Omahub
← All plugins
I

Daily Islamic Reminder

by Idris Akorede Ibrahim

A daily Quran ayah and/or graded Hadith with a full-detail panel.

Security review

Review recommended · 2 findings

Deterministic scan — not a security guarantee

Medium
Risk level
Medium
Analyzed commit
a47e791
Scanned
2 days ago
  • medium external_hosts Service.qml:148

    Downloads or connects to an external HTTP(S) host.

    curl", "-fsS", "--max-time", "10", "https://api.alquran.cloud/v1/edition?format=text&type=translation"]
  • medium external_hosts Service.qml:150

    Downloads or connects to an external HTTP(S) host.

    curl", "-fsS", "--max-time", "10", "https://cdn.jsdelivr.net/gh/fawazahmed0/hadith-api@1/editions.min.json"]

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
a47e791
Reviewed
2 days ago

The plugin fetches Quran and Hadith content from two well-known public APIs (Al Quran Cloud and jsDelivr) via curl, caches results locally, and performs a one-time safe migration of legacy cache files. No obfuscation, credential theft, destructive commands, or hidden behavior was found. The external network calls are clearly documented and expected for this widget's functionality.

  • The plugin makes HTTPS requests to external hosts (api.alquran.cloud and cdn.jsdelivr.net) at runtime, which is disclosed in the README and is inherent to its purpose of fetching religious texts.
  • The migration script in Paths.js uses a shell command with positional arguments, but it only copies files if the source exists and destination does not, and touches a marker file; no dangerous operations are performed.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/korex-f/daily-islamic-reminder --enable
Widgets #bar #quickshell #system

Daily Islamic Reminder for Omarchy

An Omarchy Quattro bar widget and panel that presents a daily Quran ayah, a graded Hadith, or both. The bar stays compact; click Today’s Reminder to read Arabic and English text, provenance, and the visible Hadith grade.

Plugin preview

What it does

  • Rotates Quran and Hadith independently once per local calendar day.
  • Supports sequential (resumable) or deterministic random rotation per source.
  • Defaults to both sources, Saheeh International (en.sahih), and records graded sahih or hasan. The default any collection pool uses Sahih al-Bukhari and Sahih Muslim; other collection records are considered only when their source-supplied grade passes the active filter.
  • Keeps Quran Arabic separate from translation, and presents Hadith metadata separately so no commentary can be mistaken for Quran text.
  • Caches immutable text and edition metadata under $XDG_CACHE_HOME/dki.quran-verse-of-the-day/ (default ~/.cache/...) and rotation state under $XDG_STATE_HOME/dki.quran-verse-of-the-day/ (default ~/.local/state/...). Existing data under the former Omarchy plugin cache is copied once when the new locations are initialized.

Sources and attribution

  • Quran Arabic, translations, and optional recitation links come from Al Quran Cloud / api.alquran.cloud. The selected edition is named beneath each translation.
  • Hadith Arabic, English, collection/book references, and grade metadata come from fawazahmed0/hadith-api, served through jsDelivr. A Hadith is never rendered without a visible grade.

Neither source needs an API key; this repository contains none.

Install

omarchy plugin add https://github.com/korex-f/daily-islamic-reminder.git --enable

The widget is added to the right bar section. To move it:

omarchy bar plugin move dki.quran-verse-of-the-day --section center

Settings

Click the widget, then use the persistent gear icon in its panel. Settings are saved to the Omarchy bar entry and include:

  • Quran translation edition, with a searchable sensible-English list or a directly entered Al Quran Cloud edition code;
  • preferred Hadith collection (any, Bukhari, Muslim, Abu Dawud, or Tirmidhi);
  • rotation mode (both, quran-only, or hadith-only);
  • sequential/random order independently for Quran and Hadith;
  • the opt-in filter to include grades beyond sahih/hasan; and
  • optional Quran recitation link.

On first open the panel opens its settings surface with suggested defaults; there is no install-time wizard or background service.

Network, cache, and privacy

The plugin runs commands through Omarchy’s unsandboxed shell integration to make HTTPS curl requests to the two sources above. It requests only selected, uncached immutable records on panel open, plus Quran edition metadata at most weekly. No account, API key, telemetry, or personal content is sent.

There is no offline catalogue bundled with the plugin. Previously viewed items remain readable from the local cache; a new uncached item needs network access. Al Quran Cloud has a soft per-second rate limit, so the plugin deliberately does not poll in the background.

Remove cleanly

omarchy plugin remove dki.quran-verse-of-the-day
rm -rf "${XDG_CACHE_HOME:-$HOME/.cache}/dki.quran-verse-of-the-day" "${XDG_STATE_HOME:-$HOME/.local/state}/dki.quran-verse-of-the-day"

The second command is optional and removes only this plugin’s cached texts and rotation state. Legacy data is read from ~/.config/omarchy/plugins/dki.quran-verse-of-the-day/cache during the one-time migration.

Development checks

omarchy plugin validate .
qmllint BarWidget.qml Panel.qml Service.qml
node tests/model.test.js
node tests/runtime.test.js

License

MIT. See LICENSE.