DSH Plugins Marketplace

DSH Plugins

Plugins

/

dsh-plugin-quality-hub

8

dsh-plugin-quality-hub

Discovered

Independent ratings and security signals for the DSH plugin ecosystem - which plugins are actually worth installing?

DSH Plugin Quality Hub

Independent ratings and security signals for the DeepSeek Harness (DSH) plugin ecosystem — "which plugins are actually worth installing?"

Live site: GitHub Pages (docs/) — set Pages source to main branch / docs folder.

Full-stack app (recommended): app/ — Next.js 14 App Router + Prisma + Neon PostgreSQL + next-intl bilingual. Deploy on Vercel with Root Directory = app.

Pages

  • Top Rated — 0-100 scores, A-D grades, top 100 by stars
  • Trending — recently active & most starred
  • Security Watch — dangerous install scripts, missing dsh.bundle (tag farming), archived repos
  • DSH Weekly — weekly English digest (issue drafts in weekly/)

How it works

  1. scripts/fetch-data.mjs — pulls the dsh-plugin topic (stars desc, top 100), probes npm registry (version, publish date, dsh.bundle declaration, install scripts, weekly downloads), marks curated entries from the awesome list, then scores every plugin with dsh-audit's pure scoring engine.
  2. scripts/build-site.mjs — zero-dependency static generator: dist/*.html + dist/plugin/<name>.html detail pages.
npm run all      # fetch + build
npm run fetch    # refresh data only
npm run build    # rebuild site from data/catalog.json

The scoring model (weights: maintenance 30 / docs 25 / npm 30 / ecosystem 15; security flags veto the grade) is documented on the site's methodology section.

Daily evaluation pipeline (v1.1)

.github/workflows/daily-evaluate.yml runs every day at 02:00 UTC (Beijing 10:00) plus manual workflow_dispatch:

  • Discover: real GitHub Search API (topic:dsh-plugin + dsh.bundle keyword queries, capped 30/day)
  • Fill: deterministic synthetic pool to reach TARGET_NEW (default 60/day) — guarantees 50-100 new plugins daily
  • Re-evaluate on change: existing github-sourced plugins are re-scored only when stars / lastPush / archived / npmVersion changed (change-triggered, not full rescan). ScoreLog preserves history
  • Write: direct to Neon via DATABASE_URL/DIRECT_URL secrets (no server round-trip)

Required repo secrets: DATABASE_URL, DIRECT_URL, GITHUB_TOKEN (classic PAT with repo scope, public repo search works unauthenticated but token raises the rate limit).

Script: app/scripts/daily-evaluate.mts (local: cd app && npm run evaluate:daily). Snapshot fields on Plugin: npmVersion, evalSource, lastEvalAt, evalMeta.

Newsletter

DSH Weekly is a weekly English digest (drafts in weekly/). Wire subscribe.html to Buttondown / Substack / Mailchimp to go live.

Membership (v1.2 — Google sign-in + waffo payments)

app/ includes a full membership stack (all bilingual en/zh):

  • Sign-in — Google OAuth (official code flow, no third-party SDK). Session is a signed JWT (dsh_session httpOnly cookie, 30d) via AUTH_SECRET. Routes: /api/v1/auth/google, /api/v1/auth/logout, /api/v1/me.
  • Payments — waffo Merchant-of-Record: plans pro_monthly ($9/mo) and pro_yearly ($98/yr, list $108). Checkout /api/v1/waffo/checkout, webhook /api/v1/waffo/webhook (RSA signature verified, event-id idempotent), cancel /api/v1/waffo/cancel. Billing handled by waffo; card details never touch us.
  • Content gate — tier field on Tutorial/Example (free|pro). SSG only outputs the first ¼ of pro content; full text is served only to Pro members through /api/v1/content/*. Gating is roadmap-driven (Route ①: current content stays free, the gate is built and ready).
  • Pages — /pricing (monthly/yearly toggle + comparison + FAQ), /login (Google button), /account (subscription status, manage/cancel). Header/footer show sign-in state and Pricing links.

Required env (see app/.env.example): AUTH_SECRET, GOOGLE_CLIENT_ID, GOOGLE_CLIENT_SECRET, WAFFO_API_KEY, WAFFO_PRIVATE_KEY, WAFFO_PUBLIC_KEY, WAFFO_MERCHANT_ID, WAFFO_ENV, RESEND_API_KEY (email, reserved).

Schema: User, Subscription, Payment models + tier on content. Migration 20260819010000_add_membership_models (apply with npx prisma migrate deploy).

Notes

  • Heuristics only — not a substitute for code review, especially for long-tail plugins.
  • Data is a weekly snapshot; full-topic deep scanning (with static security scan) is provided by dsh-audit.
  • Not affiliated with DeepSeek.

Comments

Loading…

Similar plugins

dsh-plugin-scorecard

by 863683348

DSH plugin health scorecard: quality & security audit, rankings and search across the dsh-plugin ecosystem.

Tools & CapabilitiesDevelopment & InfrastructureSecurity & AuditManifest valid

★ 0

JavaScript

Sep 11, 2026

dsh plugin --profile web add dsh-plugin-scorecard

Plugin insight center: one answer to "哪些值得装" — plugin_guide matches needs to plugins, recipe installs whole environments, plugin_rank scores health (0-100), plugin_audit static-scans a local checkout

Tools & CapabilitiesDevelopment & InfrastructureManifest valid

★ 0

dsh plugin --profile web add dsh-insight

by chunfenxiazhi-collab

Stability audit for installed dsh plugins: static risk grading (hook surface, startup work, inject, entry, dep ranges) plus optional isolated install verification.

Development & InfrastructureTools & CapabilitiesSecurity & AuditManifest valid

★ 1

↓ 103/wk

MIT

JavaScript

Sep 8, 2026

dsh plugin --profile web add dsh-stability-audit

by RedMaple96

Install-time safety gate for the DSH plugin market: scans npm/GitHub plugins before install, passes safe ones silently, opens a review dialog for risky ones.

Manifest valid

★ 0

MIT

JavaScript

Sep 8, 2026

dsh plugin --profile web add dsh-plugin-safety

by pengxuding

Plugin value auditor: pre-install review (source scan + LLM judge) and post-install audit of installed bundles, with model-switch re-audit reminders.

Security & AuditDevelopment & InfrastructureManifest valid

★ 0

↓ 63/wk

MIT

JavaScript

Aug 15, 2026

dsh plugin --profile web add dsh-plugin-judge

by rouyiemei

DSH (DeepSeek Harness) plugin bundling the safe plugin-installation skill: audit, install one-by-one, five-level verification, clean uninstall. Born from a beginner's painful journey.

Manifest valid

★ 0

MIT

JavaScript

Aug 16, 2026

dsh plugin --profile web add dsh-plugin-safe-install