Omahub
← All plugins
D

DeTrack

by Dorneles

URL tracker cleaner and instant QR Code sharing popup for Omarchy.

Security review

Review recommended · 1 finding

Deterministic scan — not a security guarantee

Low
Risk level
Low
Analyzed commit
bbd11a4
Scanned
1 month ago

Flagged patterns appear only in documentation files (README / docs) — descriptive examples, not executable code.

  • Docs external_hosts README.md:50

    Downloads or connects to an external HTTP(S) host.

    git clone https://github.com/jvlianodorneles/detrack.git

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
bbd11a4
Reviewed
1 month ago

The deterministic external-host finding is limited to the README's git clone installation example and is not part of the plugin's runtime. The executable code is readable and transparent: it cleans clipboard URLs, generates QR codes, and only writes to the clipboard or makes network requests when explicitly triggered or when the opt-in auto-clean setting is enabled. I found no obfuscation, hidden persistence, credential theft, or destructive install behavior.

  • The plugin reads Omarchy's clipboard history and can rewrite the clipboard via wl-copy; this is core documented behavior, and auto-clean is off by default.
  • The optional unshorten feature makes outbound HTTP(S) requests to user-provided short URLs; the included Python code attempts SSRF protection by rejecting private, loopback, and link-local IPs.
  • The install/uninstall scripts modify ~/.config/omarchy/shell.json and restart the shell, but this is expected plugin registration behavior and is limited to the user's own configuration.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/jvlianodorneles/detrack --enable
Productivity #bar

🛡️ DeTrack

URL Tracker Cleaner & Instant QR Code Sharer for Omarchy.

License: MIT Omarchy Quattro Platform

<p align="center"> <img src="preview.png" alt="DeTrack Preview" width="340"> </p>

DeTrack automatically intercepts URLs in your clipboard, strips all tracking parameters (such as utm_*, fbclid, gclid, matt_*, Google/Facebook redirect wrappers, etc.), and instantly renders a pixel-perfect, scannable QR Code with 1-click COPY and BROWSE actions.


✨ Features

  • 🧹 Pure JavaScript Sanitization Engine (Engine.js):
    • Global tracking parameters (utm_*, gclid, fbclid, _ga, mc_eid, mkt_tok, vgo_ee, hsa_*, etc.).
    • E-commerce & Shopping filters (matt_*, cq_*, gad_*, pdp_filters, from=gshop, Amazon canonical /dp/ASIN).
    • Social media trackers (YouTube si/feature, Twitter/X s/t, TikTok, Instagram, Spotify, Twitch, Steam, Substack).
    • YouTube Shorts normalization (/shorts/ID -> canonical /watch?v=ID).
    • Unwraps Google (google.com/url?q=), Facebook (l.facebook.com/l.php?u=), and Reddit redirects.
  • 🔍 Interactive Tracker Breakdown & Shortlink Resolution:
    • Click on the tracker badge to expand interactive tags showing each parameter stripped.
    • Detects shortener links (bit.ly, t.co, tinyurl) and offers 1-click on-demand unshortening.
  • 📱 Instant Native QR Code (QRCode.js):
    • Full 40-version Reed-Solomon support.
    • Native integer-module grid rendering for crisp, pixel-perfect camera scanning without blurry rasterization.
  • ⚡ Zero-Latency Clipboard Synchronization:
    • Synchronously syncs with Omarchy's clipboard state (~/.local/state/omarchy/clipboard-history.json) and wl-paste.
  • 🎨 Native Omarchy Theme Integration:
    • Uses PanelHero, PanelSeparator, PanelKeyCatcher, and Style.cornerRadius to adapt automatically to any Omarchy theme and Hyprland window rounding.
  • ⌨️ Keyboard Navigation:
    • C / Ctrl+C: Copy cleaned URL to clipboard.
    • B / Enter / Space: Open cleaned URL in default web browser.
    • Tab / Shift+Tab: Switch between bar panels.
    • Esc: Close popup.
  • 💻 Standalone CLI Tool (detrack):
    • Clean URLs directly in your terminal or scripts via detrack --clipboard --qr, with support for --unshorten and --preserve.

📦 Installation

Option 1: Automatic Script

Clone the repository and run the install script:

git clone https://github.com/jvlianodorneles/detrack.git
cd detrack
./install.sh

Option 2: Manual Installation

Copy the repository into your Omarchy plugins directory:

mkdir -p ~/.config/omarchy/plugins/dorneles.detrack
cp -r * ~/.config/omarchy/plugins/dorneles.detrack/
omarchy-restart-shell

⚙️ Configuration

DeTrack supports customizable settings in your Omarchy bar configuration (~/.config/omarchy/shell.json):

Setting Type Default Description
showTrackerBadge boolean false Displays the number of stripped trackers directly on the bar icon.
iconStyle enum "shield" Bar icon style ("shield": 󰒃, "link": 󰌹, "qrcode": 󰐳).
autoCleanClipboard boolean false Silently clean URLs copied anywhere on your system in background.
preserveParams string[] [] Whitelist of query parameters to never strip (e.g. ["ref", "tag"]).

🧪 Testing

Run the automated test suite covering 29 unit tests:

node tests/test_engine.js

📄 License

This project is licensed under the MIT License.