Omahub
← All plugins
S

Salted Adhan

by salted-sorbet

Adhan prayer times widget with popup panel

Security review

Review recommended · 14 findings

Deterministic scan — not a security guarantee

Medium
Risk level
Medium
Analyzed commit
700512c
Scanned
1 month ago
  • medium eval praytimes.py:178

    Dynamic code execution via eval().

    eval(params['imsak']), times['imsak'], 'ccw')
  • medium eval praytimes.py:179

    Dynamic code execution via eval().

    eval(params['fajr']), times['fajr'], 'ccw')
  • medium eval praytimes.py:184

    Dynamic code execution via eval().

    eval(params['maghrib']), times['maghrib'])
  • medium eval praytimes.py:185

    Dynamic code execution via eval().

    eval(params['isha']), times['isha'])
  • medium eval praytimes.py:218

    Dynamic code execution via eval().

    eval(params['imsak']) / 60.0
  • medium eval praytimes.py:220

    Dynamic code execution via eval().

    eval(params['maghrib']) / 60.0
  • medium eval praytimes.py:222

    Dynamic code execution via eval().

    eval(params['isha']) / 60.0
  • medium eval praytimes.py:223

    Dynamic code execution via eval().

    eval(params['dhuhr']) / 60.0
  • medium eval praytimes.py:229

    Dynamic code execution via eval().

    eval(asrParam)
  • medium eval praytimes.py:248

    Dynamic code execution via eval().

    eval(params['imsak']), nightTime, 'ccw')
  • medium eval praytimes.py:249

    Dynamic code execution via eval().

    eval(params['fajr']), nightTime, 'ccw')
  • medium eval praytimes.py:250

    Dynamic code execution via eval().

    eval(params['isha']), nightTime)
  • medium eval praytimes.py:251

    Dynamic code execution via eval().

    eval(params['maghrib']), nightTime)
  • medium eval praytimes.py:278

    Dynamic code execution via eval().

    eval(self, st):

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
700512c
Reviewed
1 month ago

The plugin is a straightforward prayer times widget. The eval() calls in praytimes.py operate on hardcoded configuration values from the plugin's own methods dictionary, not on user input, so they do not pose a realistic code execution risk. The plugin performs network geolocation and writes files to the user's config directory, which is expected behavior.

  • The eval() calls in praytimes.py are flagged, but they only evaluate hardcoded strings from the plugin's internal configuration, not user-controlled input, so the risk is minimal.
  • The plugin makes an external network request to ip-api.com for geolocation, which is disclosed in the README and is a common practice, but users should be aware of this privacy consideration.
  • The plugin writes prayer times and notification tracking files to the user's config directory, which is normal for a widget but could be a minor concern if the directory is not properly sandboxed.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/salted-sorbet/salted.adhan --enable
Appearance #media

Salted Adhan

Preview

Prayer times widget with popup panel for Omarchy.

Features

  • Auto-detection: Automatically detects your location via IP geolocation
  • Accurate times: Uses MWL (Muslim World League) calculation method (Fajr 18°, Isha 17°)
  • Notifications: Critical urgency notifications when prayer time arrives
  • Popup panel: Click the widget to see all 5 daily prayer times
  • Refresh on demand: Manually refresh times from the panel

Installation

omarchy plugin install salted-sorbet/salted.adhan

Add to your shell layout:

{
  "bar": {
    "layout": {
      "right": [
        { "id": "salted.adhan" }
      ]
    }
  }
}

Removal

  1. Remove from your shell layout in ~/.config/omarchy/shell.json
  2. Uninstall the plugin:
omarchy plugin uninstall salted.adhan
  1. Remove config (optional):
rm -rf ~/.config/omarchy/salted.adhan

Usage

  • The widget displays "A" in the bar
  • Click to open the prayer times panel
  • Click Refresh to update times from the network
  • Notifications appear automatically at each prayer time

Configuration

The plugin stores its config in ~/.config/omarchy/salted.adhan/:

  • config.json — Saved coordinates (auto-detected or manual)
  • prayer_times.txt — Current prayer times
  • sent_today.txt — Tracks sent notifications

To manually set coordinates, edit config.json:

{
  "coordinates": [48.8566, 2.3522, 0]
}

Prayer Times

Prayer Description
Fajr Dawn prayer
Dhuhr Midday prayer
Asr Afternoon prayer
Maghrib Sunset prayer
Isha Night prayer

Calculation Method

Uses Muslim World League (MWL) method:

  • Fajr angle: 18°
  • Isha angle: 17°
  • Maghrib: Sunset (no offset)
  • Asr: Standard (Shafi'i)

License

MIT License — see LICENSE for details.