Omahub
← All plugins
6

Proton Mail

by 686f6c61

Unread Proton Mail count in the bar, recent-mail dropdown and desktop notifications

Security review

Review recommended · 6 findings

Deterministic scan — not a security guarantee

Low
Risk level
Low
Analyzed commit
c2ad5c4
Scanned
1 month ago

Flagged patterns appear only in documentation files (README / docs) — descriptive examples, not executable code.

  • Docs external_hosts README.de.md:59

    Downloads or connects to an external HTTP(S) host.

    git clone https://github.com/686f6c61/Omarchy-Proton-Mail.git
  • Docs external_hosts README.md:56

    Downloads or connects to an external HTTP(S) host.

    git clone https://github.com/686f6c61/Omarchy-Proton-Mail.git
  • Docs external_hosts README.it.md:59

    Downloads or connects to an external HTTP(S) host.

    git clone https://github.com/686f6c61/Omarchy-Proton-Mail.git
  • Docs external_hosts README.zh.md:47

    Downloads or connects to an external HTTP(S) host.

    git clone https://github.com/686f6c61/Omarchy-Proton-Mail.git
  • Docs external_hosts README.fr.md:60

    Downloads or connects to an external HTTP(S) host.

    git clone https://github.com/686f6c61/Omarchy-Proton-Mail.git
  • Docs external_hosts README.es.md:59

    Downloads or connects to an external HTTP(S) host.

    git clone https://github.com/686f6c61/Omarchy-Proton-Mail.git

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
c2ad5c4
Reviewed
1 month ago

The plugin is a well-hardened Proton Mail notifier that uses a dedicated browser profile with CDP over pipe fds (no TCP debug port) and a read-only unix-socket API with SO_PEERCRED authentication. The deterministic findings are documentation-only examples of `git clone` in READMEs; the actual installer uses vendored assets and no install-time downloads. No obfuscation, hidden persistence, or destructive commands were found.

  • The broker forwards non-Proton tabs to the default browser (with cookies/logins) and closes them in the webapp; this is documented but could be surprising to users who click links in emails.
  • The broker has access to mailbox metadata (sender, subject, time) via CDP; this is inherent to the widget's function and is clearly described.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/686f6c61/Omarchy-Proton-Mail --enable
Widgets #bar #quickshell

Omarchy Proton Mail Notifier

English | Español | Français | Deutsch | Italiano | 中文

An Omarchy shell plugin that shows your unread Proton Mail count in the bar (top-right, next to the tray), drops down a list of your most recent messages when clicked, and raises a desktop notification when new mail arrives.

No browser extension, no Proton Mail Bridge — works with free and paid Proton accounts and any Chromium-based browser (Brave, Chrome, Chromium, Edge).

The widget speaks English, Español, Français, Deutsch, Italiano and 中文 (English by default), and everything — poll interval, dropdown size, header nickname, notifications, language — is configurable live via omarchy bar set.

Screenshots

Dropdown with recent messages

Widget tooltip in the bar

How it works

Proton Mail webapp (dedicated browser profile, --app window)
title: "(3) Inbox | … | Proton Mail"
        │
        ├─ hyprctl clients -j ──► omarchy-protonmail-unread ──► badge 󰇮 N + notification
        │   (window titles)          (every intervalSec)
        │
        └─ --remote-debugging-pipe ──► omarchy-protonmail-broker ──► dropdown with last N
            (CDP over inherited fds 3/4,        (sole CDP client, unix-    messages + external
             no TCP debug port at all)           socket API + tab sweep)    links to default browser
  • Unread count: Proton Mail puts it in the page title as (N), and Hyprland exposes window titles via hyprctl clients -j. Works with the webapp window and any regular browser tab showing Proton Mail.
  • Recent messages: the webapp launches through omarchy-protonmail-broker with --remote-debugging-pipe, so the browser speaks CDP over file descriptors inherited from the broker — there is no TCP debug port, fixed or random, for other processes to attack. The broker serves truncated inbox rows on a unix socket (SO_PEERCRED-authenticated) to omarchy-protonmail-recent — stdlib-only Python, nothing else to install.
  • External links: the broker also sweeps the tab list and forwards any tab whose host is outside the exact Proton allowlist to the default browser (your main profile, with cookies and logins), closing it in the webapp.

