I usually trust more, so I would go to a separate application domain,
but on your question, I think you're a little tired, and I.
If you really want to be safe, I would say, load the plugins into a separate process and give the plug-in interface an "interprocess" bridge just for what it needs ...
Thus, you are sure that you only choose what you want to connect the plugin to.
In addition, you can easily run this daemon process as a “weak” user who has limited access to system calls, the file system, and the environment.
Tomer w
source share