Open source trust has always rested on a simple idea: you can read the code, so you can decide for yourself. That idea holds when you install from the author. It gets weaker the moment a plugin distribution layer sits between the author and you, because what you install is no longer exactly what they published. Plugin distribution risk is mostly not about malicious authors. It is about the quiet intermediaries that repackage, mirror, cache, or re-score a plugin before it reaches your machine, and about how hard verifying plugin provenance becomes once they exist.
The trust chain you actually accept
Install one plugin and you accept a chain with at least four links.
| Link | Who controls it | What can differ from the source |
|---|---|---|
| Source repo | The author | Nothing, this is the reference |
| Registry or index | Platform operator | Metadata, tags, version ordering |
| Mirror or CDN | Hosting provider | Cached bytes, stale versions |
| Installer script | Plugin or wrapper author | Extra downloads, post-install steps |
Each link can be honest and still produce a result that does not match the repository you read. A cached tarball from last month is not malicious. It is also not the version whose changelog you just reviewed.
Where the middleman sits
The word covers several distinct roles, and they carry different risk.
- Aggregator sites list plugins they do not maintain. Their value is discovery; their risk is that listing data goes stale and nobody owns correcting it.
- Wrapper packages depend on the real plugin and add configuration. Convenient, but you now trust two maintainers instead of one.
- Mirrors are set up for network or compliance reasons inside a company. Fast, and a silent source of version drift.
- Install scripts fetched at install time rather than stored in the package. The package can be clean and the script can still do something else six months later.
Four failure modes that are not attacks
Most real-world trouble comes from neglect rather than malice.
- Version drift: the index shows 2.4.1, the mirror serves 2.3.8, and your lockfile records something else. Nothing breaks loudly.
- Abandoned wrappers: the upstream plugin is maintained, the wrapper has not been touched in two years and pins an old API.
- Metadata inflation: tags and category placement are often written by whoever submitted the listing, not the author, so search results reflect marketing rather than function.
- Install-time fetching: a plugin that downloads part of itself during install has a trust boundary you cannot review from the package contents.
What an intermediary can change without telling you
Three things specifically: which version you get, what metadata describes it, and what runs after the download finishes. None of these require write access to the author repository, which is why repository-level security work does not address them.
A signed commit proves the author published that commit. It does not prove the thing you installed was built from it.
Checking the chain in ten minutes
- Compare the version in the index against the latest release in the source repository. If they disagree, find out why before installing.
- Read the install script before running it, and prefer packages that ship the script rather than fetching it.
- Look for a wrapper. If the name you install is not the name on the repository, you have added a maintainer.
- Check the last publish date of the artifact, not the last commit of the repo.
- Confirm the maintainer identity on the registry matches the one on the repository.
What independent scoring changes here
A score computed by the same party that distributes the plugin measures distribution, not trustworthiness. Independent scoring looks at the artifact rather than the listing: does the published version match the repository, is the install path inspectable, how long has the artifact been unchanged. That is why self-reported ratings drift upward over time while independent scores stay flat. The gap between them is itself a signal.
Pick the three plugins your setup depends on most and trace each link on dshquality.com. The scoring method behind this is explained at /blog/why-independent-plugin-scoring-beats-self-reported-ratings, and the full index is at /.