Omahub
← All plugins
E

Omaspotify

by Elliot Moreau

Spotify MPRIS controller with album art, seekable progress bar, and playback controls in a popup panel

Security review

No obvious issues detected

Deterministic scan — not a security guarantee

None
Risk level
None
Analyzed commit
4411d10
Scanned
1 month ago

No potentially dangerous behavior detected in the analyzed commit.

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

None
AI risk level
None
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
4411d10
Reviewed
1 month ago

The deterministic scan found no issues, and manual review confirms this is a benign QML bar widget that reads Spotify MPRIS metadata and provides playback controls. There are no install scripts, no persistence mechanisms, no credential access, and no destructive or obfuscated code. The plugin is disabled by default and only interacts with the user's Spotify session via standard MPRIS D-Bus interfaces.

How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/cempack/omaspotify --enable
Widgets #bar #quickshell #media

Omaspotify

preview

Bar widget + popup panel for Spotify via MPRIS (Quickshell.Services.Mpris).

This is the maintained cempack fork of archlatam/omaspotify, with working cover and artist metadata, a compact theme-aware panel, and clearer playback state coloring.

No background service or persisted state — everything is read live from Spotify's D-Bus interface. Click the Spotify icon in the bar to open the popup with album art, track info, seekable progress bar, and playback controls.

Requirements

  • Omarchy (Quickshell-based desktop environment)
  • Spotify official Linux client running — exposes MPRIS while open
  • Nerd Fonts (for the Spotify icon glyph in the bar)

If the official client doesn't report position/volume reliably (a known MPRIS limitation), you can use spotifyd or a shim like mpris-proxy as an alternative; the widget still works with the basic MPRIS fields (title, artist, play/pause, next/prev).

Install

omarchy plugin add https://github.com/cempack/omaspotify.git

The plugin is disabled by default so you can review the code first:

omarchy plugin enable io.github.cempack.omaspotify

Then add it to the bar — you'll be asked where to place it:

omarchy bar plugin add io.github.cempack.omaspotify

You can also drag-and-drop it to reposition it later, or edit ~/.config/omarchy/shell.json manually.

Usage

  • Left click — open/close the popup panel
  • Middle click — toggle play/pause directly without opening the panel
  • Popup controls — previous, play/pause, next; drag the progress bar to seek

Keyboard shortcuts

Inside the popup:

Key Action
Space Play / Pause
n Next track
p Previous track
Left / Right Previous / Next track
Enter Play / Pause
Escape Close popup
Tab Switch to adjacent panel

Suggested global keybinding (~/.config/hypr/bindings.lua):

o.bind("SUPER + M", "Toggle Omaspotify", "omarchy-shell io.github.cempack.omaspotify toggle")

Update

omarchy plugin update io.github.cempack.omaspotify

Uninstall

omarchy plugin disable io.github.cempack.omaspotify
omarchy plugin remove io.github.cempack.omaspotify

Then remove the entry from ~/.config/omarchy/shell.json.

Multi-source note

If you have multiple MPRIS players active (e.g. a browser with YouTube), the widget filters specifically by identity === "Spotify" / desktopEntry === "spotify" so it doesn't jump between sources. To make it source-agnostic (any active player), remove that filter in Panel.qml and use Mpris.players.values[0] instead.