Omahub
← All plugins
L

omARR

by luccast

The Omarchy Arr stack desktop panel for locally hosted services. With live notifications and controls for Sonarr, Radarr, Jellyfin, Plex, SABnzbd, qBittorrent, and more.

Security review

Review recommended · 1 finding

Deterministic scan — not a security guarantee

Low
Risk level
Low
Analyzed commit
45c4743
Scanned
1 month ago

Flagged patterns appear only in documentation files (README / docs) — descriptive examples, not executable code.

  • Docs external_hosts SECURITY.md:28

    Downloads or connects to an external HTTP(S) host.

    curl --proto =http,https` with `--max-time` and `--max-filesize`. URLs that are not `http://` or `https://` are refused. Redirect following is off. Reply strings render as `PlainText` and elide, so a 

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
45c4743
Reviewed
1 month ago

omARR is a homelab dashboard widget that talks only to user-configured local HTTP(S) services, stores credentials in a 0600 state file, and uses curl with size/time limits and no redirects. The deterministic finding about SECURITY.md is documentation only; the actual code matches the documented behavior and shows no obfuscation, persistence, or destructive actions.

  • Runs unsandboxed inside omarchy-shell with user permissions, so any bug in URL handling or credential storage is a local risk; the README discloses this.
  • Credentials (API keys, Plex/Jellyfin tokens, qBittorrent passwords) are stored in plaintext JSON under ~/.local/state/omarchy/omarr/credentials.json, protected only by 0600 permissions.
  • The plugin invokes curl and omarchy launch browser with user-supplied URLs; isHttpUrl() restricts to http/https, but a user could intentionally add a URL to a hostile server that returns malicious content rendered in the panel.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/luccast/omARR --enable
Other #bar #launcher #media

omARR

The Omarchy Arr stack desktop plugin for homelabs.

omARR is an Omarchy bar plugin for homelab people who already run Sonarr, Radarr, Plex, Jellyfin, SABnzbd, or qBittorrent. Click the skull icon to see your *arr fleet on the left and a live content overview on the right. Now playing, on deck, recently added, and calendar. Add custom links and use as a homelab launcher, all without leaving the Omarchy desktop.

omARR panel

Top features

  • Bar badge for active downloads and outages
  • Fleet roster with live health for every service you add
  • Overview: Plex and Jellyfin now playing and on deck, Sonarr/Radarr calendar, SABnzbd and qBittorrent queues
  • Live download notification card that stays up while SAB or qBit is actually downloading
  • Toasts for grabs, imports, finished or failed downloads, and services that drop or recover
  • Pause and resume a job from the panel
  • Scan local ports, or add any URL as a generic up/down tile
  • Add custom links and use as a launcher
  • Deeper support for more services coming soon

omARR download notification

Plugins run unsandboxed inside omarchy-shell with your user permissions. Read the code before you enable it.

Install

omarchy plugin add https://github.com/luccast/omARR.git --enable

The widget lands on the right side of the bar. Move it with:

omarchy bar move io.github.luccast.omarr

Update later with omarchy plugin update io.github.luccast.omarr.

Use

Action Result
Click the bar icon Open or close the panel
j / k Move through the fleet
Enter Open the selected service in the browser
Space Open that service’s detail, or return to Overview
s Settings
Escape Close

Toasts for grabs, imports, Plex and Jellyfin library adds, finished or failed downloads, and services going down or coming back. Click a toast to summon the panel.

While SABnzbd or qBittorrent is actually downloading, a progress card stays on screen (progress bar, title, client icon, poster when *arr has one). Those two clients poll every 2s so short jobs still get a card; everything else stays on the interval in settings. Seeding torrents are ignored. Dismiss it until that job finishes; turn the card off in settings.

Settings

First open is an empty overview. Add a service by kind, or Scan local ports to probe this machine (8989, 7878, 8080, 8096, 32400, 8123, 9696, 5055).

Kind Auth Live data Controls
Generic none Up / down Open in browser
Sonarr API key Queue, history, 7-day calendar, missing Open in browser
Radarr API key Queue, history, calendar, missing Open in browser
SABnzbd API key Queue, history, speed Pause / resume a job
Plex token Now playing, on deck, recently added Open in browser
Jellyfin API key Now playing, resume, recently added Open in browser
qBittorrent username + password Torrents, transfer speed Pause / resume a torrent

Overview shows a service’s queue or *arr calendar only when that service has the matching toggle on. SABnzbd and qBittorrent queues default on; Sonarr and Radarr queues default off.

Layout (names, URLs, groups, order, notification flags, poll interval, queue page size, density, download progress card) is stored in ~/.config/omarchy/shell.json. API keys, Plex tokens, Jellyfin keys, and passwords are stored only in ~/.local/state/omarchy/omarr/credentials.json (0600).

Icons

Fleet and settings tiles use Dashboard Icons from Homarr Labs (Apache 2.0). The colorful SVGs are bundled under icons/ so the panel never fetches a CDN at runtime. Kind tiles (Sonarr, Radarr, SABnzbd, qBittorrent, Plex) always get that icon; generic tiles match on the service name.

Service Icon
Sonarr sonarr
Radarr radarr
Lidarr lidarr
Prowlarr prowlarr
Bazarr bazarr
Readarr readarr
Whisparr whisparr
SABnzbd sabnzbd
qBittorrent qbittorrent
NZBGet nzbget
Transmission transmission
Deluge deluge
Jellyfin jellyfin
Plex plex
Emby emby
Jellyseerr jellyseerr
Overseerr overseerr
Tautulli tautulli
Kodi kodi
Navidrome navidrome
Audiobookshelf audiobookshelf
Komga komga
Kavita kavita
Calibre-Web calibre-web
Immich immich
Home Assistant home-assistant
Portainer portainer
Grafana grafana
AdGuard Home adguard-home
Pi-hole pi-hole
Uptime Kuma uptime-kuma
Syncthing syncthing
Nextcloud nextcloud
Nginx Proxy Manager nginx-proxy-manager
Traefik traefik
Paperless-ngx paperless-ngx

Name a generic tile after one of those (or a close alias like pihole) and the matching icon shows up. Unknown names fall back to a letter tile. The bar keeps the omARR glyph.

Remove

omarchy plugin remove io.github.luccast.omarr

Develop

node tests/Model.test.js
omarchy plugin validate .
qmllint -I "$OMARCHY_PATH/shell" BarWidget.qml Panel.qml Service.qml SettingsView.qml OmarrIcon.qml ServiceIcon.qml CalendarCard.qml DownloadToast.qml