Omahub
← All plugins
B

Cricket

by bhanuprassad

Live cricket in the Omarchy bar. Follow teams, glance at the pill, open the panel for the rest of the card.

Security review

No obvious issues detected

Deterministic scan — not a security guarantee

None
Risk level
None
Analyzed commit
6a8b623
Scanned
1 month ago

No potentially dangerous behavior detected in the analyzed commit.

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

None
AI risk level
None
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
6a8b623
Reviewed
1 month ago

The plugin is a straightforward cricket score widget that fetches data from ESPN via curl with strict constraints (HTTPS-only, no redirects, size caps, allowlisted hosts). It writes only a small follows config file and opens match links only through a safe allowlist. No obfuscation, persistence, or destructive behavior was found.

How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/bhanuprassad/omarchy-cricket --enable
Widgets #bar #quickshell

Cricket

Live cricket in the Omarchy bar. Follow the sides you care about; the pill shows that match, the panel holds the rest of the card.

There is no cricket plugin on the marketplace today. Scores covers the US majors, soccer and racing. This one is only cricket: Tests, ODIs, T20s, the IPL, counties, CPL.

Cricket panel

Install

Review the source first. Plugins run unsandboxed inside the long-lived Omarchy shell.

omarchy plugin add https://github.com/bhanuprassad/omarchy-cricket.git --enable
omarchy bar move io.github.bhanuprassad.cricket --section right

Needs curl and head. No API key.

Usage

Click the pill to open the panel. Right-click refreshes. Middle-click opens the current match in the browser.

Key Action
j k Move
f Follow the side under the cursor
x Unfollow it
o / Enter Open the match on ESPN
/ Search teams and matches
r Refresh now
Esc Leave search, then close

On a match row, f follows the home side first, then the away side. Search for india, MI, surrey even when they are not playing today.

Bar Meaning
AUS 165/8 BAN 64 A followed match is live
IND v PAK · 2h Next followed match
Dim ball Nothing you follow is on — open the panel and pick a side

Several followed matches at once rotate on the pill. Scroll the widget to step through them.

Configure

Follows are written to ~/.config/omarchy/cricket.json when you press f. You can also set them from the shell:

omarchy bar set io.github.bhanuprassad.cricket followedTeams "IND, AUS, MI"

Known aliases include India, RSA, Windies, and the IPL names (Mumbai Indians → MI).

Key Default What
followedTeams "" comma-separated abbreviations
livePollSec 45 refresh while a followed match is live
idlePollSec 600 floor when nothing you follow is on

Removal does not delete cricket.json.

Where the data comes from

One ESPN endpoint, the same JSON espn.com's cricket header calls:

https://site.web.api.espn.com/apis/v2/scoreboard/header?sport=cricket

No key, no signup. It is not a documented or supported API and can change without notice. The plugin sends no User-Agent: some ESPN hosts 403 a browser-shaped one and 200 curl's own.

Polling backs off when nothing you follow is live. Requests are HTTPS-only to that host, do not follow redirects, and are capped at 256 KiB before anything is kept in the shell. Match links open only if they are https:// on ESPN / ESPNcricinfo. Cache files live in ~/.cache/omarchy/io.github.bhanuprassad.cricket/. Follows are read with the same byte cap; the widget does not load shell.json.

Remove

omarchy plugin remove io.github.bhanuprassad.cricket

Dependencies

  • Omarchy Quattro (omarchy-shell, qs.Commons, qs.Ui)
  • curl

The plugin does not install packages, add hooks, or start a second Quickshell process.

License

MIT. See LICENSE.

Match names, scores and badges come from ESPN and belong to their owners. This plugin is not affiliated with ESPN or any board.

Develop

BarWidget.qml   the bar slot: pill, poll, follows
Panel.qml       the panel: card, search, keys
Model.js        parse, follow, bar line, rows

Model.js is plain functions. Run it under Node:

node Model.test.js
node static.test.js
node live.test.js