Omahub
← All plugins
K

Umbrella Countdown

by koka.no

Counts down to rain: β˜”30m when rain starts within 2 hours, πŸŒ‚2h for later today. Quiet when dry.

Security review

Review recommended Β· 4 findings

Deterministic scan β€” not a security guarantee

Medium
Risk level
Medium
Analyzed commit
e0d0b2e
Scanned
3 weeks ago
  • medium external_hosts Panel.qml:307

    Downloads or connects to an external HTTP(S) host.

    curl", "-fsS", "--max-time", "6", "https://api.open-meteo.com/v1/forecast" + "?latitude=" + encodeURIComponent(String(lat)) + "&longitude=" + encodeURIComponent(String(lon)) + "&hourly=precipitation" 
  • medium external_hosts Panel.qml:328

    Downloads or connects to an external HTTP(S) host.

    curl", "-fsS", "--max-time", "6", "-H", "User-Agent: koka-umbrella/2.0 github.com/SjoenH/omarchy-umbrella", "https://api.met.no/weatherapi/nowcast/2.0/complete" + "?lat=" + encodeURIComponent(String(l
  • medium external_hosts Panel.qml:378

    Downloads or connects to an external HTTP(S) host.

    curl", "-fsS", "--max-time", "5", "https://geocoding-api.open-meteo.com/v1/search?name=" + encodeURIComponent(geocodeActiveQuery) + "&count=5&language=en&format=json"];
  • medium external_hosts Panel.qml:452

    Downloads or connects to an external HTTP(S) host.

    curl", "-fsS", "--max-time", "5", "https://ipwho.is/"]

Automated analysis only β€” not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment Β· ~deepseek/deepseek-v4-flash-latest β€” advisory only

Low
AI risk level
Low
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
e0d0b2e
Reviewed
3 weeks ago

The plugin is a transparent weather widget that fetches precipitation data from Open-Meteo and MET Norway, with an IP-geolocation fallback via ipwho.is when no location is configured. The deterministic scan flags these external hosts, but they are legitimate, documented weather/geolocation APIs and not a sign of malicious behavior. No install scripts, obfuscated code, credential theft, or destructive actions were found.

  • The widget sends the user's IP address to ipwho.is for geolocation when no location is configured; this is disclosed in the README but is a minor privacy consideration.
  • Location coordinates and queries are sent to Open-Meteo and MET Norway weather APIs, which is expected functionality for this widget.
  • Network calls are made via curl from QML with fixed timeouts to known public APIs; no unexpected or user-unapproved destinations were observed.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory β€” it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only β€” automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/SjoenH/omarchy-umbrella --enable
Widgets #bar #quickshell

koka.umbrella β€” Umbrella Countdown

A single-purpose Omarchy bar widget that counts down to the next rain. No temperatures, no forecasts, no weather dashboard β€” just the one question: do I need an umbrella today?

Plugin ID: koka.umbrella Author: koka.no (koka.no)

Bar states

State Meaning
β˜€οΈ No rain expected in the next 16 hours
β˜” 30m Rain starting within 2 hours β€” minutes countdown
πŸŒ‚ 2h Rain expected later today β€” hours countdown

Rain counts when the hourly precipitation exceeds 0.1 mm within the next 2 hours (soon) or 0.2 mm within 16 hours (later).

Installation

omarchy plugin add https://github.com/SjoenH/omarchy-umbrella.git --enable

Then add koka.umbrella to your bar layout in ~/.config/omarchy/shell.json and restart the shell:

omarchy restart shell

Remove

omarchy plugin remove koka.umbrella

Usage

  • Left-click β€” panel with the rain timeline (start–end and mm of every rain window in the next 16 hours) and the location setting
  • Right-click β€” notification with the current rain verdict
  • Middle-click β€” force a refresh

Location is read from omarchy-weather-location (shared with the stock weather tooling). Without a configured location the widget falls back to an approximate IP-geolocated position. Weather data: Open-Meteo, hourly precipitation, no API key.

Auto-refresh defaults to 15 minutes; set "refreshMinutes" on the widget's entry in ~/.config/omarchy/shell.json to change it.

Set "barMode": "radar" to show a Yr-style mini radar chart (next 90 minutes) in the bar instead of the umbrella countdown. With no live radar data it falls back to the umbrella label.

Radar sources

  • MET Norway nowcast/2.0 (Nordics + Baltics only): 5-minute radar steps with exact mm/h, powering β˜” Now, the 90-minute chart, and hover readouts. Outside this region the widget falls back to the hourly forecast β€” no radar verdicts, no chart.

Development

# Pure logic tests (rain windows, thresholds, labels)
qmltestrunner -input BarWidget.spec.qml

# Lint
OMARCHY_PATH=/usr/share/omarchy qmllint -I /usr/share/omarchy/shell *.qml

History

This started as koka.weather, a fork of the official omarchy.weather plugin with umbrella alerts bolted on. v2.0.0 dropped the whole weather picture to focus on the one job it was actually doing.

License

MIT