Omahub
← All plugins
M

Mushaf

by MuhammadArham

Mushaf: offline Quran reader for the Omarchy bar. Uthmani Arabic text with Sahih International translation, reference jump, no audio.

Security review

Review recommended · 2 findings

Deterministic scan — not a security guarantee

Low
Risk level
Low
Analyzed commit
68e7007
Scanned
1 month ago

Flagged patterns appear only in documentation files (README / docs) — descriptive examples, not executable code.

  • Docs external_hosts NOTICE.md:79

    Downloads or connects to an external HTTP(S) host.

    curl -o /tmp/ar.json "https://api.alquran.cloud/v1/quran/quran-uthmani"
  • Docs external_hosts NOTICE.md:80

    Downloads or connects to an external HTTP(S) host.

    curl -o /tmp/en.json "https://api.alquran.cloud/v1/quran/en.sahih"

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

None
AI risk level
None
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
68e7007
Reviewed
1 month ago

This is a straightforward offline Quran reader bar widget with no runtime network access; it reads a bundled JSON data file and writes a small state file under ~/.local/state. The deterministic scan's external_hosts findings are documentation-only curl commands in NOTICE.md for rebuilding the data, not code executed at install or runtime. No obfuscation, destructive commands, credential access, or hidden persistence were found.

How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/ArhamTheDeveloper/mushaf --enable
Productivity #Hyprland #bar #quickshell

Mushaf

Offline Quran reader for the Omarchy bar. Uthmani Arabic text with the Sahih International translation, reference jump, no audio.

Plugin id: io.github.arhamthedeveloper.mushaf.

Install (this machine)

The live copy is:

omarchy plugin validate ~/.config/omarchy/plugins/io.github.arhamthedeveloper.mushaf
omarchy plugin enable io.github.arhamthedeveloper.mushaf --section right

From git later:

omarchy plugin add https://github.com/ArhamTheDeveloper/mushaf.git --enable
omarchy bar move io.github.arhamthedeveloper.mushaf --section right

Usage

  • Left-click the bar chip to open or close the reader.
  • Scroll the chip to move to the previous or next ayah (wraps at surah boundaries, and from An-Nas 6 back to Al-Fatihah 1).
  • Type a reference (2:255, al-baqarah 255, baqarah 255, البقرة 255, yasin 5, iqra) and press Enter to jump.
  • Arrow keys inside the panel: left/right moves surah, up/down moves ayah.
  • Use the surah button in the header to browse all 114 surahs, then pick one to jump to its first ayah.
  • Escape closes the panel. The last position is saved to ~/.local/state/omarchy/settings/quran-reader.json and restored on open.

Data

data/quran.json bundles the full text (6,236 ayahs, ~2.4 MB): Uthmani Arabic plus Sahih International. Text comes from alquran.cloud, sourced from tanzil.net — see NOTICE.md for the required attribution and how to rebuild the file from source.

Tests

node tests/test_quran.js
node tests/verify_arabic.js

test_quran.js covers reference parsing (numbers, transliterations, Arabic names, aliases), surah/ayah navigation and wraparound, and data-file integrity. verify_arabic.js is a deep integrity pass over the bundled text: structure and ayah counts, character hygiene (no mojibake/control/zero-width chars), Arabic-script purity, basmala placement, spot-checks of well-known verses, and a best-effort online cross-check against quran.com's API.

Remove

omarchy plugin remove io.github.arhamthedeveloper.mushaf

The reading position in quran-reader.json is left in place. This plugin is not a clock clone; removing it does not touch omarchy.clock. It also does not touch mus.quran's audio player or its state file (quran.json).

Acknowledgments

This project's code was written with heavy assistance from AI (Codebuff): product direction, design decisions, and review were the author's, while the implementation was largely AI-generated.

The Quran text itself is not AI-generated — the Arabic (Uthmani script) and Sahih International translation are the authoritative Tanzil texts, bundled unchanged (see NOTICE.md).

The plugin's architecture and UX are derived from Canon, an MIT-licensed Bible reader for the Omarchy bar — see NOTICE.md for its license notice.