Omahub
← All plugins
M

Calendar Clock

by Matteo De Venuto

Date/time label with a calendar popup

Security review

Review recommended · 2 findings

Deterministic scan — not a security guarantee

Medium
Risk level
Medium
Analyzed commit
cbca86f
Scanned
5 days ago
  • Command runs with sudo, elevating the process beyond the plugin environment.

    sudo pacman -S python-icalendar python-recurring-ical-events",
  • Docs sudo README.md:35

    Command runs with sudo, elevating the process beyond the plugin environment.

    sudo pacman -S --needed python-icalendar python-recurring-ical-events

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

None
AI risk level
None
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
cbca86f
Reviewed
5 days ago

The deterministic scan's medium findings are both benign: the sudo command appears in the README and in a user-facing dependency-install hint inside calendars-sync, and neither is executed by the plugin. The plugin runs its Python backend with a cleared environment and isolated interpreter, applies bounded reads and resource limits, rejects private/loopback network targets, and stores feed data with owner-only permissions. No obfuscation, persistence, credential theft, or destructive behavior was found in the sampled source.

How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/matteodevenuto/omarchy-calendar-clock --enable
Productivity #bar

Calendar Clock for Omarchy

The Omarchy bar clock, upgraded: date and time on the bar, and a popup with a month calendar, year/life progress bars, and your upcoming events from any iCalendar (.ics) feed.

This exists because I liked the design of Omarchy's default clock and its calendar popup — the hero date, the quiet month grid, the progress rails — and wanted that exact look to also show my real events. So this is the stock design, kept as-is, wired to live calendars.

Preview

Features

  • Bar — date/time label (formats configurable), vertical-bar mode for thin setups
  • Popup
    • Big hero date; click it or the month header to jump back to today
    • Month grid with ISO week numbers and event dots per day
    • Year progress ("2026 · 64%") and life progress (editable birth year / expectancy, double-click the year row)
    • Upcoming list and selected-day events from your calendars
  • Calendars — paste any shared iCalendar link (Proton, Google, Nextcloud, Fastmail, self-hosted…). Reorder feeds with the arrows, recolor them by clicking a feed's dot. Recurring events expand correctly across DST changes; one broken event in a feed can't sink the rest.
  • Private by default — feed URLs never appear in process arguments or logs; feeds and caches are owner-only

Requirements

sudo pacman -S --needed python-icalendar python-recurring-ical-events

Install

omarchy plugin add https://github.com/matteodevenuto/omarchy-calendar-clock --enable

It replaces the stock clock widget in place. Click the clock to open the panel; Escape closes it.

Keyboard

Key Action
←/→ Previous / next month
↑/↓ Previous / next year
t / enter Back to today
s Show/hide calendars
u Toggle upcoming list
w Toggle week start
esc Close

Settings

Key Type Default Meaning
format string locale Bar date/time format (Qt format string)
weekStartDay string locale First day of week
birthYear integer — Life-progress start year
lifeExpectancy integer 90 Life-progress span
refreshIntervalSec integer 900 Calendar feed poll interval
feedsFile path — Defaults to ~/.config/omarchy/calendars/feeds.json

Omarchy Quattro

On Quattro, third-party plugins talk to the bar through a facade. The centerHoverRevealSuppressed flag is read-only. Assigning it on panel open/close throws TypeError and freezes the shell until restart.

Use the setter, like stock omarchy.clock:

function setCenterHoverRevealSuppressed(value) {
  if (root.bar && typeof root.bar.setCenterHoverRevealSuppressed === "function")
    root.bar.setCenterHoverRevealSuppressed(value)
  else if (root.bar && "centerHoverRevealSuppressed" in root.bar)
    root.bar.centerHoverRevealSuppressed = value
}

Already applied in 1.0.3. Existing installs:

omarchy plugin update matteodevenuto.clock

Credits

Built on the stock Omarchy clock plugin (MIT, by the Omarchy authors). The calendar feed integration is based on Proton Calendar for Omarchy by itsmoorgrove (MIT), generalized to any iCalendar source. See LICENSE.

Removal

omarchy plugin remove matteodevenuto.clock
rm -rf ~/.config/omarchy/calendars ~/.cache/omarchy/calendars

Removing the clone restores the stock clock.