Omahub
← All plugins
J

Swing Music Search

by Jake

Search a self-hosted Swing Music library from the Omarchy bar.

Security review

No obvious issues detected

Deterministic scan — not a security guarantee

None
Risk level
None
Analyzed commit
630dfed
Scanned
1 month ago

No potentially dangerous behavior detected in the analyzed commit.

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

None
AI risk level
None
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
630dfed
Reviewed
1 month ago

The plugin is a well-structured media search/playback widget that connects to a self-hosted Swing Music server. The Python helper uses only the standard library, stores the password in the system keyring, enforces strict response size limits, and performs no destructive or hidden operations. The QML code is straightforward UI logic with no obfuscation or suspicious behavior.

How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/JakeWayneMurray/Swing-Music --enable
Widgets #bar

Swing Music for Omarchy Quattro

Search and play a self-hosted Swing Music library from the Omarchy top bar.

Features

  • Connects with a Swing URL, username, and password.
  • Stores the password in the desktop Secret Service keyring.
  • Shows Songs, Albums, Artists, and Playlists category bubbles.
  • Loads up to 20 recently played items (then alphabetical fallback) when a category is selected before searching.
  • Searches within the selected category.
  • Plays songs, albums, artists, and playlists through mpv.
  • Shows album art and Previous, Pause/Play, Next, and Stop controls.
  • Opens result pages in Swing with right-click.
  • Accepts browser URLs ending in /#/ and works with HTTP or HTTPS servers.

Install

omarchy plugin add https://github.com/JakeWayneMurray/Swing-Music.git --enable

The plugin appears as io.github.jakewaynemurray.swing-music. Click its music note icon in the bar, then enter the Swing server URL, username, and password.

For a local server, use its API origin, for example: http://192.168.2.69:1970 (the helper removes a copied /#/ suffix).

Dependencies and permissions

  • Omarchy Quattro and its standard QML imports.
  • Python 3 standard library (no Python packages are installed).
  • mpv for audio playback.
  • secret-tool and a Secret Service provider for password storage.
  • xdg-open for the optional Open Swing action.

The helper runs as the logged-in user. It makes authenticated HTTP requests to the configured Swing server, starts a user-owned mpv process, and creates mode-0600 temporary runtime files under $XDG_RUNTIME_DIR. It does not use sudo, install services, or modify system files. The saved config contains only the server URL and username; the password remains in the desktop keyring. HTTP response bodies are capped at 8 MiB (error bodies at 64 KiB), playback is capped at 1,000 tracks, and generated playlist/state/output data has strict size limits before it is written or sent to the shell.

Remove

omarchy plugin remove io.github.jakewaynemurray.swing-music

Removing the plugin removes its bar widget. It does not delete the keyring entry or your Swing Music server data. Use the plugin's Change connection flow or remove the omarchy/swing-music keyring entry separately if desired.

Validate from a checkout

omarchy plugin validate .
qmllint -I "$OMARCHY_PATH/shell" BarWidget.qml Panel.qml