Omahub
← All plugins
R

Umarchy

by Rolf Koenders

Umami analytics stats in the Omarchy bar: live visitors, pageviews, top pages/referrers/countries, switchable across sites.

Security review

No obvious issues detected

Deterministic scan — not a security guarantee

None
Risk level
None
Analyzed commit
6750283
Scanned
4 weeks ago

No potentially dangerous behavior detected in the analyzed commit.

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

None
AI risk level
None
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
6750283
Reviewed
4 weeks ago

Manual review found no malicious or dangerous behavior: the plugin is a straightforward Umami analytics widget that stores credentials in the system keyring, performs API calls through short-lived capped subprocesses, and uses symlink-safe state file handling. The deterministic scan found no issues, and the sampled code matches the documented security model.

How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/RolfKoenders/umarchy --enable
Widgets #bar #quickshell

Umarchy

Umarchy

Umami analytics in the Omarchy bar. Live visitor count, pageviews, bounce rate and average visit time, a pageviews-over-time chart, and top pages/referrers/countries — switchable between every site your account can see, one at a time.

Not affiliated with or endorsed by Umami Software, Inc.

Install

omarchy plugin add https://github.com/rolfkoenders/umarchy.git --enable

Setup

Umarchy connects directly to your self-hosted Umami instance's API. It does not use Umami Cloud.

  1. In Umami, create a dedicated View Only team member account scoped to the site(s) you want in the bar, rather than using your admin login — this plugin never needs write access to anything.
  2. Open the Umarchy widget, select Settings.
  3. Enter your instance URL (e.g. https://analytics.example.com), the view-only username, and its password, then Save & Connect.

Self-hosted Umami has no simple API key (that's a Cloud-only feature) — the password is used once to log in and get a session token, then stored in your system's GNOME Keyring via secret-tool so it isn't needed again until the token expires or is rejected. The password is never written to this plugin's own config file.

Configuration

Setting Description
Instance URL Your Umami server, e.g. https://analytics.example.com
Username A view-only Umami account's username
Password That account's password (kept only in the system keyring)
Live count on the bar Show the live visitor count next to the icon, or just the icon

Site and time-period selection live in the panel itself (a site picker when your account can see more than one site; Today / 7d / 30d chips), not in these settings.

Features

  • Live visitor count ("LIVE NOW"), refreshed continuously while configured.
  • Pageviews, visitors, bounce rate and average visit time for the selected period.
  • A pageviews-over-time chart (hourly for Today, daily for 7d/30d).
  • Top pages, top referrers, and top countries for the selected period.
  • Switch between every site the account can see — including sites owned by a team the account belongs to, at any role, not only sites it directly owns — no aggregation across sites, since unrelated websites' traffic isn't meaningfully summable.
  • Middle-click the bar icon to refresh; right-click to open the instance in your browser.
  • Automatic re-login, once, if the session token is rejected — you're only ever prompted again if the saved password itself no longer works.

Security

  • The login password lives only in GNOME Keyring (secret-tool), keyed by instance host and username. It is never written to this plugin's config file or passed on any process's command line.
  • Every Umami API call — including login — happens in a short-lived Python helper process (bin/umami-api), not inside the long-lived Quickshell process. QML's own XMLHttpRequest can't safely bound an untrusted response: Qt materializes every received byte into memory as it streams in, before any JS callback gets a chance to inspect or abort it. The helper instead enforces a byte cap and a wall-clock deadline during its own socket read, refuses to follow HTTP redirects (which could otherwise resend the session token to an unintended host), and only ever hands the shell process already-bounded output.
  • Response shape (list length, individual field length) is capped again on the QML side before anything is bound to a list — a response under the byte cap can still be an enormous list of tiny records, and either becomes real UI cost once rendered.
  • The instance URL is validated as a plain http(s)://host before it's saved or ever used, including for the "open in browser" action, which only ever opens that saved URL — never anything server-supplied.

Requirements

  • Omarchy Quattro v4.
  • python3 (stdlib only — no pip dependencies).
  • secret-tool (GNOME Keyring) for password storage.
  • A reachable Umami instance and a view-only account on it.

License

MIT — Copyright (c) 2026 Rolf Koenders