Omahub
← All plugins
R

Oma Stock Ticker

by ronnie

Watchlist of stock tickers with live prices, like the macOS Stocks widget

Security review

Review recommended · 2 findings

Deterministic scan — not a security guarantee

Medium
Risk level
Medium
Analyzed commit
aa062ac
Scanned
1 month ago
  • medium external_hosts Panel.qml:138

    Downloads or connects to an external HTTP(S) host.

    curl -fsS --max-time 6 -A 'Mozilla/5.0' \"https://query1.finance.yahoo.com/v8/finance/chart/" + sym + "?range=1d&interval=15m\" 2>/dev/null | " +
  • Docs external_hosts README.md:41

    Downloads or connects to an external HTTP(S) host.

    git clone https://github.com/Macs9319/OmaStockTicker ~/.config/omarchy/plugins/stockticker

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
aa062ac
Reviewed
1 month ago

The plugin is a stock-ticker widget that fetches quotes from Yahoo Finance's public chart API via curl and jq, which is its documented core behavior, so the external-host findings are expected rather than malicious. The README's install commands are documentation only and are not executed by the plugin itself, and there are no install hooks, obfuscation, credential theft, destructive commands, or hidden persistence. The only minor risks are routine network calls and shell command construction using symbols from a locally editable state file, which appears adequately quoted.

  • Panel.qml runs curl against query1.finance.yahoo.com for each watched symbol, sending the watchlist to Yahoo; this is disclosed in the README and required for the widget to function.
  • Symbols loaded from ~/.local/state/omarchy/settings/stock-ticker.json are not regex-validated before being used in a bash command, but single quotes are stripped and values are wrapped in single quotes, so command injection is not evident.
  • The repository contains only a QML entry point, manifest, README, and license; no obfuscated code, credential access, persistence, or destructive commands were found.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/Macs9319/OmaStockTicker --enable
Other #bar

OmaStockTicker

A stock ticker watchlist bar widget for Omarchy's Quickshell-based status bar, styled after the macOS Stocks widget.

Click the pie-chart icon in the bar to open a dropdown showing your watchlist, grouped into ETF and Stock tabs, each with live price, change, and an intraday sparkline.

<p align="center"> <img src="screenshots/bar-icon.png" alt="Bar icon" width="600"><br> <img src="screenshots/panel.png" alt="Stock Ticker panel" width="320"> </p>

Features

  • Add / remove tickers — type a symbol (e.g. AAPL) and hit Add; click the ✕ on a row to remove it, or select a row and press x from the keyboard.
  • Auto-categorized tabs — new tickers are classified as ETF or Stock automatically from Yahoo Finance's instrument type, and land in the right tab.
  • Live quotes — price, absolute change, and percent change, colored green/red.
  • Intraday sparkline — a small line chart under each ticker, plotted from the day's 15-minute closes.
  • Keyboard-friendly — Up/Down (or j/k) to move the selection, x to delete, Enter/Space to activate the focused control.
  • Persists across restarts — your watchlist is saved to ~/.local/state/omarchy/settings/stock-ticker.json.
  • No API key required — quotes come from Yahoo Finance's public chart endpoint via curl and jq.

Requirements

  • Omarchy (Quickshell-based shell)
  • curl and jq on PATH (both ship by default on Omarchy)

Installation

Clone this repo's contents into a plugin folder named stockticker under Omarchy's user plugin directory — the folder name must match the id in manifest.json:

git clone https://github.com/Macs9319/OmaStockTicker ~/.config/omarchy/plugins/stockticker

Add the widget to your bar:

omarchy bar put stockticker

New plugins sometimes need a full shell restart (not just a hot reload) to size the bar icon correctly the first time:

omarchy restart shell

Updating

cd ~/.config/omarchy/plugins/stockticker
git pull
omarchy restart shell

Uninstalling

omarchy plugin disable stockticker
rm -rf ~/.config/omarchy/plugins/stockticker

Your saved watchlist at ~/.local/state/omarchy/settings/stock-ticker.json is left in place in case you reinstall later; delete it manually if you want a clean slate.

How it works

Panel.qml is a single Omarchy shell plugin (bar-widget kind) built on the shell's Panel base component. On open, and every 90 seconds while open, it shells out to curl (piped through jq) against Yahoo Finance's unauthenticated chart endpoint (query1.finance.yahoo.com/v8/finance/chart/<SYMBOL>) for each tracked symbol, pulling the current price, previous close, instrument type, and a day of 15-minute closes for the sparkline. No API key or server-side component is involved.

License

MIT