The repository is a plugin shelf, not a search service
qBittorrent already has a Search tab. This repository supplies the Python scripts that make that tab query external torrent indexes, plus documentation for installing and writing more. A plugin receives a query and category, contacts a site, parses the response, then prints fields such as link, name, size, seeds, leechers, description URL, and publication date in the format qBittorrent expects.
The current tree is deliberately small. It contains site-specific engines and a Jackett bridge under nova3/engines, while the wiki points users to a much larger unofficial list. The README also sets expectations: maintainers lack capacity to add more official plugins, fixes to existing ones are welcome, and community contributors run the hub without direct management from the qBittorrent core team.
What happened when we ran it
Our run cloned commit 4082cfc into a fresh unprivileged Debian container with 3 CPUs and 8 GB of RAM. The npm install step succeeded in 9 seconds, added 0 packages, and left 1 MB on disk. npm audit reported 0 known vulnerabilities at every severity. The repository itself was 0.2 MB, with 43 files and about 1,298 source lines.
There was no npm build script or target, so the build step was skipped. The same was true for tests: no npm test script or target was available to our harness. Those skips are findings, not passes. This repository's root package file describes the wiki and declares no dependencies. Contributor instructions under nova3 use a separate Python and uv workflow, outside the Node command path our supplied sandbox run measured.
Our scan recorded 4 CI workflow files, no Dockerfile, and no tests directory. Nothing in the lab result proves that any search engine answered, that a parser still matches its site, or that qBittorrent accepted a plugin. A meaningful functional check needs qBittorrent, Python, live access to the selected index, and a lawful search query. We did not run that interaction.
Installation is easy because the code runs inside qBittorrent
A user enables Search Engine from qBittorrent's View menu, opens Search plugins, and installs a .py file from disk or a web link. There is no server deployment for a normal site-specific plugin. Python must be available, and issue 358 says qBittorrent 5.1.0 or newer requires Python 3.9 or newer for full plugin compatibility.
The Jackett path has more moving parts. You install and start Jackett, copy the supplied jackett.py URL into qBittorrent, and create jackett.json beside the engine files. That file holds the Jackett API key, service URL, whether to prefix results with the tracker name, and a thread count that defaults to 20. The guide warns against exposing Jackett directly to the public internet and recommends private networking or an authenticated TLS proxy.
Every unofficial plugin is code you chose to trust
The installation wiki opens with the right warning: search plugins are third-party Python scripts and are not guaranteed safe. They run where qBittorrent can reach the network and may contain site credentials or cookies. A green entry in a community table does not replace reading the script, checking its source repository, and deciding whether its access matches your risk tolerance.
That warning has practical weight. Open issue 390 asks maintainers to remove an unofficial Prowlarr plugin whose source had not been updated since 2021, partly because the user did not want to place credentials in abandoned code. The issue remained active in September 2026. The official Jackett bridge is the better-documented aggregation path, yet it still stores an API key locally and depends on a second service.
Site changes are the normal failure mode
Scraper plugins depend on HTML, JSON responses, anti-bot controls, and download-link behavior owned by someone else. Issue 452 says an AudiobookBay plugin stopped working and appeared to trigger a temporary IP block after the site changed access rules. Other open reports describe broken magnet links, engines failing to initialize after a qBittorrent update, and a Jackett connection path creating a zero-process pool.
Those reports do not establish that every plugin is broken. They show why this repository needs continual small repairs. When one engine fails, disable it and inspect the issue before reinstalling random replacements. If you want many indexers, the project's own Jackett guide recommends putting the volatile site logic in Jackett and using one qBittorrent bridge, which is easier to reason about than a folder of unrelated scripts.
Recent commits coexist with a large issue backlog
GitHub showed 7,039 stars, a September 28 push, and 48 open issues and pull requests combined. A separate search returned 47 open issues, leaving one open pull request in that snapshot. Issue activity continued through September, including discussion of an unsupported plugin and an update to an existing engine. There is no GitHub release for this repository.
That maintenance model suits scripts delivered through qBittorrent's updater and raw GitHub links, though it makes release notes and versioned bundles unavailable. The repository remains active by push date and issue discussion. Its backlog also reflects the churn of external sites. Use a narrow set of reviewed plugins, prefer Jackett when your indexer list grows, and expect compatibility work as part of ownership.

