Omahub
← All plugins
P

Surfshark VPN

by Pierre (Djkawada)

Fast, native, zero-bloat WireGuard VPN manager for Surfshark on Omarchy Linux.

Security review

Potentially dangerous behavior detected · 4 findings

Deterministic scan — not a security guarantee

High
Risk level
High
Analyzed commit
39699d0
Scanned
1 month ago
  • high persistence BarWidget.qml:182

    Registers scheduled or boot-time system tasks.

    systemd-run", "--user", "--pipe", root.shPath, "connect", profileId]
  • high persistence BarWidget.qml:192

    Registers scheduled or boot-time system tasks.

    systemd-run", "--user", "--pipe", root.shPath, "disconnect"]
  • Docs persistence README.md:102

    Registers scheduled or boot-time system tasks.

    systemd-run --user --pipe
  • Docs external_hosts README.md:48

    Downloads or connects to an external HTTP(S) host.

    git clone https://github.com/djkawada/omarchy-surfshark-plugin.git ~/.config/omarchy/plugins/com.github.djkawada.surfshark-vpn

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
39699d0
Reviewed
1 month ago

The plugin is a legitimate WireGuard VPN manager that uses systemd-run to execute its own shell script for connect/disconnect actions, which is a normal one-shot execution rather than persistence. The deterministic scan flagged systemd-run as persistence, but it does not install scheduled tasks or boot-time services. The Rust source is clean, keys are stored with 0600 permissions, and no malicious behavior was found.

  • The deterministic scan flagged systemd-run usage as persistence, but it is only used to run the plugin's own script on demand, not to schedule tasks.
  • The plugin requires nmcli and systemd-run, and modifies NetworkManager connections, which is expected for a VPN manager.
  • The README contains a git clone command for installation, but that is documentation only.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/Djkawada/omarchy-surfshark-vpn --enable
Widgets #bar #quickshell #security

🦈 Surfshark VPN for Omarchy Linux

Omarchy Plugin Rust Protocol License

An ultra-lightweight, zero-bloat, native WireGuard VPN manager and status monitor for Surfshark users on Omarchy Linux (Hyprland / Quickshell).


📸 Screenshots

<div align="center"> <h3>Status Bar Widget & Quick Connect Panel</h3> <img src="assets/screenshot-bar-widget.png" alt="Surfshark Bar Widget and Quick Connect" width="480" style="border-radius: 8px;" /> <br/><br/> <h3>Surfshark Manager (Settings, WireGuard Key Injection & Diagnostics)</h3> <img src="assets/screenshot-control-center.png" alt="Surfshark Manager Control Center" width="900" style="border-radius: 8px;" /> </div>

🎯 Why This Plugin?

The official Surfshark Electron client is resource-heavy (~300 MB RAM), prone to tray icon bugs on Wayland, and introduces unnecessary background daemon overhead.

Surfshark VPN for Omarchy delivers:

  • ⚡ Instant Connection (< 150ms): Powered by standard Linux kernel WireGuard integration (NetworkManager / nmcli).
  • 🦀 Native Rust Engine (surfshark-ctl): High-performance, zero memory footprint, multithreaded non-blocking status queries.
  • 🌐 Dual-Stack Public IP Monitor: Real-time display of both your public IPv4 and IPv6 addresses.
  • 🔑 In-App WireGuard Key Manager: Enter your Surfshark WireGuard Public & Private keys directly in the GUI — they are securely saved (0600) and automatically applied to all .conf profiles!
  • ⭐ Favorite Servers & Location Switcher: Star your favorite countries (France 🇫🇷, Japan 🇯🇵, USA 🇺🇸, Germany 🇩🇪, etc.) for instant one-click switching.
  • 🌍 Tri-Lingual Localization: Instant real-time UI switching between Français 🇫🇷, English 🇬🇧, and 日本語 🇯🇵.
  • 🛡️ Clean Connection Lifecycle: Automatic teardown of stale routes, zero zombie interfaces, and conflict-free NetworkManager profile management.

🚀 Installation

Option 1: Via Omarchy Plugin Manager (Recommended)

omarchy plugin add https://github.com/djkawada/omarchy-surfshark-plugin.git

Option 2: Manual Git Clone

git clone https://github.com/djkawada/omarchy-surfshark-plugin.git ~/.config/omarchy/plugins/com.github.djkawada.surfshark-vpn

Enable in Your Status Bar

In ~/.config/omarchy/shell.json, add "com.github.djkawada.surfshark-vpn" to your bar.layout.right section:

{
  "bar": {
    "layout": {
      "right": [
        "com.github.djkawada.surfshark-vpn",
        "omarchy.network",
        "omarchy.battery",
        "omarchy.clock"
      ]
    }
  }
}

Then restart the shell:

omarchy restart shell

⚙️ Easy 4-Step Setup Guide

  1. Open Surfshark WireGuard Portal: Log in to your account at my.surfshark.com > VPN > Manual setup > WireGuard.
  2. Generate or Retrieve Your Key Pair: Click “I already have a key pair” or generate a new key pair.
  3. Save Keys in Surfshark Manager: Open Surfshark Manager ↗ from the bar widget, paste your Public Key and Private Key, then click 💾 Enregistrer les Clés & Appliquer.
  4. Download Location Profiles: Download the .conf files for your preferred server locations (e.g. fr-par.conf, jp-tok.conf, us-nyc.conf) and drop them into:
    ~/.config/surfshark-vpn/configs/
    
    (Or click 📁 Ouvrir Dossier Configs directly in the manager).

🏗️ Architecture & Tech Stack

┌─────────────────────────────────────────────────────────────┐
│                       OMARCHY SHELL                         │
│   BarWidget.qml                SurfsharkControlCenter.qml   │
│   (Status Bar Slot & Popup)    (Settings & Key Injection)   │
└──────────────────────────────┬──────────────────────────────┘
                               │
               systemd-run --user --pipe
                               │
┌──────────────────────────────▼──────────────────────────────┐
│                    surfshark-vpn.sh / Rust                  │
│       Native NetworkManager / WireGuard Execution Scope     │
└──────────────────────────────┬──────────────────────────────┘
                               │
┌──────────────────────────────▼──────────────────────────────┐
│                    LINUX KERNEL WIREGUARD                   │
│   Ultra-fast UDP Crypto Tunnel (ChaCha20 / Poly1305)       │
└─────────────────────────────────────────────────────────────┘
  • UI Layer: Quickshell / Qt 6 QML (qs.Ui, qs.Commons).
  • Core Controller: Native compiled Rust binary (surfshark-ctl) with standalone POSIX bash wrapper (surfshark-vpn.sh).
  • Network Engine: Linux Kernel WireGuard via nmcli.

🔄 Updates & Removal

Update

omarchy plugin update com.github.djkawada.surfshark-vpn
# Or if installed via git:
cd ~/.config/omarchy/plugins/com.github.djkawada.surfshark-vpn && git pull && omarchy restart shell

Remove / Uninstall

omarchy plugin remove com.github.djkawada.surfshark-vpn
# Or manual:
rm -rf ~/.config/omarchy/plugins/com.github.djkawada.surfshark-vpn
omarchy restart shell

📄 License

Distributed under the MIT License. Created by Pierre (Djkawada).