Omahub
← All plugins
A

Wordle

by Akshad Agrawal

Daily NYT Wordle and archive practice in the bar: click the green W to play

Security review

Potentially dangerous behavior detected · 1 finding

Deterministic scan — not a security guarantee

High
Risk level
High
Analyzed commit
41b8098
Scanned
1 month ago
  • high destructive_filesystem data/guesses.js:3

    Low-level disk manipulation or write command.

    shred","shris","shrow","shtik","shtum","shtup","shule","shuln","shuls","shuns","shura","shute","shuts","shwas","shyer","sials","sibbs","sibyl","sices","sicht","sicko","sicks","sicky","sidas","sided","

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
41b8098
Reviewed
1 month ago

The plugin is a Wordle game that fetches daily puzzles from the NYT over HTTPS and stores local game state in ~/.local/state/omarchy/. The deterministic scan flagged a 'destructive_filesystem' finding in data/guesses.js, but that is a false positive: the snippet is just a list of valid Wordle guess words (e.g., 'shred', 'shris') and contains no destructive commands. The code is straightforward QML/JS with no obfuscation, no shell execution beyond optional clipboard copy, and no elevated privileges or persistence beyond local state files.

  • The deterministic scan's high-risk finding is a false positive; the flagged line is a word list, not a destructive command.
  • The plugin fetches the daily answer from the NYT API, which is a benign network call with no telemetry.
  • State is stored only in user-local files under ~/.local/state/omarchy/, with no system-wide modifications.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/Akshad135/wordle --enable
Widgets #bar #quickshell #games

Wordle for Omarchy

A native Omarchy status bar and popup plugin for playing Wordle directly from your desktop.

Wordle Preview

Features

  • Daily NYT Wordle: Fetches and synchronizes today's official NYT puzzle and solution.
  • Random / Practice Mode: Play random past Wordles from the archive (2021 to present) with an on-demand refresh button.
  • Stats Dashboard & Heatmap: Comprehensive stats page featuring win rates, streaks, guess distribution histogram, a 20-week GitHub-style activity calendar heatmap, and interactive per-game board replays with copyable share text.
  • Adaptive Theming: Automatically inherits colors from your active Omarchy theme (colors.toml) with dynamic luminance-based text contrast.
  • Dual Input: Full physical keyboard navigation and on-screen virtual keyboard with tactile interaction.
  • Animations: Letter pop-ins, flip reveals, shake feedback on invalid guesses, and hover highlighting.
  • Persistent State: Saves in-progress games and full historical records across shell restarts and theme switches.
  • Valid Word List: Every guess is checked against a bundled 12,947-word official dictionary (answers + accepted guesses).
  • IPC Support: Toggle or summon the game via omarchy-shell akshad135.wordle toggle.

Installation

Install and enable the plugin:

omarchy plugin add https://github.com/Akshad135/wordle.git --enable
omarchy restart shell

How to Play

  • Click the W icon in the bar or bind a shortcut to omarchy-shell akshad135.wordle toggle.
  • Daily: Plays today's official NYT puzzle.
  • Random: Plays archived puzzles from past dates with a refresh button (󰑐) to roll a new word anytime.
  • Stats: View your lifetime stats, streaks, guess distribution histogram, 20-week activity heatmap, and replay past boards.
  • Controls:
    • A-Z: Type letters
    • Enter: Submit guess
    • Backspace: Delete letter
    • Escape: Close popup

Uninstallation

To disable or remove the plugin:

omarchy plugin disable akshad135.wordle
omarchy plugin remove akshad135.wordle

Dependencies & Requirements

  • omarchy / quickshell (status bar framework)
  • curl (fetching daily NYT puzzle solutions)
  • wl-copy (optional: copying game replay scorecard to clipboard)

Security & Architecture

  • Network: HTTPS only (https://www.nytimes.com/svc/wordle/v2/), timeout-bounded, zero telemetry.
  • Execution: Structured argument arrays without shell interpolation.
  • Privilege Boundary: Runs entirely as an unprivileged user process without elevated permissions or background daemons.
  • State Storage: Strictly stored within ~/.local/state/omarchy/wordle-state.json (active game) and ~/.local/state/omarchy/wordle-history.json (completion history & stats).

Testing

Run the test suite:

node test/logic.test.mjs

License

MIT © Akshad Agrawal