Omahub
← All plugins
R

Market Stats

by radbug

Engagement stats for your plugins listed on the Omarchy Plugin Market (omarchyplugins.com) — install-command copies, detail views, and hearts totaled on the bar, with a per-plugin breakdown in the tooltip. Click to refresh.

Security review

Review recommended · 1 finding

Deterministic scan — not a security guarantee

Low
Risk level
Low
Analyzed commit
831d7c7
Scanned
1 month ago

Flagged patterns appear only in documentation files (README / docs) — descriptive examples, not executable code.

  • Docs external_hosts README.md:41

    Downloads or connects to an external HTTP(S) host.

    curl`](https://curl.se) and [`jq`](https://jqlang.github.io/jq/) — both ship

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
831d7c7
Reviewed
1 month ago

The deterministic external-host finding points to README documentation links, not malicious code. The plugin's collector script does make a real read-only GET to the documented omarchyplugins.com stats API and writes a local cache, matching its stated purpose. No obfuscation, credential access, persistence, or destructive commands were found.

  • The widget automatically contacts api.omarchyplugins.com on load and every refresh interval; this is documented and read-only, but the endpoint will see the user's IP and request pattern.
  • Network behavior is in the executable Bash collector rather than only in documentation, though the URL, method, and data handling are transparent and non-sensitive.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/alvarosaavedra/omarchy-plugins-control --enable
Developer Tools #bar #quickshell

Market Stats

An Omarchy shell bar widget that shows engagement stats for your plugins listed on the Omarchy Plugin Market (omarchyplugins.com):

⬇ 12 · 👁 54 · ♥ 2
  • ⬇ copies — how many times someone copied your plugin's install command (the market's closest thing to a download counter)
  • 👁 views — detail-page views on the marketplace
  • ♥ hearts — hearts given on the marketplace

The numbers are lifetime aggregates straight from the market's public engagement API — https://api.omarchyplugins.com/v1/stats — no account, token, or auth needed. The tooltip breaks the totals down per plugin; clicking the widget refreshes immediately.

Install

omarchy plugin add https://github.com/alvarosaavedra/omarchy-plugins-control.git --enable

(From a local checkout: omarchy plugin add /path/to/omarchy-plugins-control --enable.)

Remove

omarchy plugin remove alvarosaavedra.market-stats

This disables the widget and deletes the installed copy from ~/.config/omarchy/plugins/. To also drop the cached snapshots, delete ~/.local/state/omarchy-market-stats/.

External dependencies

  • curl and jq — both ship with Omarchy. Used by collectors/omarchy-plugin-stats to fetch and filter https://api.omarchyplugins.com/v1/stats (public endpoint, GET only, no authentication, no telemetry sent).

Settings

Settings live on the widget's entry in ~/.config/omarchy/shell.json and hot-reload on save:

{
  "id": "alvarosaavedra.market-stats",
  "settings": {
    "prefix": "alvarosaavedra.",
    "refreshMinutes": 30
  }
}
Key Default Meaning
prefix alvarosaavedra. Only market listings whose id starts with this are counted
refreshMinutes 30 Auto-refresh interval (minimum 1)

How it works

  • collectors/omarchy-plugin-stats fetches the market's stats endpoint, keeps the ids matching your prefix, computes totals, and writes an atomic snapshot to ~/.local/state/omarchy-market-stats/plugins.json.
  • BarWidget.qml restores that snapshot instantly on shell restart, refreshes it on load, on a timer, and on click.
  • Offline or when the market is down, the bar keeps showing the last good numbers, flagged with ⚠; an in-flight refresh shows ….

Caveats

  • Market counters are anonymous aggregate engagement events, not verified installs: someone can copy the command without running it, and git clone installs never touch the counter.
  • Only plugins actually listed on omarchyplugins.com are counted. Not listed yet? Submit via the marketplace's plugin submission form.
  • The plugin only reads a public endpoint; it never sends data anywhere.

License

MIT — see LICENSE.