Omahub
← All plugins
D

Omarchy Market

by DPRC137

Native Omarchy/Quattro financial market ticker and compact market terminal

Security review

Review recommended · 1 finding

Deterministic scan — not a security guarantee

Low
Risk level
Low
Analyzed commit
2504e9e
Scanned
1 week ago

Flagged patterns appear only in documentation files (README / docs) — descriptive examples, not executable code.

  • Docs external_hosts README.md:72

    Downloads or connects to an external HTTP(S) host.

    git clone https://github.com/DPRC137/omarchy-market.git ~/.config/omarchy/plugins/io.github.dpr.omarchy-market

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

None
AI risk level
None
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
2504e9e
Reviewed
1 week ago

This is a financial market ticker that fetches public market data from Yahoo Finance, Binance, Coinbase, and Hyperliquid using QML XMLHttpRequest and a bundled Node.js WebSocket bridge. The code is transparent, uses expected public APIs, has no install-time scripts, no obfuscation, no credential handling, and no destructive behavior. The deterministic scan's external_hosts finding refers only to the README's documented git clone install command, not to executable plugin code.

  • Enabling the plugin launches Node.js WebSocket bridge subprocesses that connect to external market-data services; this is expected plugin functionality and requires user consent through installation.
  • Stock data comes from unofficial Yahoo Finance endpoints, which may change or rate-limit over time, but this is a usability concern rather than a security risk.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/DPRC137/omarchy-market --enable
Widgets #bar #quickshell #system

Omarchy Market (io.github.dpr.omarchy-market) v1.2.1

A production-quality, native financial market data ticker and compact terminal plugin for Omarchy Quattro.

Preview


Features

  • Dynamic Watchlist & Market Catalog:
    • Add, remove, and reorder up to 20 crypto & stock markets.
    • Curated US equity coverage (e.g. AAPL, MSFT, NVDA, AMZN, GOOGL, META, TSLA, AVGO, AMD, etc.).
    • Dynamic Stock Search: Search and add arbitrary stocks and ETFs beyond the static catalog via unauthenticated Yahoo Finance search with clean, isolated persistence.
    • Integrated search engine with alias resolution (e.g. apple → AAPL, nvidia → NVDA, dogecoin → DOGE, bitcoin → BTC, ether → ETH).
    • Locally persisted via Qt Settings with automatic migration and schema versioning.
    • Horizontally scrollable asset tab bar with reactive gradient edge-fade scroll affordances that indicate available scrollable content.
  • Native Quattro Watchlist Manager:
    • Dedicated ⚙ settings control adjacent to asset tabs.
    • Live search dropdown with instant + Add action for catalog and remote stock search results with asset class tags (STOCK / CRYPTO).
    • Active watchlist list with ↑ / ↓ reordering and ✕ deletion.
  • Live Streaming Multi-Provider Feeds:
    • Yahoo Finance: Direct HTTP Chart API integration with strict rate-limiting serialization and session handling (Regular, Pre-Market, Post-Market, Closed).
    • Binance: Public spot ticker WebSocket streams & REST klines with dynamic subscriptions.
    • Coinbase: Advanced Trade public ticker WebSocket feeds with dynamic IPC channel subscriptions. Unsupported historical candle granularities (4H, 1W) are cleanly blocked at provider entry.
    • Hyperliquid: Real-time mid prices & market contexts (native DEX home of HYPE).
  • Distinct Instrument & Pricing Engine:
    • Distinguishes spot markets (BTC/USDT, BTC/USD), equities (AAPL, NVDA), and perpetuals (HYPE, BTC-PERP).
    • Calculates Reference Spot Price across active spot feeds without cross-market distortion.
    • Routes equities to Yahoo and DEX-native tokens directly to their native feeds.
    • Deterministic Historical Candle Routing: Centralized historical provider resolution (Spot Crypto -> Binance with Hyperliquid fallback; Perps -> Hyperliquid; Equities -> Yahoo) avoiding multi-provider data races and payload collisions.
  • Compact Market Terminal Panel:
    • Large price display with color-coded 24h change & freshness indicator (LIVE, STALE, OFFLINE).
    • 24h High, Low, and USD Volume statistics.
    • Multi-exchange comparison table showing live prices across Yahoo Finance (for stocks) or Binance, Coinbase, and Hyperliquid (for crypto).
    • Native QML Canvas sparkline chart with timeframe selectors (1H, 4H, 1D, 1W).
    • Native Chart Hover Inspection: Crosshair hairline, highlighted data point glow, and formatted date/time and price badge without external charting libraries.
    • Subdued baseline loading state eliminating artificial 3-point synthetic lines on asset or timeframe switches.
    • Single-click + Add to Watchlist action on the asset header.
  • Zero Cost & Zero Daemon:
    • $0 operating cost, zero API keys required, zero paid backends.
    • No background daemons, no extra Quickshell processes, no systemd units, no sudo needed.
  • Resilient & Isolated:
    • Single active HTTP request invariant for Yahoo with minimum 1200ms spacing and exponential backoff with jitter on HTTP 429/5xx.
    • Dynamic subscription updates over stdin without restarting unaffected feeds.
    • Automatic reconnection with exponential backoff and jitter.
    • Independent provider failure isolation (one exchange going down does not disrupt the others or block watchlist editing).
    • Clean process teardown on disable or shell reload with zero orphaned child processes.

