It honestly surprises me we don't hear news about vim/neovim plugin supply chain attacks.
probably a much smaller dependency graph (lesser usage of transitive dependencies)