Omahub
← All plugins
D

Firefox Passwords

by Denis

Search, view, and copy Firefox saved logins from the bar, backed by firefox_decrypt

Security review

No obvious issues detected

Deterministic scan — not a security guarantee

None
Risk level
None
Analyzed commit
c594bed
Scanned
1 month ago

No potentially dangerous behavior detected in the analyzed commit.

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
c594bed
Reviewed
1 month ago

The plugin is a local-only Firefox password viewer that chains the standard firefox_decrypt script with a deliberately defensive stdin-piping architecture; no malicious behavior, persistence, network calls, or destructive commands were found. The deterministic scan found no issues, and the only risk is the inherent sensitivity of letting any bar plugin decrypt and copy saved credentials.

  • The plugin manages very sensitive Firefox login data; any compromise of the vendored firefox_decrypt.py or its invocation would expose saved passwords, though the sampled code is security-conscious (no argv/env secrets, memory-only storage, clipboard clearing).
  • Only a subset of source files was sampled; a full diff of the vendored firefox_decrypt.py against upstream would be prudent before publishing, but nothing in the reviewed sample is alarming.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/chupre/omarchy-firefox-passwords --enable
System #bar #security

Firefox Passwords for Omarchy

An Omarchy bar widget to search, view, and copy your Firefox saved logins — right from the bar.

Uses firefox_decrypt to decrypt logins.json / key4.db locally. Nothing is written to disk; decrypted entries live in memory only and are wiped when the popup closes.

preview

Requirements

  • Omarchy
  • Firefox (native package, profiles at ~/.mozilla/firefox or ~/.config/mozilla/firefox)
  • nss ≥ 3.113 (omarchy pkg add nss — needed for Firefox 144+)
  • wl-clipboard (wl-copy)
  • python3

Getting Started

Install the plugin:

omarchy plugin add https://github.com/chupre/omarchy-firefox-passwords.git --enable
# or for local development:
./install.sh

The 󰈹 icon appears in the right section of the bar. Click it, pick a profile (the Firefox default is pre-selected and sorted first), leave the Primary password empty unless you set one in Firefox → Settings → Privacy & Security → Primary Password, then click Unlock.

Remove it:

omarchy plugin remove chupre.firefox-passwords

Usage

  • Unlock — explicit button; shows profile picker when you have more than one profile, plus a Primary Password field (leave empty if none set). Wrong password shows “Primary password is not correct.” and lets you retry. Exit code 12 means the profile’s key database couldn’t be opened — try the other profile.
  • Search — type to filter by site or username (all terms must match).
  • Copy — ↵ copies password, ctrl+↵ copies username; or use the 󰆏 buttons. Usernames are copied from the row header; passwords are copied from the expanded row. Copies use wl-copy and are not auto-cleared.
  • Reveal — expand a row (tab or click), then eye button 󰈈/󰈉 to show the password (auto-hides after 15s, configurable via revealTimeoutSec in BarWidget.qml).
  • Profiles — default profile is first and marked (default). Change profilesDir in BarWidget.qml if your profiles.ini lives elsewhere.

Decrypted data is never written to disk and is cleared on close (Esc → collapse → clear filter → close).

Configuration

Edit BarWidget.qml at the top:

property string profilesDir: ""      // "" = auto-detect
property int revealTimeoutSec: 15    // 0 = stay revealed
property int clipboardClearSec: 30   // 0 = never clear clipboard

Security notes

  • Secrets never touch argv or a shell: the Primary Password is piped to firefox_decrypt over stdin, and copied secrets are piped to wl-copy --sensitive over stdin (EOF-terminated, forked daemon).
  • Copied passwords carry the --sensitive clipboard hint and are wiped after clipboardClearSec (default 30s) — but only if the clipboard still holds exactly what the plugin copied, so your own later copies are never clobbered. Set 0 to disable. The ownership probe is bounded at the producer (wl-paste | head -c len+1 — the pipe is cut at exactly the secret's length, so an oversized owner SIGPIPEs and the shell sees at most len+1 bytes), time-limited (3s), and fails closed: timeout, overflow, or mismatch all skip the clear and drop every buffer.
  • Producer-side output cap: the vendored firefox_decrypt.py (see the omarchy-firefox-passwords patch markers) serializes the JSON payload in the short-lived python process and refuses (exit 40) to write anything to stdout beyond 20 MiB — the long-lived shell can never receive an unbounded stream. Consumer-side layers stay as backstops: 20 MiB stdout check, 5000-entry cap (newest kept), 30s decrypt deadline.
  • stderr is parsed as a stream (SplitParser), never accumulated: only the first diagnostic line is kept and a flood past 256 KiB kills the process.
  • Decrypted entries live in memory only, wiped on close.
  • Nothing is ever written to disk.

Vendored-script maintenance: when updating firefox_decrypt.py upstream, re-apply the marked patch (search for omarchy-firefox-passwords patch).

Development

./install.sh --no-restart   # symlink for live QML edits
make validate               # qmllint + omarchy plugin validate
omarchy-shell chupre.firefox-passwords toggle  # via bar, or click the icon
journalctl --user -f | grep firefox-passwords

How it works

  • Profiles are listed with firefox_decrypt.py -l <profilesDir>
  • The default is read from profiles.ini ([Install*] Default= or [Profile] Default=1)
  • Decryption runs as python3 firefox_decrypt.py -n -f json --non-fatal-decryption -c N <dir> with the Primary Password fed over stdin only (never argv/env)

License

GPL-3.0-or-later. firefox_decrypt.py is © its authors under the same license (see LICENSE). Other plugin code is © Denis.

firefox_decrypt is based on work from unode/firefox_decrypt.