

Can we start expecting open-source or self-hostable options for Jellyfin/Plex companion apps submitted to this sub?
Lately, across a lot of hobbyist communities, I've noticed a huge influx of companion apps, dashboards, wrappers, and utilities built by passionate and well-meaning developers.
That's not necessarily a bad thing. LLMs have lowered the barrier to entry and made it much easier for someone to take an idea from "wouldn't it be cool if..." to a usable application. That's genuinely exciting and I've had great fun myself kit-bashing some mad ideas.
What I've been wondering, though, is whether communities like Jellyfin, Plex, Home Assistant, self-hosting, and homelabs should start setting higher expectations around trust and deployment models.
A recent example was an app asking users to:
> Enter your Jellyfin/Plex server URL and credentials into a hosted web app. Don't worry, your browser talks directly to your server and nothing goes through our servers.
That may be true in terms of traffic flow, but it doesn't fully address the trust issue.
If the application is loaded from a third-party domain, then the JavaScript handling those credentials is also loaded from that third-party domain. Even if no traffic is proxied through the developer's backend, users are still trusting whatever code is served today, tomorrow, and after any future update.
Another trend I've noticed is seeing the telltale signs of heavily AI-generated applications. Again, this isn't a criticism of using AI as a tool. Plenty of experienced developers use it every day.
The concern is that when an application appears to have been assembled rapidly from generated code, my confidence in long-term maintenance, security review, and the developer's understanding of the deeper workings naturally decreases. That may be unfair in some cases, but I don't think it's an unreasonable concern when we're talking about software that interacts with self-hosted infrastructure.Especially something as DB and API heavy as Jellyfin.
For context, I'm terrible at frontend development. If I built something myself, it'd probably be a collection of badly aligned divs and questionable CSS. A polished UI doesn't prove competence, just as an ugly UI doesn't disprove it.
For communities built around self-hosting and user control, I'd love to see at least one of the following become the norm:
- Open-source code
- A self-hostable Docker/container version
- A local-first deployment model
- A clear technical explanation of credential handling
- Token-based authentication rather than asking for primary account passwords where possible
Obviously nobody owes me anything, and I've contributed very little compared to many of the developers building these tools. But if we're building software for communities that value ownership, transparency, and control, I think it's reasonable to expect some combination of those things.
Curious whether others feel the same, or whether I'm being overly cautious.
I planted this wisteria when we moved in with the idea it'd cover the south facing wall but it's not really matured as much as I thought.
Is it just a case of it still being pretty young?
It does spend a bit of time in the shade of a tree, this was taken about 6am this morning 1/5/26
First time in the foothills got bored of these homing missiles, so they went in the pen :D