plasma6-applets-wmp-toolbar-plasmoid-git
Builds from the project's own git repository on gitgud.io (a GitLab instance), which is a plausible project-owned source; SKIP checksum is normal for VCS sources; no prebuilt binaries, no remote code execution, just a standard CMake build of a KDE Plasma applet.
Triggered rules
zero_votes_recent
Uploaded within the last 14 days with 2 or fewer community votes — little peer review so far.
llm_review
The static rules flagged this MEDIUM, but an AI model (anthropic/claude-sonnet-4.6) reviewed the full PKGBUILD and judged it LOW (confidence 80%): Builds from the project's own git repository on gitgud.io (a GitLab instance), which is a plausible project-owned source; SKIP checksum is normal for VCS sources; no prebuilt binaries, no remote code execution, just a standard CMake build of a KDE Plasma applet.
1 higher static finding superseded - not the current verdict (shown for transparency)
source_untrusted_domain
One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).
-
PKGBUILD:13
source=(git+"https://gitgud.io/catpswin56/wmp-toolbar-plasmoid.git")
PKGBUILD
1 offending line(s) highlighted# Maintainer: Cogumelo cogumelo@tutamail.com
pkgname=plasma6-applets-wmp-toolbar-plasmoid-git
pkgver=0.0.1
pkgrel=1
license=('none')
arch=('x86_64')
pkgdesc="MPRIS controller that looks like the WMP toolbar"
url="https://gitgud.io/catpswin56/wmp-toolbar-plasmoid"
depends=('libplasma')
makedepends=('vulkan-headers' 'gcc' 'extra-cmake-modules')
provides=("$pkgname=$pkgver")
conflicts=("$pkgname")
source=(git+"https://gitgud.io/catpswin56/wmp-toolbar-plasmoid.git")
sha256sums=('SKIP')
prepare() {
cmake -S wmp-toolbar-plasmoid -B build -DCMAKE_INSTALL_PREFIX="$pkgdir"/usr
}
build() {
cmake --build build
}
package() {
cmake --install build
}
Scan history
| Scanned at (UTC) | Severity | Rules |
|---|---|---|
| 2026-10-06 00:19:23 | Low | 3 |
| 2026-10-06 00:13:36 | Low | 3 |
| 2026-10-05 23:40:58 | Medium | 2 |