How we grade
We download every plugin's latest release, read its code, and give it one grade. The single worst finding sets it, so a plugin can't make up for a serious problem by doing well elsewhere.
The ladder
An A doesn't mean we found nothing. Small findings, such as storing an API key in Zotero's settings, are rated low and listed on the card; an A means none of them is more than that. A B means at least one finding is worth reading before you install. A C means we found something serious, such as code deliberately scrambled so nobody can check it.
What we check in the code
Every finding links to the file and line it came from. The rules are published with the code, and they're the same for every plugin: when we change one, every card is recomputed.
The live test, for A+
Reading code shows what a plugin could do. The live test shows what it actually does.
- 1We install the exact release file in a fresh copy of Zotero 10, with a small sample library.
- 2We select items, open the reader and the plugin's settings, and click its menu items.
- 3We record every server it contacts and what it sends, including any of the sample library's text.
- 4If it loaded, and everything it did is something its card already describes, an A becomes A+.