Evidence Score

Source provenance25 points
Install documentation25 points
Maintenance evidence20 points
Compatibility evidence20 points
Security evidence10 points

The score summarizes how much reviewable evidence is available. It does not mean a plugin is “86% compatible” and does not award points for tests the registry has not run.

Compatibility confidence

MediumExact DSH version or maintainer test evidence documented
LimitedProfile or platform claims exist without an exact current version
UnknownNo reliable compatibility claim collected

Registry install verified and Runtime verified are independent states. The disposable-profile install runner is connected in source; a count changes only after a schema-validated result is committed. Profile boot and capability smoke tests remain a stronger, separate layer.

Evidence freshness

FreshThe exact cell is still inside its published 168-hour recheck window
StaleThe recheck deadline passed; the old result remains visible but is no longer current
ExpiredA second refresh window passed without a new observation
UnobservedNo executable artifact cell exists for this repository and environment

Freshness never changes the historical result. It changes whether that result is safe to use as current upgrade evidence.

Manifest-aware classification

Native DSH BundleRoot package.json declares dsh.bundle and the referenced patch file exists.
Integration or bridgeDSH-specific behavior exists without a root native bundle manifest.
Topic onlyThe topic alone is not treated as proof that a repository is an installable plugin.

How the discovery number is counted

The 16,529 figure comes from one reproducible GitHub Search query, run daily and committed to this repository so any reading can be replayed.

Querytopic:dsh-plugin
SourceGitHub Search API, total_count
CadenceDaily, committed to the public snapshot
Records with a pinned commit12 of 12

The GitHub Topic web page and the Search API do not agree on a total for the same topic, and the gap moves in both directions as indexing catches up. Rather than pick whichever number looks better, this registry publishes the query, the source, and the date, so the figure can be checked against GitHub at any time.

Either way, the discovery number counts repositories carrying a tag. It is not a count of installable plugins, and the funnel above exists precisely because those two numbers are far apart.

Open data

Every reviewed record, the discovery funnel, and any live repository check are available as JSON under CC BY 4.0, with permissive CORS so other tools can consume them.

/api/plugins.jsonAll reviewed records
/api/check/{owner}/{repo}Live static check of any public repository
/api/compatible/{version}Records documenting a DSH release
/api/compatibility.jsonExact artifact, runtime, surface, observation, and expiry cells
/api/security/{owner}/{repo}Install-time and capability signals
/api/verified.jsonVersioned install and runtime evidence
Open the endpoint list

Important limits

Static signals cannot prove that a plugin is safe, future-compatible, or free from hidden behavior. Always review source, pin Git versions, and test in a disposable profile first.