Omahub
← All plugins
A

Windscribe

by ariadev

Windscribe VPN state in the Omarchy bar: connection status at a glance, plus a panel to connect, disconnect, toggle the firewall, and pick from every available location.

Security review

Review recommended · 1 finding

Deterministic scan — not a security guarantee

Medium
Risk level
Medium
Analyzed commit
f07e79a
Scanned
1 month ago
  • medium external_hosts Main.qml:372

    Downloads or connects to an external HTTP(S) host.

    curl -sf --max-time 5 https://api.ipify.org"]

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
f07e79a
Reviewed
1 month ago

The plugin is a straightforward Windscribe CLI wrapper: it polls windscribe-cli, reads tunnel interface counters from /sys/class/net, and only makes an external network request to api.ipify.org when the opt-in showPublicIp setting is enabled. The deterministic finding is valid but low-impact: the lookup is documented, off by default, and sends only the egress IP to a well-known service. No credential handling, install-time commands, obfuscation, or destructive behavior was found in the sampled code.

  • When the user enables showPublicIp, the widget sends the machine's public IP to api.ipify.org; this is the intended feature but is a third-party disclosure.
  • The widget executes commands via bash and windscribe-cli, so any future compromise of the Windscribe CLI or a maliciously crafted setting value could expand impact, but nothing in this version indicates such an issue.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/ariadev/dev.windscribe --enable
System #bar #quickshell #security

dev.windscribe — Windscribe bar widget for Omarchy

A native Omarchy shell bar widget for Windscribe: connection state at a glance in the bar, and a panel to connect, disconnect, guard the firewall, and pick from every location the CLI knows about.

The dev.windscribe bar widget and its panel: connection detail, firewall toggle, and the location list

Features

  • State in the bar — one icon, tinted by connection state, with the connected city beside it. It breathes slowly while a connect or disconnect is in flight, and carries a dot when something needs you (a failed action, or a session that is signed out).
  • The connection, in full — city and server nickname, protocol, uptime, tunnel IP, live throughput, and data used against your plan's allowance.
  • Controls — connect, disconnect, jump to the fastest location, and a firewall toggle.
  • Every location, searchable — favourites and static IPs first, then all regions. Type to filter across region, city and nickname; the connected location is checked; unavailable ones are greyed out and inert.
  • Keyboard driven throughout (see below).

Requirements

  • windscribe-cli on PATH, signed in (windscribe-cli login).
  • bash, ip and awk — used to read the tunnel interface's byte counters.

Nothing is compiled or installed. The widget never asks for or handles your credentials; signing in stays a terminal job.

Install

omarchy plugin add https://github.com/ariadev/dev.windscribe --enable --yes
omarchy bar put dev.windscribe --after omarchy.network

Or, for a copy already sitting in ~/.config/omarchy/plugins/dev.windscribe/:

omarchy-shell shell rescanPlugins
omarchy plugin enable dev.windscribe
omarchy bar put dev.windscribe --after omarchy.network

Settings

Set from the Omarchy setup UI, or with omarchy bar set dev.windscribe <key> <value>.

Key Default What it does
pollIntervalSec 10 Status poll interval while idle. Transitions always poll every 2s.
showLabel true Draw the connected city next to the icon.
hideWhenDisconnected false Collapse the bar slot unless connected, connecting, or in trouble.
showPublicIp false Look up the egress IP once per connection change.
protocol "" protocol[:port] passed to every connect, e.g. tcp:80.

Leave protocol empty and the CLI picks its own default, WireGuard:443. Some networks drop that quietly: the connect never fails, it just sits at "Connecting" forever. If windscribe-cli connect <place> tcp:80 works in a terminal where the widget stalls, pin the same protocol here:

omarchy bar set dev.windscribe protocol tcp:80

showPublicIp is off by default because it is the only thing this widget does that leaves your machine: it fetches your address from api.ipify.org. Every other reading comes from windscribe-cli and /sys/class/net.

Mouse

Action Effect
Left click Open the panel
Right click Connect / disconnect
Middle click Refresh status and locations

Keyboard

Key Action
j / k Move down / up the location list
Enter Connect to the selected location
/ Focus the search box
Escape Clear the search, then leave it
g / G First / last location
c Connect to the last used location
b Connect to the best location
d Disconnect
f Toggle the firewall
r Refresh now
Tab Switch to the neighbouring panel

IPC

omarchy-shell dev.windscribe status      # "Connected — Copenhagen - LEGO"
omarchy-shell dev.windscribe toggle      # open/close the panel
omarchy-shell dev.windscribe connect     # last used location
omarchy-shell dev.windscribe disconnect
omarchy-shell dev.windscribe refresh

Notes on the CLI

Two behaviours of windscribe-cli shape how this widget is written, and are worth knowing if you hack on it:

  • It always exits 0 — even for an unknown subcommand. Exit codes carry no information, so success is judged by re-reading status, and failures are recognised from the text it printed.
  • It is single-instance. A second invocation prints Windscribe CLI is already running instead of doing its job, and the lock outlives the process by a moment. Every call this widget makes goes through one gate with a short gap between calls, and a collision retries rather than being reported as a VPN problem.

Uptime is tracked client-side, because the CLI does not report it — so it is only shown for a connection this widget watched come up.

License

MIT