For the complete documentation index, see llms.txt. This page is also available as Markdown.

Disclaimer

Project status, security guidance, legal disclaimer, and support expectations.

Project status

CrossWatch is in active development. Things can break between releases.

Disclaimer

CrossWatch is an independent community project. It is not affiliated with, endorsed by, or sponsored by Plex, Emby, Jellyfin, Trakt, SIMKL, TMDb, Tautulli, AniList, MDBList, or PublicMetaDB.

CrossWatch uses the AniBridge mappings dataset to translate media identifiers between AniList and providers such as TMDb, TVDB, IMDb, MyAnimeList, and AniDB.

All product names, logos, and brands belong to their respective owners. They are used for identification only.

Third-party APIs have their own rules. Use them without getting yourself banned.

This software is provided "as is", without warranties. Backups still beat regret.

Security

Do not expose CrossWatch directly to the public internet!

CrossWatch is intended for LAN/VPN use and may contain security weaknesses.

Putting CrossWatch on the public internet turns it into a target for automated scanners and real attackers. If there are any weaknesses, common ones in self-hosted apps include auth bypasses, weak session handling, missing rate limits, insecure defaults, outdated dependencies, or simple bugs, an attacker can use them to:

  • Get unauthorized access to the UI and any data it can reach.

  • Steal credentials/tokens if traffic isn’t properly encrypted end-to-end.

  • Abuse the service (brute-force logins, spam requests, DoS) if there’s no throttling/WAF.

  • Exploit known CVEs in the stack (framework/libs) the moment your instance is discoverable.

Therefore:

  • Keep CrossWatch off the public internet (no direct exposure, no port-forwarding).

  • Prefer binding to localhost / LAN only and restrict access with your firewall.

  • For remote access, use a VPN (WireGuard/Tailscale) rather than opening ports.

  • Enable UI authentication (Settings - Security).

  • Enable HTTPS/TLS (recommended).

Dependencies

Runtime dependencies (for transparency)
  • fastapi - API server

  • pydantic - request/response models

  • uvicorn - ASGI server

  • requests - HTTP client

  • plexapi - Plex API client (third-party)

  • websocket-client - WebSocket client (events where applicable)

  • websockets - asyncio WebSocket support

  • python-multipart - multipart/form-data support

  • packaging - version parsing and feature gating

Support expectations

This is a community project. Support is best-effort.

Be respectful and constructive when you ask for help. If you need guaranteed support, this project is not that.

Last updated

Was this helpful?