Omahub
← All plugins
B

Homepage Shortcuts

by bscott

A dropdown of the services and bookmarks configured on a Homepage (gethomepage.dev) dashboard, refreshed from its API so the list stays in sync with the dashboard.

Security review

Review recommended · 4 findings

Deterministic scan — not a security guarantee

Medium
Risk level
Medium
Analyzed commit
5309f30
Scanned
1 month ago
  • medium external_hosts tests/fetch.test.sh:38

    Downloads or connects to an external HTTP(S) host.

    curl -fso /dev/null "http://127.0.0.1:$port/api/services" && break; sleep 0.2; done
  • medium external_hosts tests/fetch.test.sh:69

    Downloads or connects to an external HTTP(S) host.

    curl -fso /dev/null "http://127.0.0.1:$port/api/services" && break; sleep 0.2; done
  • medium package_manager …/workflows/ci.yml:49

    System package manager operation.

    apt-get install -y shellcheck >/dev/null
  • Command runs with sudo, elevating the process beyond the plugin environment.

    sudo apt-get install -y shellcheck >/dev/null

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
5309f30
Reviewed
1 month ago

This plugin is a straightforward Homepage dashboard widget that fetches service/bookmark lists from a user-configured URL and opens shortcuts via a configurable command. The deterministic scan's medium findings are all in test/CI files (local test server, installing shellcheck in CI) and do not affect end users. The only user-facing risk is the configurable openCommand, which could be set to an arbitrary command, but that requires deliberate user configuration.

  • The openCommand setting allows arbitrary command execution with the URL as an argument; a malicious or misconfigured value could execute unintended commands, though this requires explicit user configuration.
  • The widget fetches data from a user-specified baseUrl and caches it locally; if the URL is compromised, the displayed links could be malicious, but opening them still relies on the user's openCommand (default xdg-open).
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/bscott/homepage-oma-plugin --enable
Widgets #quickshell #launcher

Homepage Shortcuts

Homepage Shortcuts panel

An Omarchy shell bar widget that drops down the services and bookmarks configured on a Homepage dashboard, so anything on the dashboard is one click away from the top bar.

The dashboard's config is the single source of truth: the widget reads Homepage's own /api/services and /api/bookmarks endpoints, so adding, renaming, or removing a service on the dashboard is all it takes for the dropdown to follow.

Install

omarchy plugin add git@github.com:bscott/homepage-oma-plugin.git --enable

Then set your Homepage URL in the widget's settings (or in the widget's shell.json entry as "baseUrl"). Until it is set, the dropdown shows a hint instead of shortcuts.

To remove the plugin:

omarchy plugin remove bscott.homepage

Removal leaves your Homepage dashboard untouched. The widget's own data is two small directories you can delete if you want a full cleanup: ~/.local/state/omarchy-homepage-widget/ (pins) and ~/.cache/omarchy-homepage-widget/ (fetch cache).

Upgrading from 1.x: version 2.0.0 renamed the plugin id from net.dogdragon.homepage to bscott.homepage. After updating, change the widget's id in your shell.json (and any keybindings that call the old IPC target) to the new name. Pins and settings are otherwise unaffected.

Behavior

  • Bar icon (apps grid): left-click toggles the dropdown, right-click refreshes the list, middle-click opens the dashboard itself.
  • Dropdown: shortcuts grouped exactly as Homepage groups them, each with a monogram tile, name, and description. Click one to open it in the browser.
  • Pinned favorites: pin any shortcut to a "Pinned" group at the top — right-click a row, press p on it, or use the pin button that appears under the cursor. Pins keep the order you pinned them in, persist in ~/.local/state/omarchy-homepage-widget/pins.json, and survive a pinned service temporarily disappearing from the dashboard.
  • Keyboard: ↑/↓ or j/k to move, Enter/Space to open, / to focus the filter field, p to pin/unpin, r to refresh, o to open the dashboard, Esc to close. In the filter field: Enter opens the selected match, ↓ returns to the list, Esc clears then unfocuses.
  • Staying up to date: the list re-fetches on a configurable interval (default 5 minutes) and on panel open once it is more than a minute old.
  • Offline: the last successful fetch is cached on disk (~/.cache/omarchy-homepage-widget/) and served — labeled as cached — when Homepage is unreachable, so the dropdown never empties out on a VPN blip.

Settings

Configured per-instance in shell.json (or via the shell's widget settings):

Key Default Meaning
baseUrl (unset) Homepage instance to mirror, e.g. https://homepage.example.com
refreshIntervalSec 300 Background refresh cadence
includeBookmarks true Also list bookmark groups
openCommand xdg-open Command that receives a shortcut URL

IPC

omarchy-shell bscott.homepage toggle    # also: open / close
omarchy-shell bscott.homepage refresh
omarchy-shell bscott.homepage status
omarchy-shell bscott.homepage pin "https://photos.example.com"   # toggles
omarchy-shell bscott.homepage pins

toggle is handy behind a Hyprland keybinding.

Requirements

curl and jq (both ship with Omarchy).