METHODOLOGY

How the audits work

Every value comes from the automated collection pipeline or the manual review file, and pages are rendered straight from that data — no audit number on this site is typed in by hand.

The four checks

  1. Permissions (manual): automation only surfaces hints (network or exec libraries among dependencies); the verdict is written by a human who reads the code, with the review date recorded. Reviews older than 60 days on a since-updated repo drop back to Pending automatically.
  2. Maintenance (automated): last commit ≤14 days green, ≤45 days amber, older or archived red.
  3. dsh.bundle (automated): per the official docs, a package without this declaration activates nothing after install. Missing declaration = red.
  4. Tests / CI (automated): test script or test directory, plus .github/workflows. Both green, one amber, neither red.

Where the data comes from

Sources: raw GitHub repository contents plus the npm registry, collected daily at 09:20 UTC+8 and published the same day. The tracked-plugin list lives in the site repo — additions welcome.

Three verdicts: Pass (all green, permissions reviewed) · Pending (automated checks green, review queued) · Watch (at least one red flag).