Compare / Free vs paid Claude Code plugin marketplaces: how to choose

Free vs paid Claude Code plugin marketplaces: how to choose

Published 2026-10-11 · Last verified 2026-10-11 · 882 words · figures link to their sources; numbers change daily.

"Marketplace" means three different things in the Claude Code world, and most comparison pages blur them. There is the mechanism — a JSON file any git repo can carry — there is Anthropic's directory, and there are third-party catalogues, free and paid, that use the mechanism. Once you separate them, the free-versus-paid question gets much easier.

The mechanism: marketplace.json

A plugin marketplace is any directory or git repository with a .claude-plugin/marketplace.json that lists plugins and where to fetch each one (Create a marketplace). The file needs a name, an owner and a plugins array; each entry needs a name and a source, which can be a relative path inside the same repo, a GitHub repo, or a subdirectory of another repo. Users add it with claude plugin marketplace add owner/repo and install with claude plugin install name@marketplace; updates arrive through claude plugin update or an opt-in auto-update (Publish and distribute a plugin).

Two consequences follow. First, publishing is free and permissionless — "Once the file is in the repository, the plugin is published, with no submission form." Second, anyone who can clone the repository can install from it, so a private repo is a private marketplace. The paid catalogues on the market are therefore not selling the marketplace mechanism; they are selling what is inside it, plus hosting, curation and support.

Anthropic's directory

Anthropic's directory at claude.ai/directory is the catalogue people browse on claude.ai and in Cowork; a plugin listed there also loads in Claude Code via account sync. Submitting requires a paid claude.ai plan and goes through a developer portal with its own review; Anthropic's official marketplace, claude-plugins-official, "doesn't take submissions through the directory portal" (Publish and distribute a plugin). So the directory is free for users, gated for publishers, and reviewed — the closest thing to an app store.

Third-party directories and lists

These are free, usually community-maintained, and vary from a curated README to a generated catalogue. Verified on the "last verified" date via the GitHub API:

DirectoryFormStarsLast commitSource
awesome-claude-codeCurated README, all resource types55,4162026-10-11API
skills.shDirectory + install leaderboard; CLI repo vercel-labs/skills33,719 (CLI repo)2026-10-09API
buildwithclaude"Single hub to find Claude Skills, Agents, Commands, Hooks, Plugins, and Marketplaces"3,6152026-10-10API
awesome-claude-pluginsCurated plugin list1,9382026-07-26API
awesome-claude-code-pluginsCurated plugin list9692026-08-12API
claude-code-hooksA working marketplace: 22 hook plugins, MIT5382026-10-04API
awesome-claude-code-modsScanner-generated catalogue of 3,088 mods with per-mod access badges4792026-10-11API

What free directories give you: breadth, zero cost, and — in the best cases — a scanner or audit that tells you what a plugin can touch. What they do not give you: a maintainer who answers when something breaks, versioned releases you can pin, or any filter on quality beyond stars.

Paid catalogues

Paid catalogues use the same marketplace.json or a CLI of their own, and charge for the contents. Across the ones compared on the skills libraries page, monthly tiers sit at $9–$9.99 and lifetime at $99–$169; HookCrate is $9/month or $99 lifetime for eight packs, with two hooks free under MIT. The honest case for paying is narrow: a small set of things you will actually use, maintained by someone accountable, with tests and previews you can inspect before buying. The honest case against is wide: most of what a paid catalogue sells exists somewhere free, and the free version is often more battle-tested.

A neutral decision checklist

Work through these in order; stop at the first one that decides it.

  1. Does a free, maintained plugin already do the job? Search awesome-claude-code and skills.sh first. If yes, use it.
  2. Can you read the source before installing? Public repos: yes. Paid catalogues: only if they show previews or transcripts. If you cannot read it, do not run it — hooks execute on every tool call.
  3. What can it touch? For hooks and mods, prefer sources that report file, network and shell access (the mods catalogue's badges, skills.sh audits, Agensi's scan). Run a secret scanner over anything you install; HookCrate's release-scrub works for this.
  4. Will it be updated when Claude Code changes? Check the last commit date. A hook library untouched since early 2026 may not know about newer events or fields.
  5. Who answers when it breaks? Free: an issue tracker and hope. Paid: that is what you are paying for; check the refund terms.
  6. How many machines and projects? A CLI (claude plugin install, npx skills add, hookcrate install) beats ZIP downloads once you pass two.
  7. Is the price for access or for items? Subscriptions suit heavy users of a library; per-item purchases suit one specific need.

If you reach the end and the answer is "pay", pay for the smallest thing that solves the problem and keep the free directories bookmarked for everything else.

FAQ

Can I run my own private marketplace for my team?

Yes. Put .claude-plugin/marketplace.json in a private git repository; anyone who can clone it can claude plugin marketplace add it. No account, approval or fee is involved (docs).

Is Anthropic's directory the same as the official marketplace?

No. The directory accepts submissions from paid claude.ai accounts through a review portal; the official marketplace claude-plugins-official does not take submissions through that portal (docs).

Are paid plugins safer than free ones?

Not inherently. Safety comes from being able to read the code, knowing what it can access, and seeing tests — properties that free public repos often have and paid catalogues sometimes lack. Judge each by the checklist, not the price.

Related guides

Related packs

  • Credential Guard — Blocks shell and HTTP tool calls that would ship a literal API key or token to an outbound command.
  • Release Scrub — Scans a folder for emails, phone numbers, IBANs, API keys and a configurable names list before anything is published.