Omahub
← All plugins
A

Zonitor

by Andres Ochoa

Live ZEC price and shielded-pool stats for the Omarchy bar, with optional Nasdaq CYPH.

Security review

Review recommended · 2 findings

Deterministic scan — not a security guarantee

Low
Risk level
Low
Analyzed commit
1f0d385
Scanned
1 month ago

Flagged patterns appear only in documentation files (README / docs) — descriptive examples, not executable code.

  • Docs sudo README.md:36

    Command runs with sudo, elevating the process beyond the plugin environment.

    sudo or pkexec is required. No extra packages, API keys, or accounts.
  • Docs sudo SECURITY.md:7

    Command runs with sudo, elevating the process beyond the plugin environment.

    sudo or pkexec is required, and none is used.

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
1f0d385
Reviewed
1 month ago

The plugin is a display-only bar widget that fetches public cryptocurrency data via curl from hardcoded HTTPS endpoints. It does not use sudo, install anything, or access sensitive files. The deterministic scan flagged 'sudo' mentions in documentation, but these are only descriptive text stating that no sudo is used, not actual commands.

  • The plugin runs curl commands, but they are bounded with --max-time and --max-filesize, and URLs are hardcoded to trusted public APIs.
  • It writes only to its own entry in ~/.config/omarchy/shell.json, which is expected for configuration.
  • No installer, remote code execution, or credential access is present.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/andresochoas/zonitor --enable
Widgets #bar #quickshell

Zonitor

An Omarchy bar widget that keeps Zcash ($ZEC) one glance away: live USD price, 24h range, and shielded-pool stats. Nasdaq $CYPH (Cypherpunk Technologies, the public ZEC treasury company) is optional and off by default.

This is not a wallet. It never touches keys, nodes, or funds.

Zonitor on Osaka Jade, 30-day ZEC trend

Bar widget:

Zonitor bar pill

Same panel on other Omarchy themes:

Tokyo Night

Catppuccin Latte

Rose Pine

Features

  • Compact bar pill: $ZEC $816 ▼5.8%
  • Panel with last price, 24h change / high / low / volume, and a sparkline
  • Ironwood migration and shielded vs transparent supply
  • Block height, recent shielded transaction share, and CipherScan privacy score
  • Optional $CYPH quote, lit from the filter row and stored in shell.json
  • Last good values stay on screen when a feed is down

Requirements

  • Omarchy 4 with omarchy-shell
  • curl (already on a standard Omarchy install)
  • Outbound HTTPS to the hosts listed in SECURITY.md

No sudo or pkexec is required. No extra packages, API keys, or accounts.

Install

omarchy plugin add https://github.com/andresochoas/zonitor.git

omarchy plugin add clones the repo into ~/.config/omarchy/plugins/io.github.andresochoas.zonitor/ and leaves it disabled so you can read the code first. Then:

omarchy plugin enable io.github.andresochoas.zonitor

For a non-interactive add:

omarchy plugin add https://github.com/andresochoas/zonitor.git --enable --yes

Move it later with:

omarchy bar move io.github.andresochoas.zonitor --section right

Usage

Input Action
Left click Open / close the panel
Middle click Refresh now
r (panel focused) Refresh now
Escape Close the panel
Tab Next bar panel
Show / Hide Turn the optional CYPH quote on or off

Configure

Settings live on the widget entry in ~/.config/omarchy/shell.json:

omarchy bar set io.github.andresochoas.zonitor showCyph true --json
omarchy bar set io.github.andresochoas.zonitor showChange true --json
omarchy bar set io.github.andresochoas.zonitor compact true --json
omarchy bar set io.github.andresochoas.zonitor pollSeconds 10
omarchy bar set io.github.andresochoas.zonitor chartRange 7d
Key Default Meaning
showCyph false Show Nasdaq CYPH in the panel (never on the bar)
showChange true Append 24h change to the ZEC pill
compact false $816 instead of $815.63 on the bar
pollSeconds 10 ZEC ticker interval (minimum 5)
chartRange today Sparkline window: today, 7d, 30d, 1y, or max

Remove

omarchy plugin remove io.github.andresochoas.zonitor

That disables the widget, drops its shell.json entry, and deletes the git checkout. Nothing else is touched.

Data sources

Feed Source Auth
ZEC/USD ticker and candles Bitfinex public REST none
Shielded pools, height, privacy score CipherScan public REST none
CYPH Yahoo Finance public chart API none

Prices and chain stats are informational and may be delayed or wrong. Do not trade off a status bar.

Not affiliated with the Zcash Foundation, Electric Coin Company, CipherScan, Bitfinex, Yahoo, Nasdaq, or Cypherpunk Technologies.

Develop

node tests/model.test.js
omarchy plugin validate .
qmllint -I /usr/share/omarchy/shell BarWidget.qml Panel.qml Sparkline.qml SplitBar.qml MeterSection.qml BusySpinner.qml

Model.js is dependency-free JavaScript so Node can test parsing without QML.

License

MIT — see LICENSE.