Omahub
← All plugins
S

Now Playing

by Sumiran Dahal

Now-playing panel with album art and playback controls

Security review

No obvious issues detected

Deterministic scan — not a security guarantee

None
Risk level
None
Analyzed commit
2fc5f3d
Scanned
3 weeks ago

No potentially dangerous behavior detected in the analyzed commit.

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
2fc5f3d
Reviewed
3 weeks ago

This is a straightforward QML bar widget that reads MPRIS metadata and sends play/pause/seek commands to the active player; there is no install-time code, obfuscation, credential handling, or destructive behavior. The deterministic scan found no issues, and nothing in the sampled source is malicious. The only manual finding is a user-triggered xdg-open of an MPRIS-supplied http(s) URL inside focusPlayer(), which is low risk but makes the README's no-subprocesses claim slightly overstated.

  • focusPlayer() runs xdg-open on an MPRIS metadata URL when the player cannot be raised; the URL is filtered to http/https and shell-quoted, so the practical risk is low, but it is still a subprocess invocation controlled partly by MPRIS data.
  • The README claims the plugin spawns no subprocesses, while focusPlayer() does spawn xdg-open in one user-triggered case; this is a documentation discrepancy rather than a sign of malicious intent.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/sumdahl/omarchy-plugin-media --enable
Widgets #bar #quickshell #media

Now Playing

A now-playing bar widget for Omarchy 4.

It sits in the bar as a single icon — the same way Audio, Network and Bluetooth do — and appears only while something is actually playing. Click it and a panel opens with the album art, the track detail, a seek bar, and the transport controls.

Features

  • Album art, rendered at the display's real pixel density, with a graceful placeholder while it loads or when the player supplies none.
  • Track detail — title, artist, album, and a dim secondary line for album artist and track number, each shown only when it exists and differs from what's above it.
  • Seek bar with elapsed and total time, driven by a poll timer while the panel is open (Spotify never emits MPRIS Seeked, so a plain binding would sit still).
  • Transport — shuffle, previous, play/pause, next, repeat. Repeat cycles off → playlist → track, matching Spotify's own control.
  • Source picker listing every running player when there is more than one, so you can switch which one the panel controls.
  • Bar-icon shortcuts — middle-click to play/pause, scroll to skip tracks, without opening the panel at all.
  • Spotify accent, optional: tints the panel's accent to Spotify green while Spotify is the active player. Falls back to your theme accent for everything else.
  • Keyboard — a global hotkey to summon the panel (see Keybindings), then ←/→ to skip, ↑/↓ to move through the sources, Enter to activate, Esc to close.

Works with any MPRIS player: Spotify, mpv, Firefox, Chromium, VLC, and so on.

Install

omarchy plugin add https://github.com/sumdahl/omarchy-plugin-media.git --enable

Pick a bar section when prompted (right is the default). Then enable it later, move it, or change its settings from Omarchy menu → Setup → Bar.

Optionally add the SUPER + CTRL + M hotkey — see Keybindings.

Remove

omarchy plugin remove io.github.sumdahl.media

That deletes ~/.config/omarchy/plugins/io.github.sumdahl.media/ and drops the widget from the bar. Nothing else on your system is touched.

Settings

Configurable per widget instance from the bar setup menu:

Setting Default What it does
artSize 96 Album art edge length in pixels (48–200, in steps of 8).
showProgress true Show the seek bar and the elapsed/total times.
showSourcePicker true List the other running players at the bottom of the panel.
spotifyAccent true Tint the accent Spotify green while Spotify is the active player.

Keybindings

Omarchy plugins cannot install keybindings — a plugin only draws itself, it never edits your Hyprland config. So this is one manual step, and it is worth doing: the panel is much more useful when you can summon it without reaching for the mouse.

Add this to ~/.config/hypr/bindings.lua, then hyprctl reload:

o.bind("SUPER + CTRL + M", "Now Playing", "omarchy-shell shell toggle io.github.sumdahl.media")

SUPER + CTRL + M now toggles the panel open and closed. The same call works from a script or another terminal:

omarchy-shell shell toggle io.github.sumdahl.media

omarchy-shell ships with Omarchy and forwards an IPC message to the shell process that is already running — it does not launch anything, and it needs no extra software.

Once the panel is open

Key Action
← / → Previous / next track
↑ / ↓ Move through the source list
Enter Switch to the selected source
Tab Move to the next bar panel
Esc Close

Without opening the panel

The bar icon responds directly: middle-click to play/pause, scroll to skip tracks.

Optional: media keys without the panel

If you also want plain transport bindings — the kind that work with no shell panel involved — the usual approach is playerctl, available from the Arch repositories as the playerctl package. This plugin does not install it, require it, or call it.

o.bind("SUPER + ALT + P", "Play/Pause",    "playerctl play-pause")
o.bind("SUPER + ALT + N", "Next Track",    "playerctl next")
o.bind("SUPER + ALT + B", "Previous Track", "playerctl previous")

This is entirely optional and separate from the plugin. playerctl is not a dependency of this widget — the widget never calls it, and everything above works without it installed. It is listed here only because these bindings are a common companion to a now-playing widget, and both talk to the same MPRIS players, so they stay in sync with each other.

Requirements

  • Omarchy 4 (Quickshell-based shell)
  • Any MPRIS-capable media player — Spotify, mpv, Firefox, Chromium, VLC, and so on

That is the complete list. No playerctl, no daemons, no Python, no network service.

How it works, and what it does not do

This plugin is presentation only. All MPRIS work is delegated to Omarchy's first-party omarchy.media service, which it reads through shell.firstPartyServiceFor("omarchy.media") — the same handle the built-in media widget uses. The service is left untouched and keeps receiving upstream fixes; this plugin does not clone, replace, or disable it, and the built-in media widget is unaffected if you also have it enabled.

Consequently:

  • No subprocesses are spawned — no playerctl, no shell-outs, nothing on any hot path.
  • No network access. Album art is loaded from whatever URL the player itself advertises over MPRIS (usually a local file, or the player's own CDN); no other requests are made.
  • No file writes. Settings live in Omarchy's own bar config, written by Omarchy.
  • No privilege escalation. The plugin requests no elevated permissions, manages no services, and ships no bundled binaries.

Like every Omarchy plugin, it runs unsandboxed inside the long-lived omarchy-shell process. The whole thing is one QML file, one plain-JS helper file, and a manifest — read them.

License

MIT. See LICENSE.