Omahub
← All plugins
V

OMA-CHESS

by Vishal Desai

Chess.com & Lichess stats panel for the Omarchy bar

Security review

No obvious issues detected

Deterministic scan — not a security guarantee

None
Risk level
None
Analyzed commit
5342bcd
Scanned
2 weeks ago

No potentially dangerous behavior detected in the analyzed commit.

Automated analysis only — not a security guarantee.

AI advisory review

Review recommended

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
review
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
5342bcd
Reviewed
2 weeks ago

The plugin itself is a read-only chess-stats widget: it fetches public chess.com/Lichess APIs for user-supplied usernames, shells out only to fixed curl commands with quoted arguments, stores no credentials, and sanitizes/bounds incoming data. The deterministic scan found nothing, but my review flags an auxiliary VSCode task that runs `node` on a bundled font file; this is not executed by the plugin at install/runtime, but it should be verified before publishing.

  • .vscode/tasks.json defines a folder-open VSCode task that executes `node ./lib/public/fonts/fa-solid-400.woff2`, and .vscode/settings.json enables automatic tasks; the woff2 file was not in the sampled files, so a human should confirm it is a real font and not an obfuscated script.
  • The bundled `lib/public/fonts/README.md` describes unrelated 'Blockchain Explorer' fonts, and Font Awesome assets appear unused by the widget; this is a suspicious leftover but not a runtime risk.
  • The widget's runtime network code appears safe: curl commands are restricted to fixed API hosts, user input is shell-quoted, responses are capped at 4 MiB, and parsed strings are stripped of HTML/control characters.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/DesaiVishal-16/oma-chess --enable
Widgets #bar #quickshell

OMA-CHESS

A Chess.com & Lichess stats panel for the Omarchy bar. A ♞ pill that opens a popup with your live ratings, recent games, and upcoming tournaments — plus one-click matchmaking and quick links back to your games.

OMA-CHESS preview

Install

omarchy plugin add https://github.com/DesaiVishal-16/oma-chess.git --enable

The ♞ icon appears in the bar (category: Info). Reposition it with:

omarchy bar move oma.chess --section right

First run

On first open the panel asks "Where do you play?" — pick Chess.com, Lichess, or both. Click a card, type your username, hit ✓ (or Enter). You can always add, disable or remove accounts later via ⚙ ACCOUNTS:

  • The toggle enables/disables a site instantly (disabled sites use no network traffic and lose their tab)
  • X clears an account's username

Only your accounts are ever shown — nothing is hardcoded.

Usage

  • Click ♞ — open/close the panel
  • ⚙ ACCOUNTS (top-right) — manage your chess.com / lichess accounts
  • Tabs — appear when both sites are active; ←/→ arrow keys switch tabs
  • Esc — close the panel; Tab — jump between bar panels

What each tab shows

Chess.com Lichess
Ratings Bullet / Blitz / Rapid / Daily + W-L-D per speed, Puzzles peak, FIDE Bullet / Blitz / Rapid / Classical / Puzzles with trend arrows
Profile Avatar, name, last seen Avatar, title, online dot, last seen
Recent games Last 2, click (or 👁) to open on chess.com Last 2, click (or 👁) to open on lichess
Tournaments Link to chess.com tournaments page (no public API) Full list of arenas starting within 48h

Hide ratings you don't care about: hover any rating row → ✕. Hidden categories come back via the pill chips below the list (Blitz +).

Tournaments: click the TOURNAMENTS entry for your active site to open a full-page list. Lichess shows each arena's live/upcoming status, countdown, category, time control, duration and player count; click any row to open it in the Lichess app. VIEW ALL TOURNAMENTS → opens lichess.org/tournament.

Play

▶ FIND OPPONENT launches the active site in its installed app (Omarchy web apps like Chess/Lichess are detected automatically; native GUIs such as En Croissant or ChessX also work) and falls back to the browser otherwise. Neither platform publicly supports deep-linking a specific time control, so pick it there — both sites remember your last-used control afterwards.

Recent games and tournament rows also respect installed apps: they open inside your Lichess/Chess app window whenever possible.

Keyboard shortcut (optional)

Enable Super + Ctrl + Alt + C by adding one line to your Hyprland Lua bindings (~/.config/hypr/bindings.lua):

o.bind("SUPER + CTRL + ALT + C", "Chess", "omarchy-shell oma.chess toggle")

(A ready-made snippet ships as bindings.lua in this repo.) Use any combo you prefer — see omarchy menu keybindings to view existing binds. The command it runs is simply omarchy-shell oma.chess toggle.

Live game indicator (optional)

Off by default (it polls once every 30s even while the panel is closed). Enable it in ~/.config/omarchy/shell.json on the widget entry:

{ "id": "oma.chess", "liveIndicator": true }

While one of your lichess games is running, the ♞ pill lights up.

Remove

omarchy plugin remove oma.chess
rm -rf ~/.cache/omarchy-chess

Notes

  • Data is cached to ~/.cache/omarchy-chess/ and rendered instantly; fetches happen only while the panel is open (unless liveIndicator is on)
  • Requests to chess.com and lichess are serialized per site and back off for 2 minutes after failures, respecting their rate limits
  • All links opened from the panel are validated against an allow-list of chess.com / lichess hosts before launching
  • Read-only public APIs only — no tokens or credentials are stored
  • Known quirk: chess.com's game archive can lag behind live play (ratings update instantly, but newly finished games appear in the recent-games list only after their archive publishes them). Lichess games show up near-instantly