Omahub
← All plugins
T

DDEV Projects

by Tony

Herd-style DDEV project manager for the bar — see running projects, start/stop, and launch them in your browser

Security review

No obvious issues detected

Deterministic scan — not a security guarantee

None
Risk level
None
Analyzed commit
9382014
Scanned
1 month ago

No potentially dangerous behavior detected in the analyzed commit.

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
9382014
Reviewed
1 month ago

The plugin manages local DDEV projects via a bar widget, executing ddev/docker commands with proper timeout and quoting. User inputs (like project paths) are shell-quoted to prevent injection, and all external output is capped to avoid resource exhaustion. The manifest, README, and sampled QML files show no obfuscation or malicious patterns; the deterministic scan found no issues.

  • New WordPress sites are created with default admin/admin credentials, which is a weak default but documented in the README.
  • The plugin runs as the current user and can start/stop containers and install add-ons, which is expected for a DDEV manager; a user should review the trustworthiness of ddev/ddev-adminer if used.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/sanjayatony/omarchy-ddev-projects --enable
Developer Tools #bar

DDEV Projects

A Herd-style bar widget for managing local DDEV projects from the Omarchy bar — start/stop projects, open a database admin tool, check sent email, and scaffold new WordPress sites, without leaving the bar.

Install

omarchy plugin add https://github.com/sanjayatony/omarchy-ddev-projects.git --enable

Choose a bar section when prompted (right is the default).

Usage

Click the server-rack icon in the bar to open the panel. It lists every project ddev list knows about, refreshing automatically every few seconds while open.

Each project row shows:

  • A status dot (accent = running, muted = stopped) and an uncommitted-changes warning badge when a running project's git repo is dirty.
  • Open in browser — opens the project's primary URL.
  • Mailpit — opens the project's Mailpit inbox (sent emails), no extra setup required.
  • DB Admin — opens Adminer for the project's database. On first use per project this installs the ddev/ddev-adminer add-on and restarts that project's containers; subsequent clicks just open the browser.
  • Start / Stop — runs ddev start / ddev stop for that project.

At the top of the panel, New WordPress Site creates a fresh WordPress install at a path you choose (defaults to ~/Work/): it runs ddev config, ddev start, ddev wp core download, and ddev wp core install, then shows the login (admin / admin) until you hit refresh.

Configuration

No configuration file — the panel always reflects live ddev list output. There's nothing to set in shell.json beyond the widget's placement (omarchy bar move tony.ddev-projects --section <left|center|right>).

Notes

  • Every ddev/docker action the panel runs is wrapped in a timeout, with a background watchdog as a second safety net, so a hung command can't permanently disable the panel's buttons.
  • DB Admin and site creation both invoke ddev/Docker directly and can restart or create containers — expected DDEV behavior, not a bug.
  • Change the WordPress admin credentials in Panel.qml's createSite() if you don't want the admin/admin default.

Removal

omarchy plugin remove tony.ddev-projects

This only removes the plugin — it does not touch any DDEV projects, containers, or data.