Omahub
← All plugins
J

CoinGecko

by Jonny Heggheim

Cryptocurrency prices from CoinGecko in the Omarchy bar: a live ticker for your favourite coin plus a popup with price, 1h/24h/7d change, market cap and rank for every coin you follow.

Security review

Review recommended · 1 finding

Deterministic scan — not a security guarantee

Low
Risk level
Low
Analyzed commit
51aee7b
Scanned
1 month ago

Flagged patterns appear only in documentation files (README / docs) — descriptive examples, not executable code.

  • Docs external_hosts README.md:19

    Downloads or connects to an external HTTP(S) host.

    git clone https://github.com/hegjon/omarchy-coingecko \

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
51aee7b
Reviewed
1 month ago

The plugin is a straightforward CoinGecko price ticker that fetches market data via curl and renders it in a QML widget. The only flagged item is a git clone URL in the README, which is documentation and not executable code. No obfuscation, persistence, credential theft, or destructive commands were found.

  • The deterministic scan flagged an external host in the README (git clone URL), but this is documentation only and not part of the plugin's runtime behavior.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/hegjon/omarchy-coingecko --enable
Appearance #bar

CoinGecko for Omarchy

Cryptocurrency prices from CoinGecko in the Omarchy bar.

Bar ticker and popup

  • A live ticker on the bar: BTC $64.6k ▲0.5% for your first coin, every coin you follow, or just an icon.
  • A popup with price, 1h / 24h / 7d change, market cap and rank for each coin, sorted by market cap (or configured order, or 24h change). Click a coin to open its CoinGecko page; press R to refresh.
  • Any of CoinGecko's quote currencies (USD by default; EUR, NOK, BTC, …).
  • No account needed. An optional free Demo API key raises the rate limit.

Install

git clone https://github.com/hegjon/omarchy-coingecko \
  ~/.config/omarchy/plugins/hegjon.coingecko
omarchy bar put hegjon.coingecko

The shell picks up the new plugin without a restart. If it does not, run omarchy restart shell.

Settings

Change them from the bar's widget settings, or with omarchy bar set:

omarchy bar set hegjon.coingecko coins "bitcoin,ethereum,solana"
omarchy bar set hegjon.coingecko currency EUR
omarchy bar set hegjon.coingecko barDisplay "All coins"
omarchy bar set hegjon.coingecko showChangeInBar false --json
Key Default Meaning
coins bitcoin,solana,monero,stellar,bitcoin-cash Comma-separated CoinGecko ids. The first is the one on the bar.
currency USD Quote currency code, case-insensitive.
barDisplay First coin First coin, All coins or Icon only.
panelSort Market cap Popup order: Market cap, Configured order or 24h change.
showChangeInBar true Append the 24h change to the ticker.
compactPrices true 64.6k instead of 64,568 on the bar. The popup is never compact.
refreshIntervalSec 300 Poll interval, 60–3600 s.
apiKey (empty) CoinGecko Demo API key, sent as x-cg-demo-api-key.

Coin ids are the slug in a coin's CoinGecko URL: coingecko.com/en/coins/solana → solana. Ids the API does not know are listed in the popup rather than silently dropped.

Rate limits

CoinGecko's public endpoint allows roughly 5–15 requests a minute per IP and serves prices cached for about a minute, so the widget polls no faster than every 60 s and defaults to 300 s. When CoinGecko answers 429, the popup says so and the last known prices stay on screen; a longer interval or a free Demo key is the fix.

IPC

omarchy-shell hegjon.coingecko open|close|toggle|refresh

How it works

coingecko-fetch does the one HTTP request (/coins/markets) with curl and normalizes the answer with jq (normalize.jq); the widget (CoingeckoWidget.qml) only ever runs that script and renders its JSON. The API key travels in the environment, never on the command line.

Development

test/lint runs qmllint with the shell's modules on the import path; test/test-normalize exercises normalize.jq against the fixtures under test/fixtures/; test/test-manifest checks manifest.json against the shell's rules, and omarchy plugin validate . is the authority on an Omarchy machine. CI (.github/workflows/ci.yml) runs the hermetic subset: manifest, shellcheck and normalization.

License

MIT — see LICENSE. Data is provided by CoinGecko under their terms.