipeline habits
One person reading quickly does not scale. These three posts moved the same check from a personal habit to something the codebase enforces.
- /blog/setting-up-a-plugin-allowlist-for-your-dev-team turns review into three tiers so experimentation survives alongside default-deny.
- /blog/ci-cd-plugin-scanning wires the same checks into every commit, which matters because a plugin can rot after it passes review.
- /blog/how-to-update-dsh-plugins-without-breaking-your-setup lays out the pre-update check, snapshot, one-at-a-time update, and rollback.
Signals, scores, and what they leave out
Three posts looked at the parts of a plugin listing that people either over-trust or do not read at all.
- /blog/dsh-plugin-score-trends-what-a-dropping-score-means argues that the direction of a score matters more than its current value.
- /blog/tag-baiting-problem covers plugins that stuff their metadata with keywords they do not deliver, and how scoring reads around it.
- /blog/hidden-gem-dsh-plugins makes the case against top-ten lists: the safest plugin for your stack is often one nobody is talking about.
A plugin that scored 84 last quarter and 78 today is telling you something the current letter cannot. Direction is the part people skip.
Care, hygiene, and what to check in October
Two posts closed the month on maintenance, and both exist because configs fail quietly rather than loudly.
- /blog/backup-dsh-plugin-configuration covers surviving a bad update, a wiped machine, and a repo rename.
- /blog/how-to-evaluate-plugin-documentation-quality is a checklist for judging whether docs will still support you three months into production.
Your October list
- Pick one plugin you installed before September and re-run its score. Anything trending down goes on a watchlist.
- Add a plugin check step to CI before adding a second plugin to any project.
- Back up one config using the routine above, then test the restore once. An untested backup is a rumour.
- Subscribe at /weekly if you want next month to arrive instead of being something you remember in November.
The full index lives at dshquality.com, with every score and its method explained at /blog/dsh-quality-score-decoded. Grade interpretation is at /blog/what-a-b-grade-dsh-plugin-tells-you, the decline signals are at /blog/dsh-plugin-score-trends-what-a-dropping-score-means, and the low end of the index is browsable at /low-quality. Everything published sits at /blog.
FAQ
- How often does this monthly plugin digest come out? On the first business day after each month closes, pulling whatever the scanner flagged across the previous four weeks.
- What counts as a September entry? Anything published between 2026-09-02 and 2026-09-21 was written against September scanning data.
- Where do the scores come from? The same four pillars every month, described in full at /blog/dsh-quality-score-decoded so numbers stay comparable across editions.
- Nothing dangerous turned up this month. Should we relax? No. An empty findings list is what the checks are for, and it only stays empty while the checks run.