Omahub
← All plugins
R

Minimalist Athan Notifier

by Rockeyxx

Desktop notification at each Islamic prayer time. Location and calculation method are detected automatically.

Security review

Review recommended · 2 findings

Deterministic scan — not a security guarantee

Medium
Risk level
Medium
Analyzed commit
e9595bb
Scanned
1 month ago
  • medium external_hosts Service.qml:295

    Downloads or connects to an external HTTP(S) host.

    curl -fsS --max-time 6 --max-filesize 65536 https://ipwho.is/) || " +
  • medium external_hosts Service.qml:296

    Downloads or connects to an external HTTP(S) host.

    curl -fsS --max-time 6 --max-filesize 65536 https://ipapi.co/json/); " +

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
e9595bb
Reviewed
1 month ago

The plugin is a prayer-time notifier that fetches daily prayer times from a public API and optionally performs an IP-based geolocation lookup. The code is transparent, well-documented, and contains no obfuscation, persistence, or destructive actions. The external network calls are expected and disclosed in the README, and the deterministic findings are consistent with the plugin's stated functionality.

  • The plugin makes external HTTP requests to ipwho.is and ipapi.co for geolocation, which sends the user's public IP address to these services. This is disclosed in the README and is a standard practice for location detection, but users should be aware of the privacy implication.
  • The plugin uses curl to fetch data from external hosts, but it limits response size and timeout, reducing the risk of data exfiltration or resource abuse.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/Rockeyxx/omarchy-plugin-minimalist-athan-notifier --enable
Productivity #Hyprland #quickshell

Minimalist Athan Notifier

Shows a notification at each Islamic prayer time on Omarchy. It detects where you are and which calculation method your country uses, so there is nothing to configure.

The prayer notification

Install

omarchy plugin add https://github.com/Rockeyxx/omarchy-plugin-minimalist-athan-notifier.git --enable

That is the whole setup. The next prayer will notify you.

What it detects

From Config key
Location your Omarchy weather location if it has coordinates, otherwise your IP latitude, longitude
Method your country: Umm al-Qura in Saudi Arabia, ISNA in North America, Diyanet in Türkiye, Karachi in Pakistan, Muslim World League elsewhere method
Asr Hanafi in Afghanistan, Bangladesh, India and Pakistan, standard elsewhere school

Times come from the Aladhan API, which needs no account or key.

The notification

The plugin draws its own surface instead of going through notify-send. That is what makes it look the same on a fresh machine as on a configured one: install it and you get the card above, with nothing else to add, disable, or edit.

It is a Wayland layer-shell surface on the overlay layer, which means it never takes focus from whatever you are typing in, reserves no space so no window gets resized or pushed, and sits clear of the bar whether your bar is on the top or the bottom. Click it to dismiss, or leave it and it goes after 8 seconds.

This is the code that draws it, from Service.qml. The colour is applied here and nowhere else, so it does not depend on any notification daemon or on any other plugin being installed:

readonly property color accentColor: (root.configState && root.configState.color)
  ? root.configState.color : "#ebcb8b"

PanelWindow {
  visible: root.toastVisible
  color: "transparent"

  WlrLayershell.namespace: "athan-toast"
  WlrLayershell.layer: WlrLayer.Overlay
  WlrLayershell.keyboardFocus: WlrKeyboardFocus.None   // never steals input
  exclusionMode: ExclusionMode.Normal
  exclusiveZone: 0                                     // reserves no space

  anchors { top: true; right: true }
  margins { top: Style.space(12); right: Style.space(12) }

  Rectangle {
    anchors.fill: parent
    radius: Style.space(10)
    color: Color.notifications.background
    border.width: 2
    border.color: root.accentColor        // the border

    Text {
      text: root.toastName + " Prayer"
      color: root.accentColor             // the title
      font.bold: true
    }
    Text {
      text: "It's time for " + root.toastName + " (" + root.toastTime + ")"
      color: Color.notifications.text
    }
  }
}

Config

Create ~/.config/omarchy/athan.json. Every key is optional, and any key you set beats detection. The file is watched, so saving it applies right away.

