Omahub
← All plugins
T

OpenHAB

by tdeckers

Show selected OpenHAB items on the Omarchy bar and in a details panel.

Security review

No obvious issues detected

Deterministic scan — not a security guarantee

None
Risk level
None
Analyzed commit
61e4693
Scanned
1 month ago

No potentially dangerous behavior detected in the analyzed commit.

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
61e4693
Reviewed
1 month ago

The plugin is a straightforward OpenHAB bar widget that fetches item states over HTTP(S) and stores credentials in the user keyring or a 0600 config file. The deterministic scan found no issues, and the sampled code shows no obfuscation, persistence, or destructive behavior. The only minor concern is that the helper script is invoked via `python3` and the plugin stores a token/URL in a user config file, which is expected and disclosed in the README.

  • The plugin stores an OpenHAB URL and API token/credentials in ~/.config/omarchy/tdeckers.openhab.json (mode 0600) when no keyring is available; this is disclosed and acceptable, but users should prefer a keyring.
  • The helper script is executed with `python3` from the plugin directory; if the plugin checkout is writable by an attacker, the script could be modified, but this is a general plugin trust consideration, not a specific flaw.
  • The plugin makes network requests to a user-configured OpenHAB server; no unexpected network destinations or destructive commands were found.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/tdeckers/omarchy-openhab --enable
Hardware #bar #quickshell

OpenHAB for Omarchy

Bar widget for Omarchy that shows the first selected OpenHAB item. Click the pill to see the rest (up to 10). Right-click or Setup configures the server and picks items.

Plugin id: tdeckers.openhab

Install

omarchy plugin add https://github.com/tdeckers/omarchy-openhab.git --enable

Place it on the bar if needed:

omarchy bar move tdeckers.openhab --section right

Setup

  1. Left-click OH on the bar, then Setup (or right-click the pill).
  2. Paste the OpenHAB URL (http://openhab.local:8080 or https://…). If a reverse proxy sits in front, use that public URL.
  3. Paste credentials:
    • username:password when the server uses HTTP Basic (common behind a proxy)
    • or an API token from OpenHAB → Profile → Security (starts with oh.)
  4. Save, then Reload items.
  5. Search the list and click rows to select (●). The first selected item is the bar label.

The secret is stored with secret-tool when a keyring is available; otherwise it is written to ~/.config/omarchy/tdeckers.openhab.json (mode 0600). Prefer HTTPS.

Selected item names and the URL are stored in that same config file. It is outside the plugin checkout and is never committed.

Use

  • Left-click the bar: status panel
  • Right-click the bar: settings
  • Escape closes the panel

States refresh every 15 seconds by default:

omarchy bar set tdeckers.openhab refreshIntervalSec 30

Remove

omarchy plugin remove tdeckers.openhab

Working on the plugin itself is covered in CONTRIBUTING.md.

License

MIT. Not affiliated with the OpenHAB project or Omarchy.