Stock Market Data Notice: Stock market data is provided through Yahoo Finance's unofficial Chart API. Availability, rate limits, symbol coverage, delays, and endpoint behavior are controlled by Yahoo Finance and may change without notice.


Prerequisites & Dependencies

  • Desktop Shell: Omarchy Quattro (omarchy-shell / Quickshell 0.3.0+, Qt 6.8+).
  • Runtime Transport: node (Node.js v20+, v22+, or v26+ with native WHATWG WebSocket support, 0 npm packages required).

Installation

Method 1: Automatic via Omarchy CLI

omarchy plugin add https://github.com/DPRC137/omarchy-market.git --enable --yes

Method 2: Manual Installation

  1. Clone or symlink into your Omarchy plugins directory:
    git clone https://github.com/DPRC137/omarchy-market.git ~/.config/omarchy/plugins/io.github.dpr.omarchy-market
    
  2. Rescan and enable:
    omarchy-shell shell rescanPlugins
    omarchy plugin enable io.github.dpr.omarchy-market
    

Removal

Automatic via Omarchy CLI

omarchy plugin remove io.github.dpr.omarchy-market

Manual Removal

rm -rf ~/.config/omarchy/plugins/io.github.dpr.omarchy-market
omarchy-shell shell rescanPlugins

Usage & Controls

  • Left-Click on the bar ticker: Opens / closes the compact Market Terminal popup.
  • Middle-Click: Forces an immediate market data refresh across all providers.
  • Right-Click: Cycles the active single-asset display in compact mode.
  • Watchlist Settings (⚙): Opens the native Watchlist Manager to search, add, reorder, and remove assets.
  • Keyboard in Terminal:
    • Tab / Shift+Tab: Switch between watchlist asset tabs.
    • R: Refresh market data.
    • Escape: Close Watchlist Manager / close terminal popup.

Configuration (shell.json)

Settings can be customized directly in ~/.config/omarchy/shell.json:

{
  "id": "io.github.dpr.omarchy-market",
  "multiAsset": false,
  "speed": 4000
}
  • multiAsset (boolean): Toggle between full multi-asset scrolling ticker and single-asset compact cycling mode.
  • speed (number): Multi-asset cycling interval in milliseconds (default: 4000).

Development & Testing

  • Run the automated test suite:
    ./tests/run_tests.sh
    
  • Run fault-injection tests:
    ./tests/test_fault_injection.sh
    
  • Run live integration connectivity tests:
    ./scripts/live-test.sh
    
  • Monitor live resource usage:
    ./tests/measure_resources.sh