How each plugin was checked in Obsidian
An automated check installs a plugin from its GitHub release into a new vault and tests 7 things. The table shows the result for all 18 plugins.
Who ran the check and how
The developer of these plugins runs this check. No outside lab ran it, and Obsidian staff did not run it.
A script downloads main.js, manifest.json and styles.css from the GitHub release of a plugin. Those are the files that Obsidian downloads when you install the plugin.
The script puts the files in a new vault and starts the desktop app, Obsidian 1.14.4. The app runs with its own profile folder and a test keychain.
Sign in used the developer's own GitHub account, which does not sponsor. So the live part of the check covers the path where Pro stays off.
Each row of the table is one run, on the version and date in that row. A newer version has no result until a new run adds one.
What each check means
Install
The check put the files of the GitHub release in a new vault and turned the plugin on.
Free feature
One free feature did its job on a test note, with no account and no sign in.
Pro text
The settings showed the Pro text, a button that opens GitHub Sponsors, and the sign in button.
Sign in
Sign in showed a code and opened
github.com/login/device, and after approval the settings showed the GitHub login.Pro stays off
The account that signed in does not sponsor, so Pro stayed off and the status said so.
Network
A request log saw no request before sign in, and after sign in only requests to
github.comandapi.github.com.Token storage
The GitHub token was in the secret storage of Obsidian, and no file in the vault or the app profile held it.
Results for each plugin
Under each name are the version that was checked and the date of the run. On a narrow screen, the column numbers match the list above.
| Plugin | install | free | Pro text | sign in | Pro off | network | token |
|---|---|---|---|---|---|---|---|
| AsciiDoc Files | Pass | Pass | Pass | Pass | Pass | Pass | Pass |
| Bases Filter Switches | Pass | Pass | Pass | Pass | Pass | Pass | Pass |
| Bases Freeze Panes | Pass | Pass | Pass | Pass | Pass | Pass | Pass |
| Bases Link Graph | Pass | Pass | Pass | Pass | Pass | Pass | Pass |
| Bases Note Templates | Pass | Pass | Pass | Pass | Pass | Pass | Pass |
| Bases Task Rows | Pass | Pass | Pass | Pass | Pass | Pass | Pass |
| Context Trees | Pass | Pass | Pass | Pass | Pass | Pass | Pass |
| Embed Outline | Pass | Pass | Pass | Pass | Pass | Pass | Pass |
| Flatten Table | Pass | Pass | Pass | Pass | Pass | Pass | Pass |
| Footnotes in Callouts and Tables | Pass | Pass | Pass | Pass | Pass | Pass | Pass |
| Heading Link Sync | Pass | Pass | Pass | Pass | Pass | Pass | Pass |
| Kanban Embed | Pass | Pass | Pass | Pass | Pass | Pass | Pass |
| Mobile Timer for Toggl Track | Pass | In part | Pass | Pass | Pass | In part | Pass |
| PDF Cover Cards | Pass | Pass | Pass | Pass | Pass | Pass | Pass |
| Search Operators | Pass | Pass | Pass | Pass | Pass | Pass | Pass |
| Table Rollup | Pass | Pass | Pass | Pass | Pass | Pass | Pass |
| Task Date Links | Pass | Pass | Pass | Pass | Pass | Pass | Pass |
| Visual Line Numbers | Pass | Pass | Pass | Pass | Pass | Pass | Pass |
- Pass
- In part
- Fail
Mobile Timer for Toggl Track was checked without a Toggl token. Its timer features need a token, so the check saw only the message that asks for one. The request log saw no request to api.track.toggl.com. With a saved token the plugin talks to that host, and this check did not cover those requests.
More results from the newer runs
The newer runs also recorded these results. The line under the list names the plugins they cover.
