Omahub
← All plugins
O

World Clock

by Olivier Melcher

A native Omarchy world clock for comparing time and weather across places, converting time zones, and pinning places to the bar.

Security review

Review recommended · 3 findings

Deterministic scan — not a security guarantee

Medium
Risk level
Medium
Analyzed commit
9f7865a
Scanned
4 weeks ago

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
9f7865a
Reviewed
4 weeks ago

The plugin is a legitimate world clock widget for Omarchy. The flagged items are not part of the plugin's runtime path: the `apt-get` calls appear in a build/verification script (`scripts/check-globe-artifacts.sh`) used only during development, not during installation or normal use. The octal/hex escape sequence in `src/config.rs` is likely a false positive or a minor string encoding issue (e.g., a null byte in a timezone name) rather than obfuscation; the source is open and the backend is reproducible from the checked-in Rust code. The plugin does make network requests to Open-Meteo for weather and city search, which is expected functionality. The precompiled backend binary is a static PIE with checksums and reproducibility scripts, reducing supply-chain risk. No malicious behavior was observed in the sampled files.

How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/olivoil/omarchy-world-clock --enable
Widgets #bar #quickshell #system

Omarchy World Clock

A native Omarchy Quattro world clock. Open the bar widget for current time and weather across your places, add new timezones, pin the ones you want always visible, or scrub and enter times to convert from one timezone to the others.

This repository is the installable root of the native Quattro plugin io.github.olivoil.world-clock. It is listed in the independent community Omarchy Plugin Marketplace.

<p> <img src="preview.png" alt="Omarchy World Clock live panel, interactive time scrubber, globe, and add-location flow" width="960"> </p>

Install

On Omarchy Quattro:

omarchy plugin add https://github.com/olivoil/omarchy-world-clock.git --enable

The interactive installer asks where to place the widget. You can move it after installing at any time:

# Place it immediately after Omarchy's clock.
omarchy bar move io.github.olivoil.world-clock --after omarchy.clock

# Or place it in a particular section.
omarchy bar move io.github.olivoil.world-clock --section left

Use center or right instead of left as needed.

Update

omarchy plugin update io.github.olivoil.world-clock
omarchy restart shell

The restart ensures the updated QML frontend and bundled backend are loaded together. Omarchy releases affected by its stale plugin hot-reload bug can otherwise keep the previous QML component cached until the shell restarts. Saved places and widget settings are preserved.

Upgrading from the old AUR release

Versions through 0.3.x used omarchy-world-clock-bin for a separate backend. If that release already installed the Quattro plugin, update it with the command above. If it did not, use the normal omarchy plugin add ... --enable command instead.

The new plugin ignores the old /usr/bin/omarchy-world-clock executable and bundles its own, so the AUR package is no longer required.

Use

  • Left click the world icon to open or close World Clock.
  • Right click it to open Omarchy's system-timezone selector and set your local timezone.
  • Use the pencil to rename, pin, or remove locations. Click a location name to edit it, then press Enter to save it or Escape to cancel. Submit an empty name to restore the location's default place name.
  • All is the default view. Choose a named group to show only its cards and timeline markers. In a group, the same pencil edits its name, order, and membership; click cards to include or exclude them. The plus beside the views creates another group. World Clock supports up to eight named groups; the view picker scrolls horizontally when its segments exceed the panel.
  • Pin any combination of places. The first three stay visible as compact location codes and times beside the bar icon; additional pins collapse into a +N summary and remain available in the panel.
  • Drag the time ruler beneath its fixed center marker to compare every place at that moment: pull right for earlier or left for later, then release to keep the selection. Two-finger trackpad scrolling and the mouse wheel work too.
  • With no field focused, start typing a number to replace the local summary time, or start typing a location name to open Add mode and search for it.
  • Cards automatically become compact only when the large layout would not fit.
  • Click the weather icon and temperature beside the home time or on any location card to open that place's Field Notes forecast: current conditions, a local narrative, three near-term phases, four-day temperature and UV ranges, and interactive 24-hour graphs. Use Escape or the back button to return to the clocks.
  • Select a displayed time and enter another time to convert the same instant across every visible place.
  • Use plus to open the full-panel globe. Start typing or select search to find a city or timezone, or rotate the globe and choose a place directly. Before adding any place, you can give its clock an optional personal label. Choosing a place that is already saved offers Add another.
  • Use refresh at any time to return to live time and update the weather. Its active fill still only indicates a scrubbed or converted time.

Features

  • Any number of saved places, with automatic large or compact cards plus a bounded, scrollable panel for unusually long lists.
  • An interactive, DST-aware time scrubber with a fixed playhead, direct ruler dragging, trackpad and wheel input, plus explicit previous- and next-day overflow context.
  • Optional current temperature, conditions, feels-like temperature, humidity, directional wind, rain chance and amount, pressure, visibility, sunrise, sunset, hourly UV and wind, a 24-hour forecast, and a four-day outlook for every place with a known coordinate.
  • Multiple named places in the same timezone, such as Boston and New York.
  • Multiple independent cards for the same place, such as Boston for a person and Boston for an office.
  • Reusable named groups that focus the card grid and timeline without removing locations from the complete All view.
  • Personal labels for saved locations, such as a person's name or "Home". The actual place remains visible beside a personal label.
  • Multiple pinned place clocks in the bar, kept in pin order and identified by compact codes such as TOK or NY, with excess pins summarized as +N.
  • A compact bar tooltip showing up to twelve time-sorted places, pairing any personal label with its actual place, plus a count for additional locations.
  • Manual time conversion with DST-aware IANA timezone handling.
  • Local timezone and alias search that works offline.
  • Optional Open-Meteo city search for queries not resolved locally.
  • A progressively loaded, high-resolution full-panel globe with detailed Natural Earth 1:10m coastlines, type-to-search, live major-city suggestions, drag-to-rotate, extended mouse-wheel or trackpad zoom, and offline click-to-add.
  • Automatic 12/24-hour display matching the Omarchy clock or system locale.
  • Automatic temperature units matching Omarchy Weather's effective preference, including its configured home location, then the system locale.
  • Persistent state in ~/.config/omarchy-world-clock/config.json.

