Omahub
← All plugins
W

Windscribe

by Windscribe Limited

Windscribe controls for Omarchy in a terminal-grade panel: one-key connect, live traffic, exit search with favourites, Firewall, protocol and port selection, IP rotation, and allowance tracking.

Security review

Potentially dangerous behavior detected · 4 findings

Deterministic scan — not a security guarantee

High
Risk level
High
Analyzed commit
6a582e0
Scanned
1 month ago
  • high destructive_filesystem tests/model.test.js:160

    Destructive operation on the root filesystem or a block device.

    rm -rf /"), false)
  • Command runs with sudo, elevating the process beyond the plugin environment.

    sudo
  • Docs sudo README.md:15

    Command runs with sudo, elevating the process beyond the plugin environment.

    sudo in a floating terminal). Then sign in. Username and password go into Windscribe's own prompt, not into this plugin.
  • Docs sudo README.md:51

    Command runs with sudo, elevating the process beyond the plugin environment.

    sudo pacman -R windscribe-cli

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
6a582e0
Reviewed
1 month ago

The plugin is a well-engineered bar widget that controls the official Windscribe CLI. It downloads and installs the CLI only after verifying SHA-256 and a detached GPG signature against a pinned key, and it uses argv arrays and output limits to avoid injection and resource abuse. The deterministic scan's high-risk findings are false positives: the `rm -rf /` appears in a unit test asserting that unsafe input is rejected, and the sudo references are in documentation and the user-initiated installer.

  • The installer runs `sudo pacman` to install the Windscribe CLI, which is a privileged operation; however, it is user-triggered and the package is verified before installation.
  • The plugin downloads a binary package from Windscribe's CDN; trust relies on Windscribe's signing key and the pinned fingerprint, which is a reasonable security posture.
  • The README documents `sudo pacman -R windscribe-cli` for removal, which is expected and not a plugin action.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/yegors/windscribe-omarchy --enable
Productivity #bar #quickshell #security

Windscribe for Omarchy

A bar widget for Windscribe VPN on Omarchy. Click the badge, pick a city, connect, watch the traffic. Firewall, protocol selection, and IP rotation are in the panel too.

This is not the official desktop app. I installed Omarchy, wanted the VPN on the bar, and wired the plugin to the official Linux CLI so it talks to the same client you'd run in a terminal.

<img src="preview.png" width="840" alt="Windscribe for Omarchy: connection panel and settings">

Install

omarchy plugin add https://github.com/yegors/windscribe-omarchy.git --enable

Open the Windscribe badge on the bar. If the CLI isn't installed yet, the panel will offer to install it (that step asks for sudo in a floating terminal). Then sign in. Username and password go into Windscribe's own prompt, not into this plugin.

The installer uses curl, jq, GnuPG, and pacman, all included with a normal Omarchy installation.

From there: connect, search exits with /, star the ones you want at the top. Right click the badge to connect or disconnect without opening the panel. s opens settings.

Updating

omarchy plugin update com.windscribe.vpn
omarchy-restart-shell

That second command restarts the Omarchy shell. Plugin updates don't always reload in place, so if you pulled a new version and it still looks like the old one, you probably skipped the restart.

Remove

omarchy plugin remove com.windscribe.vpn

This removes the bar widget. It does not uninstall the Windscribe CLI. An active tunnel or Firewall also stays active after the widget is gone. If you want normal networking first, run these separately:

windscribe-cli status
windscribe-cli disconnect
windscribe-cli firewall off
omarchy plugin remove com.windscribe.vpn

To remove the CLI package too:

sudo pacman -R windscribe-cli

Keyboard

  • J / K or arrows: move
  • Enter: connect, or toggle the selected control
  • /: search exits
  • F: star or unstar a favourite
  • S or ← / →: settings and back
  • T: connect or disconnect
  • W: toggle Firewall
  • R: refresh
  • Esc: leave search, close a menu, go back, then close

Middle click the badge to refresh status and locations.

Protocol and port changes apply on the next connect. Sign-out asks for a second confirm, and if the Firewall is on it stays on.

Design

The panel is typographic: dashed and dotted leader lines, numbered exit rows, [ on ] bracket toggles, and one full-width connect button. Colors are derived from the active Omarchy theme's foreground and accent, so it follows your theme instead of shipping its own.

Decisions that shape it:

  • Windscribe's own terms, as-is: fastest location, Firewall, Favourites, preferred protocol.
  • Omarchy's panel, theme, and keyboard conventions win over brand styling.
  • Nothing is shown that can't be measured. No guessed origin, no per-exit latency (the CLI doesn't expose ping per city; the fastest-location row is Windscribe's own latency pick), no DNS safety claims, no synthetic privacy score.
  • Copy stays short, and consequences are stated where you act.
  • Packaging details stay out of the product UI.

Widget settings

Stored with the Omarchy bar entry:

  • refreshIntervalSec: closed-panel status interval, from 2 to 60 seconds
  • preferredProtocol: protocol with optional :port
  • notifications: connection alert toggle
  • motion: interface animation toggle
  • favoriteLocations: managed by the stars in the exit list
  • lastLocation: last connected city label, for the disconnected hero

Scripting

vpn=com.windscribe.vpn
omarchy-shell "$vpn" toggle
omarchy-shell "$vpn" toggleVpn
omarchy-shell "$vpn" best
omarchy-shell "$vpn" connectTo "The 6"
omarchy-shell "$vpn" disconnect
omarchy-shell "$vpn" firewall on
omarchy-shell "$vpn" rotate
omarchy-shell "$vpn" refresh
omarchy-shell "$vpn" status

Privacy and security

The plugin:

  • stores no credentials, tokens, or account identity
  • makes no location or telemetry requests of its own
  • passes normal commands as argument arrays rather than shell strings
  • asks the official Windscribe update API for the latest supported stable Arch CLI and only accepts its expected HTTPS CDN path
  • verifies both the API-provided SHA-256 and the package's detached signature against the Windscribe Linux signing key bundled with this plugin before asking for sudo
  • downloads that package into a private mktemp directory, not a shared /tmp path
  • caps subprocess stdout and stderr before the Omarchy shell collects it
  • validates user-entered locations before they reach the CLI
  • renders CLI output as plain, sanitized text
  • reads tunnel byte counters only while the panel is open
  • stores short-lived sign-in/update result markers under a 0700 directory at ~/.local/state/omarchy-windscribe/ (written with mktemp plus mv -T, read through bounded cat). Favourites and the last-city hero label persist in the Omarchy widget settings, not a plugin-private file.

Install, sign-in, and update use Omarchy's floating terminal because those commands may need interactive input.

Development

./scripts/validate.sh

The validator runs Omarchy plugin validation, shell syntax checks, qmllint, optional shellcheck, and the Node tests when Node is available.

Acknowledgements

The Windscribe badge is redrawn from the official Windscribe Desktop App asset and follows the active Omarchy theme.

License

MIT