Omahub
← All plugins
S

OmaTrack

by sh1d0w

Freelance and Project time tracking plugin for Omarchy

Security review

Review recommended · 1 finding

Deterministic scan — not a security guarantee

Medium
Risk level
Medium
Analyzed commit
c2d797e
Scanned
1 month ago

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
c2d797e
Reviewed
1 month ago

The plugin is a time-tracking utility with a Python helper and QML UI. The only flagged item is an eval() in the test script (tests/helper_test.sh), which is not part of the runtime and is used only for test assertions. No network access, no obfuscation, no destructive commands, and all file writes are confined to the user's state directory and Downloads folder.

  • The deterministic scan flagged eval() in tests/helper_test.sh, but this is a test-only helper and never executed during normal plugin operation.
  • The plugin writes invoice/export files to ~/Downloads and uses xdg-open to open them, which is expected behavior for the documented features.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/Sh1d0w/omatrack --enable
Productivity #bar
<div align="center">

OmaTrack

Freelance and project time tracking for Omarchy.

OmaTrack is a time tracking plugin for the Omarchy Quattro shell. It puts a live timer in your bar, a quick-start popup one click away, and a full dashboard for managing your entries, clients, projects, reports, and invoices. All data stays local in a single JSON file — no database, no cloud, no telemetry.

<img src="https://img.shields.io/badge/Omarchy-Quattro-a855f7?style=flat-square" alt="Omarchy Quattro"> <img src="https://img.shields.io/badge/python3-stdlib_only-22d3ee?style=flat-square" alt="python3 stdlib only"> <img src="https://img.shields.io/badge/license-MIT-64748b?style=flat-square" alt="MIT">

<br><br>

<img src="preview.png" alt="OmaTrack — bar timer and quick-start popup" width="820"> </div>

Features

  • Live bar timer — current task and elapsed time in the bar. Click it to open the quick-start popup.

  • Quick-start popup — start, pause, resume, or stop a task in one screen, with your last client and project pre-selected.

  • Dashboard — a toplevel window with seven tabs:

    Tab What it does
    Timer Live timer hero plus start/pause/resume/stop, new-task form, and manual entry form
    Entries Filterable, paginated log — add, edit, delete
    Clients & Projects Manage both, with referential-integrity guards
    Reports Totals by day / client / project over any date range, export to CSV or HTML
    Invoices Billable entries for one client and range → numbered HTML invoice at your hourly rate
    Settings Currency, hourly rate, invoice identity and numbering
  • CLI-driven — omarchy-shell omatrack start|stop|pause|resume|toggle|status drives the timer from anywhere, and python3 omatrack.py -h exposes the full command set.

  • Lightweight — no database, no polling, no extra processes: one JSON state file, written atomically by a stdlib-only python3 helper.

Requirements

  • Omarchy with the Quattro shell
  • python3 (standard library only)
  • xdg-open (opens CSV/HTML exports)

Install

omarchy plugin add https://github.com/Sh1d0w/omatrack.git --enable

plugin add clones the repository into the plugin folder (the registry forbids symlinks, so a real clone is required) and enables the plugin. Update it later with omarchy plugin update io.github.sh1d0w.omatrack.

Uninstall

omarchy plugin remove io.github.sh1d0w.omatrack

To also remove your data:

rm ~/.local/state/omarchy/omatrack/state.json

Usage

  • Bar — click the timer icon for the popup: start/stop the current task or set up the next one (client, project, description, billable).
  • Dashboard — omarchy-shell shell toggle io.github.sh1d0w.omatrack, optionally with '{"tab":"entries"}' (tab ids: timer, entries, clients, projects, reports, invoices, settings).
  • CLI — omarchy-shell omatrack start|stop|pause|resume|toggle|status|ping for the timer; python3 omatrack.py -h for entries, reports, clients, projects, invoices, and settings.

Data & privacy

Everything is local: ~/.local/state/omarchy/omatrack/state.json (XDG_STATE_HOME honored), written atomically under an exclusive file lock. No network, no telemetry. Delete the state file to start over.

Development

License

MIT © sh1d0w