Why QML and Rust?

QML is the frontend because Quattro is a Quickshell/QML shell. It is what lets World Clock use the same panel, bar, focus, keyboard, and theme primitives as built-in Omarchy widgets. This frontend is native shell code rather than a separate desktop window.

Rust is used as a small headless backend for arbitrary IANA timezone conversion, DST edge cases, config migration and atomic writes, place search, HTTP fallback, and coordinate to timezone lookup.

See Architecture for the component boundary, JSON protocol, packaging, etc.

Configuration

State is written to:

~/.config/omarchy-world-clock/config.json

Example:

{
  "version": 9,
  "pinned_locations": [
    {
      "id": 2
    },
    {
      "id": 3
    }
  ],
  "groups": [
    {
      "id": 1,
      "name": "Launch crew",
      "location_ids": [2, 3]
    }
  ],
  "timezones": [
    {
      "id": 1,
      "timezone": "America/Cancun",
      "place": "Cancun",
      "label": "Home",
      "latitude": 21.1619,
      "longitude": -86.8515
    },
    {
      "id": 2,
      "timezone": "Europe/Paris",
      "place": "Rennes",
      "latitude": 48.1173,
      "longitude": -1.6778
    },
    {
      "id": 3,
      "timezone": "Asia/Tokyo",
      "place": "Tokyo",
      "label": "Akiko",
      "latitude": 35.6764,
      "longitude": 139.65
    }
  ]
}

Each saved card has its own stable id. place is the geographic name used when the card was added; optional label is the personal name shown most prominently. Pins and named groups refer to card IDs, so duplicate places and duplicate personal labels remain independent. All is built in and is not stored as a group.

To prevent all Open-Meteo requests, add:

{
  "disable_open_meteo_geolocation": true
}

This disables both remote city search and current weather. Existing coordinates remain usable for the map.

The widget's native Show current weather setting controls weather separately. Turning it off suppresses weather requests, conditions, and attribution while leaving optional Open-Meteo city search available.

Privacy and third-party data

Local timezone searches and map clicks do not call a remote service. In live read mode, World Clock sends the saved coordinates for visible places directly from the user's machine to Open-Meteo in bounded batches. Results are cached for 15 minutes while the panel stays loaded and are attributed beside the weather display. An explicit refresh bypasses that freshness window, while a two-minute request cooldown coalesces rapid clicks and failed retries. When a typed place query has no local result, World Clock may also send that query to Open-Meteo's Geocoding API.

Set disable_open_meteo_geolocation to true to disable both requests. Weather is hidden in converted-time views because it always represents current conditions.

See Open-Meteo's Terms & Privacy and Licence.

Uninstall

omarchy plugin remove io.github.olivoil.world-clock

This removes the plugin but preserves saved places. Delete ~/.config/omarchy-world-clock/config.json separately only if you also want to discard that state.

Development

Build and test the source backend:

cargo build --locked --bin omarchy-world-clock-backend
cargo test --locked

Exercise the JSON protocol:

cargo run --locked --bin omarchy-world-clock-backend -- module
cargo run --locked --bin omarchy-world-clock-backend -- snapshot
cargo run --locked --bin omarchy-world-clock-backend -- weather

Rebuild checked-in artifacts after relevant source or dependency changes:

scripts/build-timezone-grid.sh       # only when map source/data changes
scripts/build-plugin-backend.sh      # whenever backend inputs change

For a local branch review on an Omarchy workstation, install an isolated, visually marked copy without replacing the normal plugin:

scripts/install-review-preview.sh

The review copy gets a collision-resistant branch-derived plugin ID, a distinct icon color, a branch header in its tooltip, and its own seeded config file. Re-running the command updates that branch's copy in place.

To prepare a complete local review in one command—rebuild and verify the current branch, update the normal production plugin, install the current branch's isolated review, and remove other inactive World Clock reviews—run:

scripts/review-current-branch.sh

Reviews associated with live worktrees are reported and retained. Close that work before running the command again if you also want its review removed.

Artifact reproduction requires Podman or Docker. The scripts use a digest-pinned official Rust/Alpine image and produce a static x86-64 Linux backend; users installing the plugin need neither the container engine nor a Rust toolchain.

Run every release check, including byte-for-byte artifact reproduction and Quattro validation when Omarchy tooling is available:

scripts/ci.sh

The same source and reproducibility checks run in GitHub Actions on pull requests and changes to master; QML validation additionally runs on the maintainer's Omarchy system.

The committed backend is intentionally part of the plugin distribution. See bin/README.md for its provenance and verification files.

Support policy

New releases target Omarchy Quattro on x86-64 Linux. Omarchy 3/Waybar is not part of the new plugin architecture; users who need it can remain on the older AUR release.

Documentation

License

The application source is MIT licensed. The derived timezone map database is licensed under ODbL 1.0; see data/ODbL-1.0.txt. The plugin manifest expresses the combined distribution as MIT AND ODbL-1.0.

Omarchy World Clock is an unofficial project and is not affiliated with Basecamp or the Omarchy project.