Omahub
← All plugins
S

CalDav Calendar

by sirwizardlizard

Create events in the Omarchy clock and sync them to iPhone, Mac, and other CalDAV calendars.

Security review

Review recommended · 2 findings

Deterministic scan — not a security guarantee

Medium
Risk level
Medium
Analyzed commit
2b35b6f
Scanned
2 weeks ago

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
2b35b6f
Reviewed
2 weeks ago

The plugin is a well-engineered CalDAV calendar widget with a Python helper that includes extensive security hardening (file permission checks, symlink rejection, response size limits, timeouts, and credential handling via the system keyring). The only deterministic finding is a `sudo apt-get install -y jq` in the CI workflow, which is test infrastructure and not part of the plugin runtime, so it poses no risk to end users. No obfuscation, hidden persistence, or destructive behavior was found.

  • The CI workflow uses `sudo apt-get install -y jq`, but this runs only in GitHub Actions for testing and is not executed on user systems.
  • The plugin can modify the shell config to retarget the center anchor if it points to `omarchy.clock`; this is documented and only happens when the user installs the plugin, not silently.
  • The plugin offers to install Evolution Data Server via `omarchy pkg add` if missing, but this is user-initiated and clearly prompted.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/SirWizardLizard/omarchy-caldav-calendar --enable
Productivity #bar #quickshell

CalDav Calendar

Add an event from the Omarchy clock. It shows up on your iPhone, Mac, and everywhere else your CalDAV calendar lives.

iCloud, Nextcloud, Fastmail — same two-way sync. Month, week, and day views, meeting links, and reminders, without moving the clock.

<p align="center"> <img src="screenshots/month.png" alt="Month view" width="800"> </p>

Install

omarchy plugin add https://github.com/SirWizardLizard/omarchy-caldav-calendar --enable

This replaces the built-in clock. Shortcuts stay put. If Omarchy leaves the center pin on omarchy.clock, the plugin retargets that pin to itself on first run. It does not change a custom or empty pin.

The plugin needs Evolution Data Server. If it is not installed, the clock opens a prompt with Click to install (opens a terminal for omarchy pkg add evolution-data-server) and SOURCE (the Arch package page). You do not have to run that command yourself.

What it does

  • Month, week, work week, and day views
  • Create, edit, and delete events (including overnight and recurring) — they sync to your phone and other devices
  • iCloud, Nextcloud, Fastmail, and other CalDAV servers
  • Calendars that live only on this computer
  • Join Zoom, Google Meet, or Teams from a link on the event
  • Optional desktop reminder 5–30 minutes before timed events
<p align="center"> <img src="screenshots/week.png" alt="Week view" width="480"> </p>

Add iCloud

Do not use your Apple ID password. Apple requires an app-specific password.

  1. Open account.apple.com → Sign-In and Security → App-Specific Passwords

  2. Generate a password (2FA must be on)

  3. Click the clock → Add calendar

  4. Enter:

    Field Value
    Display name iCloud
    CalDAV URL https://caldav.icloud.com/
    Username your Apple ID email
    Password the app-specific password
  5. Add CalDAV source, then Sync if events are not there yet

Remove a calendar later from settings.

Other CalDAV

Same form. Use the provider’s CalDAV URL and an app password when they require one.

  • Nextcloud: https://your-server/remote.php/dav/
  • Fastmail: https://caldav.fastmail.com/

Subscribe to an iCalendar feed

For a read-only .ics or iCalendar subscription URL:

  1. Click the clock → Add calendar → iCalendar
  2. Enter a display name and the subscription URL
  3. Click Add subscription

No username or password is needed when access is provided by a token in the URL. Subscription events refresh automatically and cannot be created, edited, or deleted from this plugin.

Meetings

Paste a Zoom, Meet, or Teams URL on the event (meet.google.com/… is fine). Join opens it. The plugin does not sign in to Google, Zoom, or Outlook.

Reminders

Settings → Remind me: off, or 5 / 10 / 15 / 30 minutes before timed events. Click a meeting toast to join.

<p align="center"> <img src="screenshots/settings.png" alt="Settings" width="800"> </p>

Not included

Google Calendar and Outlook need OAuth app review. They are not in this plugin. CalDAV servers and local calendars are.

Uninstall

omarchy plugin disable sirwizardlizard.calendar
omarchy plugin remove sirwizardlizard.calendar

Requirements

Omarchy 4, Python 3, and Evolution Data Server. If EDS is missing, the plugin offers to install it. License: MIT.

Credentials stay in the system keyring. They are never written to shell.json or this repo.

Development

./test/all
omarchy plugin validate .