Omahub
← All plugins
J

Bazaar

by Jeremy Longshore

Bazaar brings the Omarchy plugin marketplace to your bar. Search names, descriptions, tags, and authors; filter by category or kind; rank trending by views per day since listing; and flag listings whose marketplace record has no install command. Save a private local shortlist, see listings added since your last visit, open a listing or repo, copy a safe CLI command, or install from a validated GitHub URL. Catalog refreshes every six hours and stats every 30 minutes. No account data is ever sent.

Security review

Potentially dangerous behavior detected · 9 findings

Deterministic scan — not a security guarantee

High
Risk level
High
Analyzed commit
0163268
Scanned
1 week ago
  • high destructive_filesystem scripts/rig-verify.sh:76

    Destructive operation on the root filesystem or a block device.

    rm -rf /tmp/$NAME && mkdir -p /tmp/$NAME && tar xzf /tmp/$NAME.tgz -C /tmp/$NAME' || exit 3
  • high destructive_filesystem scripts/rig-verify.sh:97

    Destructive operation on the root filesystem or a block device.

    rm -rf /tmp/$NAME /tmp/$NAME.tgz >/dev/null 2>&1
  • medium external_hosts tests/model.test.js:330

    Downloads or connects to an external HTTP(S) host.

    git clone https://x\nrm -rf ~"), "")
  • medium external_hosts tests/model.test.js:331

    Downloads or connects to an external HTTP(S) host.

    git clone https://x\r\nevil"), "")
  • medium external_hosts tests/model.test.js:334

    Downloads or connects to an external HTTP(S) host.

    git clone https://x  "), "git clone https://x")
  • Augments a command with octal/hex escape sequences.

    \x89PNG\r\n\x1a\n" or raw[12:16] != b"IHDR":
  • Docs external_hosts docs/FIXTURES.md:8

    Downloads or connects to an external HTTP(S) host.

    curl -sf  https://plugins.omarchy.org/catalog.json     -o /tmp/catalog.json
  • Docs external_hosts docs/FIXTURES.md:9

    Downloads or connects to an external HTTP(S) host.

    curl -sfL https://api.omarchyplugins.com/v1/stats      -o /tmp/stats.json
  • Docs external_hosts README.md:79

    Downloads or connects to an external HTTP(S) host.

    git clone https://github.com/jeremylongshore/omarchy-bazaar-entry.git \

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
0163268
Reviewed
1 week ago

The plugin is a marketplace browser that fetches catalog and stats from official Omarchy endpoints, renders untrusted text safely, and only installs plugins via the official `omarchy plugin add` CLI after validating the URL is a GitHub repository. The deterministic scan's high-risk findings are all in developer-only scripts (rig-verify.sh, rig-render.sh) that never run on an end-user machine, and the obfuscation finding is a false positive (PNG header check). No credential theft, persistence, or destructive runtime behavior was found.

  • The plugin fetches data from external hosts (plugins.omarchy.org, api.omarchyplugins.com) on a timer; this is expected functionality but does involve network activity.
  • The install action runs `omarchy plugin add` with a URL from the catalog; the URL is validated to be a GitHub URL, and the command is executed without a shell, so injection risk is low.
  • The clipboard copy uses wl-copy with stdin and refuses newlines, mitigating paste-based command injection.
  • The plugin scans ~/.config/omarchy/plugins with a bounded bash command; the command is fixed and does not interpolate untrusted data.
  • The deterministic scan flagged destructive `rm -rf` in scripts/rig-verify.sh, but these are development/CI tooling that never ships to users.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/jeremylongshore/omarchy-bazaar-entry --enable
Productivity #bar #quickshell
<p align="center"><img src="assets/banner.svg" alt="Bazaar" width="100%"></p>

Bazaar

The plugin marketplace, in your bar. Search every listing, filter by category, sort by what is actually trending, and copy an install command without opening a browser.

Bazaar preview

You are in a terminal. You want a clipboard widget, or a VPN indicator, or something you cannot name yet. The marketplace is a website, so finding out means leaving what you were doing, loading a page, scrolling, and coming back.

