Omahub
← All plugins
P

Omalog

by palccod

Screen time tracker popup — today, week, and month views powered by ActivityWatch.

Security review

Potentially dangerous behavior detected · 3 findings

Deterministic scan — not a security guarantee

High
Risk level
High
Analyzed commit
e415195
Scanned
1 month ago

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
e415195
Reviewed
1 month ago

The plugin runtime is a read-only QML/Python viewer over ActivityWatch's local SQLite database with no network access or credential handling. The deterministic scan's high findings are explained by the optional setup script and bundled systemd units, which are transparent, user-initiated, and match the documented behavior. The setup script does install an AUR package and modify user services/autostart, so it is not risk-free, but nothing malicious or hidden was found.

  • The optional setup script installs activitywatch-bin from the AUR via yay with sudo, which is a supply-chain consideration but is user-initiated and clearly documented.
  • The setup script kills running aw-qt/aw-watcher processes and writes an autostart override; this is invasive but scoped to ActivityWatch and explained in the README.
  • The bundled systemd user units enable services at login; this is expected for a tracker and only installed when the user explicitly runs the setup script.
  • The deterministic scan's external_hosts finding is in README documentation only, not executable code.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/Palccod/Omalog --enable
Productivity #bar #quickshell

Omalog for Omarchy

A screen-time dashboard for the Omarchy bar. Click the calendar icon and a popup panel shows where your time on this computer goes — which apps, which categories, which hours of the day. Today, this week, this month. All local, no cloud.

Built as an Omarchy Quickshell plugin, powered by ActivityWatch.

What it does

The plugin reads ActivityWatch's local database directly (aw-server-rust's SQLite file) and renders the same picture the Daylog TUI gives you, as a bar popup:

  • Today — active time, longest focus stretch, best 3-hour window, and how today's categories compare to your usual week (pattern shift). A full-width timeline barcode of the day so far, colored by category. Top apps, categories, and domains. An hourly activity chart with the Daylog "activity spectrum" (warm at dawn, violet at midnight).

  • Week — total active time, daily average, and best day for the current Mon–Sun week. Seven horizontal bars stacked by category, with the peak day marked. Top apps, categories, and domains over the last 7 days.

    Week view

  • Month — total, daily average over active days, and best day of the last 30 days. A GitHub-style year heatmap of daily activity. Top apps, categories, and domains over the last 30 days.

    Month view

If the tracker's window watcher wedges (a known awatcher failure mode: it keeps running but only records unknown apps), the panel shows a "Tracking is degraded" banner with a one-click Restart watcher button, so you can fix tracking without touching a terminal.

Tabs are clickable, and also respond to <kbd>1</kbd>–<kbd>3</kbd> and <kbd>←</kbd>/<kbd>→</kbd>. Data refreshes live while the panel is open (today every 5 s, week/month every 30 s).

Getting started

You need Omarchy (Quickshell-based shell) and Python 3. An AUR helper (yay/paru) is only needed for the tracking setup in step 2.

1. Install the plugin

omarchy plugin add https://github.com/Palccod/Omalog.git --enable

The calendar icon appears in your bar's center section. If it doesn't show up right away, restart the shell once (omarchy restart shell). Move the widget anywhere with:

omarchy bar move palccod.omalog --section right

To update to the latest version whenever the plugin is pushed to:

omarchy plugin update palccod.omalog && omarchy restart shell

(The restart reloads the QML — updates to the tracking setup aren't tied to plugin updates; the script in step 2 is safe to re-run on its own.)

2. Set up tracking

The plugin is a viewer — it reads ActivityWatch's database but doesn't run the tracker itself.

  • Already running ActivityWatch (aw-server-rust + a window watcher)? You're done — the plugin reads the standard database path and just works.

  • Starting from scratch? Run the setup script that shipped inside the plugin install (no extra clone needed):

    ~/.config/omarchy/plugins/palccod.omalog/setup/setup-tracking.sh
    

    It installs activitywatch-bin from the AUR (asks for your sudo password) and the awatcher window/AFK watcher for Wayland — downloaded over HTTPS and verified against a pinned SHA-256 checksum — then enables their systemd user services. Tracking starts within seconds; the database lives at ~/.local/share/activitywatch/aw-server-rust/sqlite.db. The script is safe to re-run and never touches existing data.

