Omahub
← All plugins
D

omaportless

by dingyi

Give every local dev server a named .localhost address you can rename from the Omarchy bar.

Security review

No obvious issues detected

Deterministic scan — not a security guarantee

None
Risk level
None
Analyzed commit
385ba71
Scanned
4 days ago

No potentially dangerous behavior detected in the analyzed commit.

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
385ba71
Reviewed
3 days ago

The plugin is a transparent local reverse proxy for dev servers. It scans /proc for listeners, proxies *.localhost to those services, and can optionally install a loopback-only nftables redirect via a polkit prompt. All system-level changes are documented and user-initiated; no malicious or hidden behavior was found in the sampled code.

  • The plugin creates persistent user systemd services and, when port 80 is occupied, attempts to install a root nftables redirect and systemd unit with a pkexec prompt, which is a significant but well-documented system change.
  • The proxy can expose any local listening port to *.localhost; while loopback-only, a user might unintentionally make a sensitive local service accessible to other local processes or browsers.
  • There are odd literal strings like "https://example.net/id/garnet" in match arms that appear to be typos or leftover placeholders, but they have no harmful effect.
  • The plugin can terminate user processes via the UI (SIGTERM/SIGKILL), which could be destructive if clicked accidentally, though this requires explicit user action.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/dingyi/omaportless --enable
Developer Tools #bar

omaportless

Give every local dev server a named .localhost address, and rename it from the Omarchy bar.

omaportless panel

This plugin does not wrap npm run dev. It scans listeners that are already running, then reverse-proxies http://name.localhost to that port.

On systemd-resolved (and most browsers), *.localhost already maps to loopback, so no /etc/hosts edit is required.

Install

Needs Rust once, to compile the proxy (omarchy pkg add rust if cargo is missing).

omarchy plugin add https://github.com/dingyi/omaportless.git --enable
~/.config/omarchy/plugins/dingyi.omaportless/setup

setup builds the binary and starts a user systemd service. The panel switch can also run install after that.

Usage

  • Left click opens the panel
  • Right click starts or stops the proxy
  • Middle click opens http://localhost (the index of named apps)
  • Edit a row's name and press Enter to pin name.localhost
  • Click .localhost, the port, or the project path to open it; right click copies the URL

Keys in the panel: t proxy, o index, r refresh.

If something else already owns port 80, omaportless listens on 7777 and, with one polkit prompt, installs a loopback-only nftables redirect so http://name.localhost still works with no port. Unknown hosts that are not *.localhost are passed through to 127.0.0.2:80. A missing name.localhost app gets omaportless's own 404, not the other server's.

~/.config/omarchy/plugins/dingyi.omaportless/omaportless enable-port80

Names are stored in ~/.config/omaportless/config.json, keyed by project directory when /proc/<pid>/cwd is readable.

Remove

~/.config/omarchy/plugins/dingyi.omaportless/omaportless uninstall
omarchy plugin disable dingyi.omaportless