DSH Quality

How We Score Plugins

Every score is computed from four weighted dimensions using public GitHub and npm metadata. No human judgement, no paid placements.

Maintenance

28%

Commit frequency, issue responsiveness, and release cadence over the last 90 days.

Docs

28%

README completeness, dsh.bundle declaration presence, and usage examples.

npm

24%

npm publishing, version stability, and install script safety.

Ecosystem

20%

Stars, forks, and community activity around the repository.

Weight table

DimensionWeightData sourceScoring
Maintenance
30%
GitHub APICommit/issue/release recency
Docs
25%
GitHub APIREADME & dsh.bundle checks
npm
30%
npm registryPublish history & install script scan
Ecosystem
15%
GitHub APIStars/forks normalized to log scale

Grade legend

GradeRangeDescription
A90–100Excellent
B75–89Good
C60–74Fair
D<60Poor

Dangerous install script rule

If a plugin install script matches any of curl|sh, /dev/tcp, base64 -d, iex, or powershell -enc, it is flagged as danger and its grade can never exceed D.

Patterns scanned: curl|sh · /dev/tcp · base64 -d · iex · powershell -enc

Transparency

Every number on this site is derived from public data. Scores are recomputed weekly; flags are re-scanned on every refresh.

Advertising policy

Sponsored slots and promos are clearly labeled and completely separate from scoring, rankings, and security ratings. No paid placement ever influences a score.