How We Score Plugins
Every score is computed from four weighted dimensions using public GitHub and npm metadata. No human judgement, no paid placements.
Maintenance
30%Commit frequency, issue responsiveness, and release cadence over the last 90 days.
Docs
25%README completeness, dsh.bundle declaration presence, and usage examples.
npm
30%npm publishing, version stability, and install script safety.
Ecosystem
15%Stars, forks, and community activity around the repository.
Weight table
| Dimension | Weight | Data source | Scoring |
|---|---|---|---|
| Maintenance | 30% | GitHub API | Commit/issue/release recency |
| Docs | 25% | GitHub API | README & dsh.bundle checks |
| npm | 30% | npm registry | Publish history & install script scan |
| Ecosystem | 15% | GitHub API | Stars/forks normalized to log scale |
Grade legend
| Grade | Range | Description |
|---|---|---|
| A | 90–100 | Excellent |
| B | 75–89 | Good |
| C | 60–74 | Fair |
| D | <60 | Poor |
Dangerous install script rule
If a plugin install script matches any of curl|sh, /dev/tcp, base64 -d, iex, or powershell -enc, it is flagged as danger and its grade can never exceed D.
Patterns scanned: curl|sh · /dev/tcp · base64 -d · iex · powershell -enc
Transparency
Every number on this site is derived from public data. Scores are recomputed weekly; flags are re-scanned on every refresh.
Advertising policy
Sponsored slots and promos are clearly labeled and completely separate from scoring, rankings, and security ratings. No paid placement ever influences a score.