A b grade plugin is the one people pause on, and the pause usually comes from not knowing what the letter covers. Start with the b grade meaning: on the dsh plugin grade scale a B sits directly below A, which means the security checks passed and the points came off somewhere softer, usually documentation or release cadence. That is the whole plugin grade interpretation in one line. What a b grade plugin tells you is therefore narrow: it is not dangerous, and it is not flawless. Below is where the line actually sits, the two B grades that came out of our top-ten scan, and the four things worth checking before you install one.
Where B sits on the dsh plugin grade scale
The letter grades are a compressed reading of the 0-100 score, and the compression is where the confusion starts. The score page breaks the number into four bands, with 70-89 described as good with minor concerns. The letter version put OpenViking at B (82) and nocobase at B (78) in the top-ten scan, while the A grades in that same table ran from 84 to 92 and the single D came in at 45.
| Grade | Score seen in our scans | What it generally means |
|---|---|---|
| A | 84-92 | Passed security, documentation and maintenance both current |
| B | 78-82 | Passed security, minor gaps in documentation or release cadence |
| C | below the B band | Review the install script before proceeding |
| D | 45 in the top-ten scan | Dangerous install script, do not install without reading the source |
The gap between A and B is smaller than the letters suggest, and it is not a security gap. Both bands cleared the same checks.
What a B grade does tell you
Three things, and they are all worth knowing before you read anything else on the plugin page.
- The install script came back clean. That is the check that separates B from C and D, and it is the one that matters most.
- The points came off a soft pillar: documentation quality or maintenance activity, both of which are recoverable and neither of which is a risk on its own.
- The plugin is closer to the top of the ecosystem than to the bottom. In the top-ten scan, seven of ten were A and only one was D.
Read as a security signal, a B is closer to an A than to a C. The letters above and below it are the ones carrying risk information.
What a B grade does not tell you
This is where people get it wrong in both directions, and both mistakes are expensive.
- It says nothing about fit. A well-documented plugin that does half of what you need is still the wrong plugin.
- It says nothing about the trend. A B that was an A six months ago is a different situation from a B that has been flat. Score movement is covered in /blog/dsh-plugin-score-trends-what-a-dropping-score-means.
- It says nothing about permissions. Requesting broader file or network access than the job requires does not always move the grade as far as it should.
- It does not predict the future. A small plugin with one maintainer can be fine for two years and then stop entirely.
A grade is a snapshot of four pillars on one day. It is not a maintenance guarantee, and treating it as one is how teams end up surprised.
The two B grades from the top-ten scan
Concrete examples are easier to reason about than a definition. Both B grades in our scan of the ten highest-starred plugins failed the same soft pillar.
| Plugin | Score | Why it lost points | Install anyway? |
|---|---|---|---|
| OpenViking | B (82) | Minor documentation gaps | Yes, if the README covers what you need |
| nocobase | B (78) | Slightly stale last-push date | Yes, check the release cadence first |
Neither raised an alarm. Both would benefit from more frequent releases, and that is a different problem from being unsafe.
Before you install a b grade plugin
Four checks, in this order. They take about five minutes together and they are the same four you would run on an A grade, just with less margin for error.
- Read the install script yourself. The scanner cleared it, and you should still know what runs on your machine.
- Check the last publish date rather than the last commit. A repo can be busy while the published artifact is a year old.
- Compare the score to its own history rather than to the ecosystem. Direction beats position.
- Confirm the index name matches the source repo. The naming tricks that sit behind /blog/tag-baiting-problem have nothing to do with grade.
If all four come back clean, install it. If two come back wrong, the grade is not what should stop you.
FAQ
- Is a B grade safe to install? Usually yes. The security pillar cleared. What a B asks for is a quick look at documentation and release cadence, not a full audit.
- Should I wait for the plugin to reach an A? Only if the missing points are in something you depend on. A plugin you use through a narrow, stable API does not need a perfect README.
- Why not just install A grades only? Because the A band is small and the B band contains most of the plugins worth using. Filtering to A excludes working software.
- Does a B mean the maintainer is unreliable? No. It means the measurable activity signals were slightly weaker. One maintainer shipping on a slow schedule can still be dependable.
The scoring behind all four pillars is explained at /blog/dsh-quality-score-decoded, and the signals that sit outside any grade are listed at /blog/how-to-avoid-risky-dsh-plugins. The full plugin index, with current grades, is at /.