Omahub
← All plugins
C

Domain Check

by cossssmin

Check domain name availability from the bar or a summonable overlay, via RDAP.

Security review

No obvious issues detected

Deterministic scan — not a security guarantee

None
Risk level
None
Analyzed commit
d27c8cd
Scanned
1 month ago

No potentially dangerous behavior detected in the analyzed commit.

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
d27c8cd
Reviewed
1 month ago

The plugin is a straightforward domain-availability checker that sends user-typed names to RDAP/whois registries and Cloudflare's DNS-over-HTTPS resolver, and opens results via xdg-open — all disclosed in the README and consistent with its stated purpose. No install-time shell code, hidden persistence, credential handling, or destructive behavior was found. The deterministic scan also found no issues.

  • User-typed domain names are transmitted to third-party endpoints (IANA bootstrap, registry RDAP/whois servers, Cloudflare DNS-over-HTTPS); this is intentional and documented, but is a privacy consideration.
  • A portion of Checker.qml (whois fallback and openRow logic) was truncated in the reviewed sample; the full-commit deterministic scan found no findings, so this is noted for transparency rather than as evidence of a problem.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/cossssmin/omarchy-domaincheck --enable
Widgets #bar #system

Domain Check

Omarchy plugin for checking domain name availability — as a bar widget, a summonable fullscreen overlay, or both.

Domain Check panel

Demo

https://github.com/user-attachments/assets/bfbe187f-4af3-4d64-94e2-2c0f366da8ed

Features

  • Type a name, see instantly which TLDs are free — all checked in parallel
  • Type a full domain like name.io to check just that one
  • Authoritative answers via RDAP, the registries' own data — no API keys
  • Parallel DNS-over-HTTPS lookup flips registered domains to taken near-instantly, before the registry even responds
  • TLDs with no RDAP service (many country TLDs) fall back to a classic whois lookup
  • Your country's TLD is included automatically, derived offline from the system timezone
  • Click a taken domain to visit it; click an available one to go buy it
  • Full keyboard support

Results

Status Meaning
available The registry has no record for it (premium/reserved names can still show as available)
taken Registered
unknown The lookup failed, or the registry's answer couldn't be interpreted

Buying an available domain opens Cloudflare Registrar when it sells that TLD; for the rest (mostly country TLDs) it opens that TLD's price-comparison page on TLD-List, so you can pick the cheapest registrar. Both can be replaced, see below.

Keyboard

Key Action
↑ / ↓ Navigate the results
Enter Open the selected result (or re-run the check when nothing is selected)
Esc Close the panel

Install

omarchy plugin add https://github.com/cossssmin/omarchy-domaincheck.git --enable

The widget appears in the bar's right section. Move it with:

omarchy bar move cossssmin.domaincheck --section center

Overlay mode

The same checker is also a fullscreen overlay you can summon from anywhere, like the emoji picker or clipboard manager. Esc or a click outside dismisses it; opening a result also dismisses it. Bar widget and overlay work independently: keep both, or remove the widget from the bar and use only the overlay.

Domain Check overlay

The overlay has no trigger of its own — Omarchy plugins can't register keybindings. It opens through a shell command, which you can try straight from a terminal:

omarchy-shell -q shell toggle cossssmin.domaincheck

To summon it with a key, bind that command in ~/.config/hypr/bindings.lua (SUPER + D is unbound on a stock Omarchy install):

o.bind("SUPER + D", "Domain Check", "omarchy-shell -q shell toggle cossssmin.domaincheck")

Configure

Both options are editable in the bar's widget settings UI, or directly in the widget's entry in ~/.config/omarchy/shell.json. The overlay reads the same settings.

TLD list — defaults to com net org dev app sh ai plus your country's TLD. Override it entirely, as a space/comma-separated string or an array:

{ "id": "cossssmin.domaincheck", "tlds": "com io sh ro" }

Registrar — send available domains to your preferred registrar instead, with a {domain} placeholder:

{ "id": "cossssmin.domaincheck", "buyUrl": "https://www.namecheap.com/domains/registration/results/?domain={domain}" }

Privacy

  • RDAP lookups go directly to the relevant registry's RDAP server (endpoint list fetched once from IANA at startup, with rdap.org as fallback)
  • DNS lookups use Cloudflare's DNS-over-HTTPS resolver
  • TLDs without RDAP are checked with whois, which contacts that registry's whois server
  • The country TLD comes from your timezone via local tzdata files — no geolocation
  • Nothing else is contacted, nothing is stored. Opening a result uses xdg-open

Remove

omarchy plugin remove cossssmin.domaincheck

License

MIT