DSH Quality

Trust in Open Source: The Plugin Middleman Problem

Reading the source tells you about the author. It tells you nothing about the registry, mirror, or install script between the author and your machine.

Open source trust has always rested on a simple idea: you can read the code, so you can decide for yourself. That idea holds when you install from the author. It gets weaker the moment a plugin distribution layer sits between the author and you, because what you install is no longer exactly what they published. Plugin distribution risk is mostly not about malicious authors. It is about the quiet intermediaries that repackage, mirror, cache, or re-score a plugin before it reaches your machine, and about how hard verifying plugin provenance becomes once they exist.

The trust chain you actually accept

Install one plugin and you accept a chain with at least four links.

LinkWho controls itWhat can differ from the source
Source repoThe authorNothing, this is the reference
Registry or indexPlatform operatorMetadata, tags, version ordering
Mirror or CDNHosting providerCached bytes, stale versions
Installer scriptPlugin or wrapper authorExtra downloads, post-install steps

Each link can be honest and still produce a result that does not match the repository you read. A cached tarball from last month is not malicious. It is also not the version whose changelog you just reviewed.

Where the middleman sits

The word covers several distinct roles, and they carry different risk.

  • Aggregator sites list plugins they do not maintain. Their value is discovery; their risk is that listing data goes stale and nobody owns correcting it.
  • Wrapper packages depend on the real plugin and add configuration. Convenient, but you now trust two maintainers instead of one.
  • Mirrors are set up for network or compliance reasons inside a company. Fast, and a silent source of version drift.
  • Install scripts fetched at install time rather than stored in the package. The package can be clean and the script can still do something else six months later.

Four failure modes that are not attacks

Most real-world trouble comes from neglect rather than malice.

  • Version drift: the index shows 2.4.1, the mirror serves 2.3.8, and your lockfile records something else. Nothing breaks loudly.
  • Abandoned wrappers: the upstream plugin is maintained, the wrapper has not been touched in two years and pins an old API.
  • Metadata inflation: tags and category placement are often written by whoever submitted the listing, not the author, so search results reflect marketing rather than function.
  • Install-time fetching: a plugin that downloads part of itself during install has a trust boundary you cannot review from the package contents.

What an intermediary can change without telling you

Three things specifically: which version you get, what metadata describes it, and what runs after the download finishes. None of these require write access to the author repository, which is why repository-level security work does not address them.

A signed commit proves the author published that commit. It does not prove the thing you installed was built from it.

Checking the chain in ten minutes

  • Compare the version in the index against the latest release in the source repository. If they disagree, find out why before installing.
  • Read the install script before running it, and prefer packages that ship the script rather than fetching it.
  • Look for a wrapper. If the name you install is not the name on the repository, you have added a maintainer.
  • Check the last publish date of the artifact, not the last commit of the repo.
  • Confirm the maintainer identity on the registry matches the one on the repository.

What independent scoring changes here

A score computed by the same party that distributes the plugin measures distribution, not trustworthiness. Independent scoring looks at the artifact rather than the listing: does the published version match the repository, is the install path inspectable, how long has the artifact been unchanged. That is why self-reported ratings drift upward over time while independent scores stay flat. The gap between them is itself a signal.

Pick the three plugins your setup depends on most and trace each link on dshquality.com. The scoring method behind this is explained at /blog/why-independent-plugin-scoring-beats-self-reported-ratings, and the full index is at /.

open source trustplugin distribution riskplugin middlemanplugin provenanceopen source trustplugin distribution riskplugin registry middlemanverifying plugin provenance