Omahub
← All plugins
R

Matomo

by Roy McKenzie

Live visitors and a visit sparkline from a Matomo instance, with a site picker.

Security review

No obvious issues detected

Deterministic scan — not a security guarantee

None
Risk level
None
Analyzed commit
fe84b9c
Scanned
1 month ago

No potentially dangerous behavior detected in the analyzed commit.

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

None
AI risk level
None
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
fe84b9c
Reviewed
1 month ago

This is a straightforward Matomo analytics widget: it stores a user-supplied API token in a mode-600 config file and sends it only to the configured Matomo instance via a small Python helper. The deterministic scan found no issues, and manual review found no obfuscation, persistence, destructive commands, or other dangerous behavior.

How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/roymckenzie/omarchy-matomo --enable
Widgets #bar #system

Matomo

Bar widget for Omarchy that shows live Matomo visitors and a visit sparkline. Click the pill for the overview, pick which sites to include, and switch Today / 7d / 30d.

Install

omarchy plugin add https://github.com/roymckenzie/omarchy-matomo.git --enable

Then open the panel (or press S) and enter your Matomo URL plus a view-only API token.

Configure

Connection details live in ~/.local/state/omarchy/settings/matomo.json (mode 600), not in shell.json. The settings form writes that file for you.

{
  "url": "https://analytics.example.com",
  "token": "",
  "siteIds": ["1"],
  "period": "today",
  "lastMinutes": 5,
  "showLiveCount": true
}

Create the token in Matomo under Administration → Personal → Security. Do not use a superuser token.

Setting Meaning
showLiveCount Bar shows the live number. Off uses a chart icon instead.
lastMinutes Window used for “live now” (default 5).
period today, 7d, or 30d.

Unique visitors are shown for Today only. Matomo does not report true uniques for custom ranges.

Usage

  • Left click opens the panel
  • Middle click refreshes
  • Refresh and cog buttons are in the panel header
  • 1 / 2 / 3 switch Today / 7d / 30d
  • S opens settings, R refreshes

Live users refresh about every 30 seconds. Visit totals and the chart refresh when the panel opens and after site or period changes.

Remove

omarchy plugin remove io.github.roymckenzie.omarchy-matomo

License

MIT