Bazaar puts the whole catalog behind one key. Type a few letters, get the matches ranked, press enter, and the install command is on your clipboard. The pill counts what has been listed since you last looked and shows nothing when you are caught up.

ko-fi

Trending means views per day, not a running total

Hearts, installs and views are cumulative counters. Ranking on them returns whatever has been listed longest and calls it popular, which is why the same handful of plugins sit at the top of every "most hearted" list forever.

The catalog records when each plugin was listed, so Bazaar divides: views per day since listing. That is the only figure here that distinguishes what is hot right now from what has been around longest, and it costs one division.

Sort by trending, hearts, installs, views, GitHub stars, newest, or name. Whatever you choose, the bar under each row shows relative magnitude, scaled to the 90th percentile rather than the maximum so one runaway listing does not flatten everything else into an invisible sliver.

It tells you when a plugin cannot be installed

The marketplace publishes, for every listing, whether an install command exists. Bazaar reads that flag and marks the ones that have none.

This is not a rare edge case. Some popular listings require manual setup because the marketplace has no install command for them. Bazaar shows you that before you spend time on a listing rather than after.

A shortlist the website cannot give you

Marketplace hearts are anonymous aggregates by design: the engagement service stores no accounts, no cookies and no browser identifiers. That is a good privacy decision, and it means there is no "plugins I hearted" to fetch back.

Bazaar keeps a saved list locally instead. Press s to save, a to show only saved. It lives in your own state directory, it is yours, and it is the one feature here that a website structurally cannot offer.

Keys

Key Action
/ search by name, description, tag or author
j k or arrows move
enter copy the install command
o open the repository
s save or unsave
a show only saved
t cycle sort
c clear search and filters
r refresh now
esc close

Category filters are pills you can click. Left-click a row copies its install command; right-click opens its repository.

Install

Copy the plugin into your Omarchy plugins directory and enable it in the bar:

git clone https://github.com/jeremylongshore/omarchy-bazaar-entry.git \
  ~/.config/omarchy/plugins/bazaar

Then add io.github.jeremylongshore.bazaar to your bar layout in ~/.config/omarchy/shell.json, or enable it from the Omarchy settings UI.

To remove it, delete that directory, drop the entry from your bar layout, and optionally rm -rf ~/.local/state/omarchy/bazaar to clear the cache and your saved list.

Settings

Setting Default What it does
Default sort Trending which ranking the panel opens on
Count new listings on the pill On show how many plugins appeared since you last looked
Flag listings nobody can install On mark plugins whose install command is missing
Desktop notifications Off notify when new plugins are listed

How it works

No node, no python, no external runtime. A stock Omarchy install has no node on the graphical session PATH, so the whole plugin is Quickshell plus the curl your box already ships. Parsing lives in a pure Model.js that loads unchanged in the shell and in node, which is how the offline suite covers it.

Two sources, refreshed on different cadences because they cost different amounts:

Source Size Cadence
plugins.omarchy.org/catalog.json about 1.2 MB gzipped (9.1 MB decoded, 2026-09-20), growing every 6 hours, conditionally
api.omarchyplugins.com/v1/stats 15 KB gzipped every 30 minutes

The catalog carries an ETag, so an unchanged catalog answers 304 with no body at all. Both are cached under ~/.local/state/omarchy/bazaar/ through FileView with atomic writes, so a killed shell never leaves half a file. The panel refreshes on open when the cache is stale, and is idle otherwise.

Neither request is authenticated and neither carries anything about you. Bazaar only reads.

Safety

Every listing is written by a third party, so all of it is treated as untrusted input. Names, descriptions, tags and authors render as PlainText, width-bound and elided, so a long or hostile name cannot push a row or shove the stats off the panel.

The install command is the one string that reaches your clipboard, and it is refused outright if it contains a newline, because a newline in a pasted command runs a second command. It reaches wl-copy on stdin rather than through a shell, so there is nothing to quote and nothing to escape.

Repository links are opened only when they match https://github.com/....

Tests

npm test

The suite runs against real catalog and stats payloads captured from the live marketplace, never the network.

Maintainers wanted

These plugins are growing, and we are looking for dependable Omarchy users who want to review issues, test releases, and keep a plugin healthy over time. Start with a small pull request or open a maintainer interest issue titled Maintainer interest. Tell us which plugin you use and how you want to help. Consistent contributors can earn maintainer responsibility.

License

MIT. See LICENSE.