Install

git clone https://github.com/686f6c61/Omarchy-Proton-Mail.git
cd Omarchy-Proton-Mail
./install.sh

The installer:

  1. Downloads the Proton icon and creates a "Proton Mail" webapp launcher (omarchy webapp install) with a dedicated profile + CDP port.
  2. Installs omarchy-protonmail-unread and omarchy-protonmail-recent to ~/.local/share/omarchy-protonmail/.
  3. Installs the shell plugin to ~/.config/omarchy/plugins/686f6c61.proton-mail/.
  4. Enables the widget in the right section of the bar (backs up ~/.config/omarchy/shell.json first) and restarts the shell.
  5. Asks for your language and an optional nickname (interactive). Non-interactive alternative: ./install.sh --language es --nickname "My mail"

Then launch Proton Mail from the app launcher (SUPER + SPACE) and log in. The dedicated profile means you log in once, separately from your main browser.

Usage

  • Left-click the widget: dropdown with the last N messages (sender, subject, time; unread ones in bold). Click a message to jump to the Proton Mail window — the existing one is focused, never duplicated.
  • The dropdown header shows the Proton Mail logo, and the bottom row has a Pause notifications switch that flips the notify setting live.
  • Links clicked inside a message open in your default browser (main profile), not in the webapp's dedicated profile.
  • With recentCount: "0" the dropdown is disabled and left-click just focuses the Proton Mail window (pure notifier mode).
  • Right/middle-click: refresh now.
  • Clicking the notification opens/focuses Proton Mail too.

Widget states (always visible while enabled):

State Meaning
󰇯 dimmed Proton Mail window not open
󰇯 normal Open, no unread mail
󰇮 N (accent) N unread — notification fired
󰇮 99+ (accent) More than 99 unread

Settings

The quickest way is the omarchy bar set command (applies live, no restart):

omarchy bar set 686f6c61.proton-mail recentCount 7
omarchy bar set 686f6c61.proton-mail nickname "My mail"
omarchy bar set 686f6c61.proton-mail language es
omarchy bar set 686f6c61.proton-mail intervalSec 10
omarchy bar set 686f6c61.proton-mail notify false

You can also edit the widget entry inline in ~/.config/omarchy/shell.json:

{ "id": "686f6c61.proton-mail", "intervalSec": 5, "recentCount": "5", "notify": true, "nickname": "", "language": "en" }
  • intervalSec (2–60, default 5): poll interval for the unread count.
  • recentCount (0–20, default 5): messages listed in the dropdown. 0 disables the dropdown (notifier only).
  • notify (default true): desktop notification when the count goes up.
  • nickname (default empty): custom text for the dropdown header when there is no unread mail. Empty shows the default "All caught up".
  • language (en/es/fr/de/it/zh, default en): widget, dropdown and notification language (English, Español, Français, Deutsch, Italiano, 中文).

Troubleshooting

  • Widget missing after install: run omarchy restart shell (the QML loader caches failures against plugin URLs; a fresh shell clears them).
  • Widget not picking up QML edits while developing: same cause — the inotify hot-reload can keep serving cached bytecode for the plugin URL. Run omarchy restart shell after editing plugin files.
  • Dropdown shows the login row: log in inside the "Proton Mail" webapp window (the dedicated profile has its own session).
  • Dropdown empty while logged in: extraction may need retuning against your Proton version — run ~/.local/share/omarchy-protonmail/omarchy-protonmail-recent --dump and open an issue with the output.
  • The unread badge depends on Proton Mail's (N) page-title format; matching lives in bin/omarchy-protonmail-unread.

Uninstall

omarchy webapp remove "Proton Mail"
rm -rf ~/.config/omarchy/plugins/686f6c61.proton-mail ~/.local/share/omarchy-protonmail
# then remove the { "id": "686f6c61.proton-mail" } entry from ~/.config/omarchy/shell.json
# (or restore the shell.json.bak.<timestamp> backup created by install.sh)
omarchy restart shell

License

MIT © 686f6c61 github@00b.tech