Omahub
← All plugins
D

OmaDeezer

by Deunnis

Deezer now-playing widget with playback controls

Security review

No obvious issues detected

Deterministic scan — not a security guarantee

None
Risk level
None
Analyzed commit
75840b3
Scanned
1 month ago

No potentially dangerous behavior detected in the analyzed commit.

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
75840b3
Reviewed
1 month ago

The plugin is a transparent QML widget that interacts with MPRIS and uses external processes (curl, magick, hyprctl) in a carefully constrained manner. Art URLs are validated to only allow HTTPS on dzcdn.net, downloads are size-limited and written to a private cache, and text is sanitized to prevent rich-text injection. The only side effect beyond the widget is the user-controlled blur slider, which sets a global Hyprland decoration setting.

  • The blur slider modifies a global Hyprland setting (decoration.blur.size), which affects the entire desktop, but this is user-initiated and clearly documented.
  • External commands (magick, hyprctl, curl, mktemp, stat, rm) are used, but all arguments are either fixed or validated, and no shell injection is possible.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/Deunnis/OmaDeezer --enable
Other #media

OmaDeezer

A Deezer now-playing bar widget and popup player for Omarchy, built as a Quickshell shell plugin.

Player popup Settings panel

Features

  • Bar widget showing the current Deezer track via MPRIS, with play/pause, next/previous
  • Click to open a popup with album art, a live seek bar, shuffle, and repeat (off → repeat playlist → repeat track)
  • Popup colors are extracted from your wallpaper's dominant colors and update automatically when you change wallpaper, with text kept legible against whatever color that produces
  • Settings panel (gear icon) with live sliders for blur, transparency, outline thickness, and corner roundness, plus reset-to-defaults and a manual reload button
  • 6 bar icon choices: logo, headphones, music note, speaker, playlist, or a text label (title + artist)

Requirements

  • Omarchy with its Quickshell-based shell
  • The official Deezer desktop app running, exposing an MPRIS interface identifying as "Deezer" (this is how the widget finds the player - it doesn't talk to the Deezer web API or need any API key)
  • ImageMagick (magick on PATH) for the wallpaper-based color extraction. If it's missing, that feature silently falls back to your theme's normal accent color - nothing else is affected.

Install

omarchy plugin add https://github.com/Deunnis/OmaDeezer.git --enable

By default it's placed on the right side of the bar; move it with:

omarchy bar move io.github.omadeezer --section right

(or place it via ~/.config/omarchy/shell.json, which is where all the settings below are also stored per-widget).

Uninstall

omarchy plugin remove io.github.omadeezer

Settings

Available from the gear icon inside the popup:

Setting Range Description
Icon 6 options What's shown on the bar and as the popup header icon
Blur 0-100 Backdrop blur behind the popup (this is a global Hyprland decoration setting, not scoped to just this popup)
Transparency 0-100 How see-through the popup background is
Outline thickness 0-6px Popup card border width
Corner roundness 0-20px Popup card corner radius

"Reset to defaults" restores all of the above. "Reload plugin" does a full reload if the widget ever looks stuck.

Notes for reviewers

  • Runs entirely as your normal user session with no elevated permissions requested. The plugin itself never calls out to the Deezer web API or needs any API key or credentials.
  • Album art is loaded from whatever mpris:artUrl the active MPRIS player reports - for the real Deezer app that's an https:// URL on Deezer's own CDN (*.dzcdn.net). Since any local process can claim the "deezer" MPRIS identity and control that URL, it's anchored to that CDN host specifically (file:// and any other host are rejected outright), then downloaded by the plugin itself via curl (no redirects followed, so a redirect can't hand trust to a different host) into an exclusively-created file in a private per-plugin cache dir, with --max-filesize bounding the transfer and a follow-up size check before the file is ever handed to Image.source. The image is also decoded with a bounded sourceSize so a malicious value can't force an oversized decode in the shared shell process.
  • Track title/artist/album come from the same untrusted MPRIS source. Every Text item displaying them is forced to Text.PlainText, and angle brackets are stripped before the text reaches the shared bar tooltip (whose own rendering this plugin doesn't control and defaults to AutoText) - both against a rogue "deezer" player smuggling rich text into the bar label, popup header, or tooltip.
  • Two external commands run via Quickshell's Process: magick (read-only, analyzes the current wallpaper image) and hyprctl eval for the Blur slider.
  • The Blur slider is the one thing with a side effect beyond this widget: it sets Hyprland's global decoration.blur.size, so turning it up blurs behind every window/layer, not just this popup.

Not included

Browsing/shuffling playlists and albums from the popup was attempted but removed - it requires Deezer's app API, and Deezer isn't accepting new API app registrations at the moment. Worth revisiting if that changes.

License

MIT - see LICENSE.