{
  "latitude": 21.1,
  "longitude": 30.2,
  "method": 4,
  "school": 0,
  "color": "#ebcb8b",
  "notify": "toast",
  "respectDnd": false
}

latitude and longitude are decimal degrees. Set both or neither.

method is the Aladhan calculation method, 0 to 23. The list is in the Aladhan docs. If you set coordinates by hand and leave this out, the country is unknown, so it falls back to Muslim World League. Set it too if you want a particular one.

school is the Asr shadow length: 0 standard (Shafi'i, Maliki, Hanbali), 1 Hanafi.

color accepts #rgb or #rrggbb and paints the card's border and title. Anything else falls back to the default yellow, so a typo cannot break the card.

notify is "toast" for the plugin's own card, or "system" to send the prayer to your notification daemon instead. See below.

respectDnd is false by default, so prayers still appear during do-not-disturb. Set it to true to silence them with everything else. This only affects the toast, since in "system" mode the daemon applies its own rules.

To change the location without touching anything else, use Omarchy's own setting, which this plugin reads:

omarchy-weather-location --set "Makkah" 21.42,39.83

Sending through the notification daemon

With "notify": "system" the prayer goes out as:

notify-send -a "athan" "Fajr Prayer" "It's time for Fajr (04:46)"

You get notification history and do-not-disturb, and the daemon decides how it looks. Urgency is normal, not critical: a prayer is an announcement, and Omarchy's card reserves its critical styling, a red border, for real alerts.

Running that command yourself will not produce the card at the top of this page, and neither will this mode on a stock install. The colour comes from the QML above, which notify-send never reaches. Stock Omarchy has three colour branches, all keyed on urgency, and no hook for a per-notification colour:

// stock NotificationCard.qml
readonly property color accentColor: urgency === 2 ? Color.urgent
  : (urgency === 0 ? dimColor : Color.notifications.countdown)

So in "system" mode a prayer renders in your theme's accent like any other message. If you want the colour, use the default "toast".

Behaviour

Five prayers: Fajr, Dhuhr, Asr, Maghrib, Isha. Sunrise and Imsak are not announced.

Restarting the shell in the afternoon does not replay the prayers that already passed today.

A prayer that arrived more than 10 minutes ago, while the machine was asleep say, is skipped rather than announced late.

A failed fetch retries with backoff, from 1 minute up to 15.

Times are computed for the detected coordinates. If your system clock is on a different timezone than your location, they will be off by the difference.

Fetching and caching

One network request per day, and no fixed time it has to happen at.

The plugin keeps a 15 second tick that only compares dates. On each tick it asks whether the schedule it holds is for today. If it is, nothing happens. If it is not, it loads today's timings, preferring the cache:

~/.cache/omarchy-athan.json     130 bytes, rewritten once a day
{"day":"2026-08-27","for":"21.517,39.219,4,0","t":{"Fajr":"04:46", ... }}

The cache is reused only while both the date and the for key still match. That key is your coordinates rounded to three decimals, the method, and the madhab, so moving city or changing method refetches and a shell restart costs nothing.

This is deliberately not a scheduled job. A cron entry or a systemd timer has to fire at some particular time, and if the machine is asleep then, the day is missed. Here there is no moment to miss: the next tick after the machine comes back notices the date no longer matches and fetches then. A laptop closed for three days fetches once when you open it.

Nothing else is written to disk. No logs, no history, no per-prayer state.

Footprint

The plugin is a service inside the omarchy-shell process that is already running. It starts no process of its own and holds no window and no timer thread. What it costs is a handful of QML objects and a five element array, which is below the run to run noise of measuring omarchy-shell at all.

Subprocesses: one curl a day, which exits immediately, and one notify-send per prayer in "system" mode.

Source is 20 KB across two files. The cache is 130 bytes.

Requirements

Omarchy 4.x, the Quickshell omarchy-shell, and curl, which a stock install already has. notify-send is needed only for "notify": "system".

Remove

omarchy plugin remove io.github.rockeyxx.minimalist-athan-notifier --yes
rm -f ~/.config/omarchy/athan.json ~/.cache/omarchy-athan.json

Your Omarchy weather location is left alone.

Privacy

When no coordinates are configured and Omarchy's weather setting has none, the plugin makes one request to ipwho.is, falling back to ipapi.co, to look up approximate coordinates and a country code from your public IP. Nothing else is sent, and nothing is stored beyond the current shell session. Setting latitude, longitude, method and school skips that lookup entirely.

License

MIT, see LICENSE.