Omahub
← All plugins
R

RSS

by Rafael Vzago

Recent posts from RSS 2.0 feeds, with an unread count on the Omarchy bar.

Security review

Review recommended · 1 finding

Deterministic scan — not a security guarantee

Low
Risk level
Low
Analyzed commit
57295d6
Scanned
1 month ago

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

None
AI risk level
None
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
57295d6
Reviewed
1 month ago

This is a well-structured RSS/Atom reader bar widget with no malicious behavior found. The code is clean, follows security best practices (HTTPS-only URLs, input validation, no eval or obfuscation), and the only deterministic finding is a false positive: the `\0binary` string is a test fixture in tests/test_settings.mjs verifying that null-byte URLs are rejected, not obfuscated code. The `bash -lc` call in shareFeeds() is properly escaped and only passes user-configured feed URLs to wl-copy.

  • The deterministic scan flagged `\0binary` in tests/test_settings.mjs as obfuscation, but this is a test case verifying that data URLs with null bytes are rejected by activateUrl() — it is a legitimate security test, not obfuscation.
  • The shareFeeds() function uses `bash -lc` with string concatenation, but the payload is properly single-quote escaped and derived from validated HTTPS feed URLs, so no injection is possible.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/rafaelvzago/omarchy-rss-plugin --enable
Widgets #bar #quickshell #media

Omarchy RSS plugin

RSS is an Omarchy bar widget for keeping up with recent posts from RSS and Atom feeds. It puts the latest items in one panel, remembers what you have read, and changes its bar icon when new items are waiting.

Install

Add the plugin from GitHub and enable it:

omarchy plugin add https://github.com/rafaelvzago/omarchy-rss-plugin.git --enable

The widget starts in the right section of the bar. You can move it later from the plugin settings.

Using the panel

Click the RSS icon to open the panel. A small accent dot appears on the icon when the New list has items. Hover over it to see the exact unread count.

The panel opens on the New tab. New contains items that have not been opened or marked read. Read contains the rest. Both tabs show their item totals, with counts above 99 displayed as 99+.

RSS panel showing unread items, filters, and pagination

The main panel keeps unread and read items in separate tabs. Use the search box to narrow the list, mark individual posts as read, or clear every item in the current result set. The controls at the bottom move between pages when the list is longer than one page.

From the panel you can:

  • Open an item's link in your default browser. This marks the item read and closes the panel.
  • Mark one item read without opening it.
  • Mark every item in the current New result set read. If a filter is active, this applies to all matching results, including results on other pages.
  • Filter items by title, excerpt, feed name, link, or identity.
  • Move through paginated lists with the Prev and Next controls.

Each row shows the title, feed name, and relative publication time when the feed supplies one. If an item has no title, the plugin uses a plain-text excerpt from its description. Undated items appear below dated items.

Feeds

The plugin reads RSS 2.0 and Atom 1.0. You can add a direct feed URL or paste a blog page. For an HTML page, the plugin looks for an RSS or Atom discovery link and then tries common feed paths on the same site. Only https:// feed and article URLs are used. The plugin fetches feed and HTML text, not images. Saved http:// feeds are ignored until replaced with https.

Items from every configured feed are combined and sorted newest first. The per-feed limit is applied before the lists are combined. Duplicate items are removed by identity: RSS uses guid and falls back to link; Atom uses id and falls back to its alternate link. Items without either identity are skipped.

JSON Feed and RSS 1.0 are not supported. A URL that does not return a supported feed does not add items to the list.

Feeds are checked when the widget starts, after settings are saved, after an import, and on the configured polling interval.

Settings

Open the cog in the panel header to change the plugin settings.

Feeds

Add or remove feed URLs. Put one feed or blog URL in each entry.

Feed settings with configured URLs and the add-feed field

The Feeds tab lists every configured source. Paste a feed or blog URL into the field, choose Add feed, then save the settings. Remove deletes a source from the draft list; the change takes effect when you save.

Options

  • Check interval: how often feeds are fetched. The default is 15 minutes, and values below 5 minutes are raised to 5.
  • Max items per feed: how many recent items to keep from each feed. The default is 10.
  • Items per page: how many feed items the panel shows before pagination. The default is 10.
  • Bar position: place the widget in the left, center, or right section of the Omarchy bar.

Options for polling, item limits, pagination, and bar position

Save applies the settings and fetches the feeds again. Dismiss closes the settings without applying the draft values.

Share and import

Share copies the configured feed list to the Wayland clipboard as a small JSON payload. This action uses wl-copy.

Share and import settings

Use Share to copy your feed list to the clipboard. To bring in another list, paste it into the text field and choose Import. The plugin adds those feeds to your saved list and fetches them immediately.

Import accepts any of these formats:

  • A list shared by this plugin
  • OPML containing xmlUrl attributes
  • Plain feed URLs, one per line

Imported feeds are merged with the existing list, duplicates are skipped, and a new fetch starts immediately.

Read state

The plugin stores the recent items and read identities in:

~/.local/share/omarchy-rss-plugin/state.json

Read identities are also mirrored in the widget settings. Opening the panel does not mark anything read. An item moves to Read only when you open its link or use a mark-read action.

The New count covers the current recent lists, not a permanent backlog. An item no longer counts once it falls outside the configured per-feed limit.

Update and reload

Update a Git-installed copy with:

omarchy plugin update io.github.rafaelvzago.rss

Files under ~/.config/omarchy/plugins/ normally reload when saved. To force Omarchy to scan plugin files again, run:

omarchy-shell shell rescanPlugins

If the shell is not running or the rescan does not pick up the change, restart it:

omarchy restart shell

Development

The plugin is split into the bar entry point (BarWidget.qml), the panel (Panel.qml), and parsing and state helpers (Model.js).

Run the model tests with:

node --test tests/*.mjs

Validate the plugin manifest with:

omarchy plugin validate .

License

MIT