How each plugin was checked in Obsidian

An automated check installs a plugin from its GitHub release into a new vault and tests 7 things. The table shows the result for all 18 plugins.

Who ran the check and how

The developer of these plugins runs this check. No outside lab ran it, and Obsidian staff did not run it.

A script downloads main.js, manifest.json and styles.css from the GitHub release of a plugin. Those are the files that Obsidian downloads when you install the plugin.

The script puts the files in a new vault and starts the desktop app, Obsidian 1.14.4. The app runs with its own profile folder and a test keychain.

Sign in used the developer's own GitHub account, which does not sponsor. So the live part of the check covers the path where Pro stays off.

Each row of the table is one run, on the version and date in that row. A newer version has no result until a new run adds one.

What each check means

  1. Install

    The check put the files of the GitHub release in a new vault and turned the plugin on.

  2. Free feature

    One free feature did its job on a test note, with no account and no sign in.

  3. Pro text

    The settings showed the Pro text, a button that opens GitHub Sponsors, and the sign in button.

  4. Sign in

    Sign in showed a code and opened github.com/login/device, and after approval the settings showed the GitHub login.

  5. Pro stays off

    The account that signed in does not sponsor, so Pro stayed off and the status said so.

  6. Network

    A request log saw no request before sign in, and after sign in only requests to github.com and api.github.com.

  7. Token storage

    The GitHub token was in the secret storage of Obsidian, and no file in the vault or the app profile held it.

Results for each plugin

Under each name are the version that was checked and the date of the run. On a narrow screen, the column numbers match the list above.

Results for each plugin
PlugininstallfreePro textsign inPro offnetworktoken
AsciiDoc Files1.0.0 · current 1.0.2PassPassPassPassPassPassPass
Bases Filter Switches1.0.0 · current 1.0.1PassPassPassPassPassPassPass
Bases Freeze Panes1.1.1 · PassPassPassPassPassPassPass
Bases Note Templates1.0.0 · PassPassPassPassPassPassPass
Bases Task Rows1.0.0 · current 1.0.2PassPassPassPassPassPassPass
Context Trees1.0.0 · PassPassPassPassPassPassPass
Embed Outline1.0.0 · PassPassPassPassPassPassPass
Flatten Table1.0.0 · PassPassPassPassPassPassPass
Footnotes in Callouts and Tables1.0.0 · PassPassPassPassPassPassPass
Kanban Embed1.1.0 · PassPassPassPassPassPassPass
Mobile Timer for Toggl Track1.0.0 · current 1.0.1PassIn partPassPassPassIn partPass
PDF Cover Cards1.0.1 · PassPassPassPassPassPassPass
Search Operators1.0.0 · PassPassPassPassPassPassPass
Table Rollup1.0.1 · current 1.0.3PassPassPassPassPassPassPass
Visual Line Numbers1.0.0 · current 1.0.1PassPassPassPassPassPassPass
  • Pass
  • In part
  • Fail

Mobile Timer for Toggl Track was checked without a Toggl token. Its timer features need a token, so the check saw only the message that asks for one. The request log saw no request to api.track.toggl.com. With a saved token the plugin talks to that host, and this check did not cover those requests.

More results from the newer runs

The newer runs also recorded these results. The line under the list names the plugins they cover.

Clean load
The plugin loaded with no error and no console message. 6 / 6 pass
Pro lock
With Pro off, a Pro action stayed locked and showed a notice or a disabled setting. 6 / 6 pass
Sign out
Sign out cleared the stored token. 6 / 6 pass

Context Trees · Footnotes in Callouts and Tables · Kanban Embed · Mobile Timer for Toggl Track · Task Date Links · Visual Line Numbers

How a plugin decides about Pro

After sign in, a plugin asks GitHub about your sponsorship and decides whether Pro is on.

The check gave the shipped code 7 replies in the form that GitHub returns. No payment was made for these cases.

What GitHub reportsExpectedResult
One payment of $50. GitHub reports no total.Pro onPro on
One payment of $10. GitHub reports $10 paid in total.Pro offPro off
One payment of $10. GitHub reports $15 paid in total.Pro onPro on
A sponsorship of $5 a month that has ended. GitHub reports $15 paid in total.Pro onPro on
A sponsorship of $5 a month that has ended. GitHub reports $10 paid in total.Pro offPro off
An active sponsorship of $5 a month.Pro onPro on
No sponsorship. GitHub reports $0 paid in total.Pro offPro off

Each case gave the expected result in all 18 checked plugins.

Verify a release yourself

GitHub Actions builds main.js and styles.css of a release from the public source and signs a record of that build. GitHub calls this record an artifact attestation.

Download main.js from the release page of the plugin on GitHub. Then run this command with the GitHub CLI.

gh attestation verify main.js --repo theluckystrike/<id>

Put the id of the plugin at the end, in place of the word in angle brackets. The id is the last part of its page address on this site, for example kanban-embed.

The command exits with code 0 when GitHub holds a signed build record for that exact file from that repository. On 11 October 2026 it passed for main.js of Kanban Embed 1.1.0, and it failed when it named another repository.

The record proves where the file was built and from which source. It doesn't prove that the code has no bug.

To see whether you have the file that the check installed, run shasum -a 256 main.js. Compare the first 16 characters with this table.

PluginVersionSHA-256 starts with
AsciiDoc Files1.0.0a9ae2a985ed49690
Bases Filter Switches1.0.0e442f246fe311d5c
Bases Freeze Panes1.1.141d928a0ec1577e1
Bases Link Graph1.0.0a82fe27053af6b0d
Bases Note Templates1.0.011bd6e6f920541db
Bases Task Rows1.0.0177fa2085d7ec4c5
Context Trees1.0.077871cbf2611876c
Embed Outline1.0.069a75dc8a1a3ff77
Flatten Table1.0.00466ee577b489a87
Footnotes in Callouts and Tables1.0.0dd6d69e96aea3b74
Heading Link Sync1.0.06dce199e4487cde8
Kanban Embed1.1.02c950228dff9963e
Mobile Timer for Toggl Track1.0.03025f29708e28cfa
PDF Cover Cards1.0.1a0c9faee93a7a2dc
Search Operators1.0.0f5259fba952ab2e5
Table Rollup1.0.1857cc0bf02ac8f48
Task Date Links1.0.07f018d6c9dd52d67
Visual Line Numbers1.0.07183e3e74901ff02

What was not tested

  • No purchase from a second GitHub account was made. The paid path was checked with replies in the form that GitHub returns, through the shipped code.
  • No phone or tablet was used. Each run used the desktop app.
  • The app ran with a test keychain, so the check did not use the keychain of the operating system.
  • Mobile Timer for Toggl Track was checked without a Toggl token, so no request went to Toggl.

The check covers install, one free feature of a plugin and the Pro sign in. It doesn't cover each feature of a plugin.