    One thing it handles for you: the activitywatch-bin package autostarts its own tray (aw-qt), whose Python watchers write garbage into the same database buckets (app: "unknown" for every window, "always afk"). The setup script stops those watchers and disables that autostart, leaving the aw-server-rust + awatcher services as the single source of truth.

If you open the panel before tracking exists, it shows a banner with this exact command — you can't get lost.

3. Optional: browser extension

For the "Top Domains" lists to fill in, install the ActivityWatch Web Extension in your browser. It connects to the local server automatically — no config. Everything else works without it.

4. Use it

  • Left-click the bar icon to open/close the panel
  • 1 / 2 / 3 jump to Today / Week / Month
  • ← / → cycle tabs, Esc closes, Tab hops between Omarchy panels
  • Hovering the bar icon shows your active time so far today (refreshes every 30 s)

The panel can also be driven from the CLI / scripts:

omarchy shell palccod.omalog.panel toggle   # or open / close

Removal

omarchy plugin remove palccod.omalog

To also stop the tracking the plugin set up (this does not delete your recorded data):

systemctl --user disable --now aw-server-rust.service aw-awatcher.service
rm ~/.config/systemd/user/aw-server-rust.service ~/.config/systemd/user/aw-awatcher.service

Optionally remove the packages and binaries (pacman -R activitywatch-bin, rm ~/.local/bin/aw-awatcher). If you want the bundle's tray back after removing the plugin, delete the autostart override the setup script created:

rm ~/.config/autostart/aw-qt.desktop

Your activity history stays in ~/.local/share/activitywatch/ until you delete it yourself.

Security, privacy, and privileges

  • The plugin itself makes no network calls and needs no privileges. It runs a read-only Python (stdlib-only) query against ActivityWatch's local SQLite database on a fixed path. Nothing leaves your machine.
  • No secrets, tokens, or credentials are read, stored, or logged. The data displayed (app names, window titles, domains) is your own ActivityWatch data, read from disk.
  • The optional setup/setup-tracking.sh helper is the only component that installs anything: it invokes your AUR helper (which uses sudo) for activitywatch-bin, downloads the awatcher binary from its official GitHub release over HTTPS, verifies it against a pinned SHA-256 checksum before installing, and creates exactly two systemd user units (aw-server-rust.service, aw-awatcher.service) for the current user. It never edits unrelated services or configuration and is idempotent.
  • ActivityWatch's own server listens on localhost:5600; the plugin does not talk to it (it reads the database file directly), but the browser extension does.

How it works

manifest.json            plugin manifest (service + bar-widget)
BarWidget.qml            the bar button (icon + tooltip)
Panel.qml                the popup panel: tabs, keyboard, states
Service.qml              data fetching, refresh timers, state
Model.js                 formatting + color helpers
omalog_data.py           reads the ActivityWatch SQLite DB and runs the
                         Daylog data pipeline (flood, AFK intersect,
                         categorization, KPIs, aggregation) — stdlib only;
                         also reports watcher health for the degraded banner
components/              TabBar, KpiStrip, SectionLabel, TopList,
                         TimelineBarcode, HourlyChart, StackedWeekBars,
                         YearHeatmap
setup/                   optional one-command setup of the ActivityWatch
                         tracking backend (systemd units + install script)

The data pipeline is a faithful port of Daylog's Rust one: window events are flooded with a 5-second pulse, intersected with non-AFK periods, categorized by regex rules (Work / Media / Comms / Browsing / …), and aggregated into apps, categories, and domains. Queries are read-only against the SQLite file.

Developing

Clone straight into the plugins dir and iterate — changes hot-reload:

git clone https://github.com/Palccod/Omalog.git \
  ~/.config/omarchy/plugins/palccod.omalog
omarchy plugin validate ~/.config/omarchy/plugins/palccod.omalog
omarchy-shell shell rescanPlugins

The data helper can be tested standalone:

python3 omalog_data.py status   # is ActivityWatch's DB there?
python3 omalog_data.py today    # today's full JSON payload
python3 omalog_data.py week     # current ISO week
python3 omalog_data.py month    # 30-day stats + year heatmap

Credits & license

MIT — see LICENSE.

Special thanks to Manas-Kenge for building Daylog.

Tracking itself is plain ActivityWatch (MPL-2.0), installed from your distro's packages or upstream releases — see Getting started. Nothing ActivityWatch-related is bundled with or downloaded by this plugin.