Unless I'm missing something, the current plugin registry [0] is pretty useless compared to WordPress or even Envato without stats for number of installs, ratings, and reviews/comments.
We launched the plugin registry last week, and our focus has been on safe, decentralised plugin distribution and discovery. Stats, ratings etc are valuable, but they need careful design to prevent abuse. We will definitely add them later.
Appreciate the context. But my larger point is that all of the sandboxing and plugin permission security features falls flat until you can easily evaluate the plugins themselves from social signals and even looking at the code on Github. It's one of the main aspects the people overlook when trying to replace WordPress is the developer network, reviews, ratings, etc.
Otherwise you just have to trust the random plugin publisher and the permissions/sandboxing doesn't really matter.
[0] https://plugins.emdashcms.com/
Otherwise you just have to trust the random plugin publisher and the permissions/sandboxing doesn't really matter.