- Clean load
- The plugin loaded with no error and no console message. 6 / 6 pass
- Pro lock
- With Pro off, a Pro action stayed locked and showed a notice or a disabled setting. 6 / 6 pass
- Sign out
- Sign out cleared the stored token. 6 / 6 pass
Context Trees · Footnotes in Callouts and Tables · Kanban Embed · Mobile Timer for Toggl Track · Task Date Links · Visual Line Numbers
How a plugin decides about Pro
After sign in, a plugin asks GitHub about your sponsorship and decides whether Pro is on.
The check gave the shipped code 7 replies in the form that GitHub returns. No payment was made for these cases.
| What GitHub reports | Expected | Result |
|---|---|---|
| One payment of $50. GitHub reports no total. | Pro on | Pro on |
| One payment of $10. GitHub reports $10 paid in total. | Pro off | Pro off |
| One payment of $10. GitHub reports $15 paid in total. | Pro on | Pro on |
| A sponsorship of $5 a month that has ended. GitHub reports $15 paid in total. | Pro on | Pro on |
| A sponsorship of $5 a month that has ended. GitHub reports $10 paid in total. | Pro off | Pro off |
| An active sponsorship of $5 a month. | Pro on | Pro on |
| No sponsorship. GitHub reports $0 paid in total. | Pro off | Pro off |
Each case gave the expected result in all 18 checked plugins.
Verify a release yourself
GitHub Actions builds main.js and styles.css of a release from the public source and signs a record of that build. GitHub calls this record an artifact attestation.
Download main.js from the release page of the plugin on GitHub. Then run this command with the GitHub CLI.
gh attestation verify main.js --repo theluckystrike/<id>Put the id of the plugin at the end, in place of the word in angle brackets. The id is the last part of its page address on this site, for example kanban-embed.
The command exits with code 0 when GitHub holds a signed build record for that exact file from that repository. On 11 October 2026 it passed for main.js of Kanban Embed 1.1.0, and it failed when it named another repository.
The record proves where the file was built and from which source. It doesn't prove that the code has no bug.
To see whether you have the file that the check installed, run shasum -a 256 main.js. Compare the first 16 characters with this table.
| Plugin | Version | SHA-256 starts with |
|---|---|---|
| AsciiDoc Files | 1.0.0 | a9ae2a985ed49690 |
| Bases Filter Switches | 1.0.0 | e442f246fe311d5c |
| Bases Freeze Panes | 1.1.1 | 41d928a0ec1577e1 |
| Bases Link Graph | 1.0.0 | a82fe27053af6b0d |
| Bases Note Templates | 1.0.0 | 11bd6e6f920541db |
| Bases Task Rows | 1.0.0 | 177fa2085d7ec4c5 |
| Context Trees | 1.0.0 | 77871cbf2611876c |
| Embed Outline | 1.0.0 | 69a75dc8a1a3ff77 |
| Flatten Table | 1.0.0 | 0466ee577b489a87 |
| Footnotes in Callouts and Tables | 1.0.0 | dd6d69e96aea3b74 |
| Heading Link Sync | 1.0.0 | 6dce199e4487cde8 |
| Kanban Embed | 1.1.0 | 2c950228dff9963e |
| Mobile Timer for Toggl Track | 1.0.0 | 3025f29708e28cfa |
| PDF Cover Cards | 1.0.1 | a0c9faee93a7a2dc |
| Search Operators | 1.0.0 | f5259fba952ab2e5 |
| Table Rollup | 1.0.1 | 857cc0bf02ac8f48 |
| Task Date Links | 1.0.0 | 7f018d6c9dd52d67 |
| Visual Line Numbers | 1.0.0 | 7183e3e74901ff02 |
What was not tested
- No purchase from a second GitHub account was made. The paid path was checked with replies in the form that GitHub returns, through the shipped code.
- No phone or tablet was used. Each run used the desktop app.
- The app ran with a test keychain, so the check did not use the keychain of the operating system.
- Mobile Timer for Toggl Track was checked without a Toggl token, so no request went to Toggl.
The check covers install, one free feature of a plugin and the Pro sign in. It doesn't cover each feature of a plugin.