Omahub
← All plugins
C

CVE Watcher

by Casper Bottelet

A scrollable timeline of new CVEs for the stack you actually run (PHP, Laravel, MySQL, Node, Rails, ...), with min-version filtering, CISA KEV exploited-in-the-wild badges, endoflife.date EOL warnings, and an unread badge on the bar.

Security review

Review recommended · 3 findings

Deterministic scan — not a security guarantee

Medium
Risk level
Medium
Analyzed commit
b232e34
Scanned
4 days ago
  • medium external_hosts Model.js:155

    Downloads or connects to an external HTTP(S) host.

    curl -fsS --max-filesize " + MAX_BYTES + " --max-time 15 -X POST -H 'Content-Type: application/json' -d " + shArg(body) + " https://api.osv.dev/v1/query")
  • medium external_hosts Model.js:169

    Downloads or connects to an external HTTP(S) host.

    curl -fsS --max-filesize " + MAX_BYTES + " --max-time 30 https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json | head -c " + MAX_BYTES + " | jq -c '[.vulnerabilities[].cv
  • medium external_hosts Model.js:173

    Downloads or connects to an external HTTP(S) host.

    curl", "-fsS", "--max-filesize", String(MAX_BYTES), "--max-time", "15", "https://endoflife.date/api/" + service.eol + ".json"]

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
b232e34
Reviewed
4 days ago

This is a conventional CVE feed widget: all outbound calls go to documented public APIs (OSV.dev, NVD, CISA KEV, endoflife.date) and are necessary for the plugin's function. Commands are built from static templates with single-quoted arguments, and no install-time scripts, persistence, obfuscation, or credential-exfiltration behavior was found. The deterministic scan's medium rating comes solely from those expected external hosts, which I do not consider a real risk here.

How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/Bottelet/omarchy-cve-watcher --enable
Developer Tools #bar #quickshell #security

CVE Watcher

An Omarchy bar plugin that watches for new CVEs in the stack you actually run — and only bugs you about the versions you actually use.

A shield icon sits in your bar. When new advisories land for a service you subscribe to, it badges up with the unread count (red when something is critical or actively exploited). Click it for a scrollable timeline of the latest CVEs across your stack; opening the panel marks everything as read.

CVE Watcher

What it shows

  • Timeline — newest CVEs first, across all subscribed services, with severity (CVSS), a summary, and age. Click any row to open the full advisory.
  • KEV badge — CVEs listed in CISA KEV (confirmed exploited in the wild) get a red KEV chip. That's the signal worth interrupting your day for.
  • EOL card — filter to one service and see its release line's latest patch version and end-of-life date, via endoflife.date.
  • Unread markers — rows published since you last opened the panel get a dot; the bar icon badge counts them.

Where the data comes from

Each service maps to the layer where its CVEs actually live:

Layer Source Services
Frameworks & libraries OSV.dev Laravel, Rails, Django, Symfony, Express, Next.js, npm CLI
Runtimes & products NVD API 2.0 PHP/PHP-FPM, Node.js, Python, Go, Rust, Java, Ruby, WordPress, MySQL, MariaDB, PostgreSQL, MongoDB, Redis, nginx, Apache, Docker, Kubernetes
Exploited-in-the-wild CISA KEV all (cross-reference)
EOL / latest patch endoflife.date all with a product page

All feeds are free and keyless. NVD limits anonymous clients to 5 requests / 30 s, so NVD fetches self-stagger a few seconds apart to stay under it.

Settings (⚙ in the panel)

  • Services — toggle which of the 24 services you subscribe to. Nothing is watched out of the box; pick your stack. (PHP-FPM CVEs are filed under PHP itself, so the PHP entry covers both.)
  • Minimum severity — All / Medium+ / High+ / Critical. KEV (exploited in the wild) and unrated entries always show regardless of the floor.
  • Min version — per service, hide advisories that only affect versions older than what you run ("I don't care about Laravel 10, I'm on 13"). Type a version or click a release line to set it — lines are listed with their latest patch and EOL date.

Tweakables via CLI:

omarchy bar set bottelet.cve-watcher refreshMinutes 60
omarchy bar set bottelet.cve-watcher highColor "#e5941b"

Install

omarchy plugin add https://github.com/Bottelet/omarchy-cve-watcher.git --enable
omarchy bar put bottelet.cve-watcher --after omarchy.clock

Usage

  • Click the shield: open/close the timeline (marks all as read).
  • Middle-click the shield: refresh all feeds now.
  • Click a service pill: filter the timeline + show that service's EOL info.
  • Click a CVE row: open the advisory (osv.dev / nvd.nist.gov).

Remove

omarchy plugin remove bottelet.cve-watcher

Settings (subscriptions, min versions, read state) live in this plugin's own entry in ~/.config/omarchy/shell.json; removing the plugin drops the widget from the bar, and the entry can be deleted from that file if you want a clean slate.

Dependencies

curl and jq — both ship with Omarchy.