Omahub
← All plugins
R

Shop

by ronald2wing

Push/pull Shopify themes and watch per-store sales from the Omarchy bar. No token is stored — auth lives in the Shopify CLI.

Security review

Review recommended · 4 findings

Deterministic scan — not a security guarantee

Medium
Risk level
Medium
Analyzed commit
fcfab17
Scanned
3 days ago
  • medium package_manager Service.qml:457

    Global npm package installation.

    npm install -g` only calls mise's best-effort npm wrapper, which can
  • Docs package_manager README.md:34

    Global npm package installation.

    npm install -g @shopify/cli@4.7.0`).
  • Docs package_manager AGENTS.md:64

    Global npm package installation.

    npm install -g` does NOT reliably produce a shim — mise's `node.npm_shim` wrapper is best-effort (`mise reshim || true`) and silently skips on failure. After install, `installRefreshTimer` keeps `cliI
  • Docs sudo README.md:43

    Command runs with sudo, elevating the process beyond the plugin environment.

    sudo required

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
fcfab17
Reviewed
3 days ago

The plugin is a transparent Shopify sales/theme manager that shells out to the user's Shopify CLI; the code is readable, tested, and contains no obfuscation, credential theft, hidden persistence, or elevated automatic actions. The deterministic medium findings are tied to documentation/comments about the optional CLI install and the README's "No sudo required" text, not to actual malicious or unintended commands. The main real-world side effects are user-initiated: installing the Shopify CLI on demand and performing explicit theme push/pull operations.

  • The one-click install action provisions @shopify/cli@4.7.0 globally (via mise/npm) when the CLI is missing; it is opt-in and surfaced in the UI, but it is a system-level package install.
  • Theme push can overwrite the live Shopify theme; it is explicitly user-triggered and makes a backup first, but it is still a destructive store operation.
  • The deterministic scan's 'sudo required' and 'npm install -g' findings come from README text and internal comments, not from actual privileged or automatic shell commands in the shipped code.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/ronald2wing/Omarchy-Shop --enable
Developer Tools #bar

Shop

Shopify sales + theme management, right from your Omarchy bar.

Shop is an Omarchy desktop-shell plugin. It shows live sales for each of your Shopify stores in the bar and gives you full theme sync (push/pull/dev) without leaving the shell. No token is stored by the plugin — authentication lives in the Shopify CLI (shopify).

Features

  • Live sales per store — today's revenue + order count in the bar, with an ▲/▼ trend versus yesterday at the same time of day.
  • Per-store dashboard — a six-range selector (Today, Yesterday, 7d, 14d, 30d, All) drives the Sales/Orders figures, a sparkline whose bar height is that period's sales and whose bar color is its per-day Revenue/Session Index (hover a bar for the day, amount, and RSI %), and an eight-stat grid: Sales, Orders, AOV, CVR, Visitors, Checkout CVR, ATC, and RSI. RSI (Revenue/Session Index) is today's revenue-per-session as a percentage of the all-time baseline — 100% is average, above means more revenue per session than usual, below less.
  • New-order notifications — when a store's today order count rises, a desktop notification fires and a short coin sound plays (both toggleable together).
  • Theme sync — push/pull with a per-store theme picker (defaults to the live theme; pick any draft/dev theme), a safety snapshot of the live theme before every push, one-click restore of any snapshot, and a live-preview theme dev mode with an "Open preview" link.
  • Store discovery — pull your accessible stores from the Shopify CLI and add them in one click; auth is triggered in-app.
  • Per-store control — toggle which stores show on the bar, and drag-to-reorder them.
  • Automatic CLI setup — if the Shopify CLI is missing, the panel shows a warning with a one-click Install button (installs via npm install -g @shopify/cli@4.7.0).

Requirements

  • Omarchy desktop shell
  • Shopify CLI (shopify) on PATH — or let the plugin install it for you (Node.js/npm ships with Omarchy via mise)
  • paplay for the new-order sound (ships with PipeWire/PulseAudio — standard on Omarchy)
  • No sudo required

Install

omarchy plugin add https://github.com/ronald2wing/Omarchy-Shop --enable

After installing, add a store (Configure → Add store, or Discover stores). Adding a store triggers a one-time browser authorization (Shopify read_reports,read_orders,read_customers scope); the token is stored by the Shopify CLI, not by this plugin.

Removal

omarchy plugin remove shop

Configuration

Config lives at ~/.config/shop/config.json:

{
  "refreshIntervalSec": 60,
  "notifyNewOrders": true,
  "stores": [
    {
      "name": "My Store",
      "domain": "my-store.myshopify.com",
      "themeDir": "/path/to/theme",
      "theme": "live",
      "showOnBar": true
    }
  ]
}
  • refreshIntervalSec — how often (seconds) the service polls live sales. Theme history and completed-period stats refresh once an hour.
  • notifyNewOrders — whether to notify (desktop notification + coin sound) when a store's today order count rises (default true; toggle it in Configure).
  • stores — one entry per store:
    • name, domain (the *.myshopify.com subdomain) — required.
    • themeDir — optional local theme path (Push/Pull/Dev are disabled without it).
    • theme — "live" (default) or a specific theme id, set via the theme picker.
    • showOnBar — whether this store appears on the bar (a new store defaults to hidden once 3 stores are already shown).
  • Currency is auto-detected from Shopify — there is no currency field.

Runtime state is written by the service to ~/.local/state/shop/state.json. ~/.local/state/shop/history.json holds a rolling 48h of 5-minute same-time stats snapshots used for the per-stat ▲/▼ trends. Theme snapshots are stored under ~/.local/state/shop/backups/<domain>/.

Keyboard shortcuts (with the popup open)

r refresh all · c configure / back · p push · u pull · a auth

Troubleshooting

Theme push/pull fails with "Theme CLI authentication failed" — your Shopify OAuth session is stale. Run in a terminal:

shopify auth logout && shopify auth login

(logout first — login alone is often insufficient to clear a stale session.)

"Shopify CLI not found" — the Shopify CLI is missing from your PATH. Click Install in the banner to install it via npm (takes a few seconds), or install it yourself from https://shopify.dev/docs/api/shopify-cli.