Omahub
← All plugins
D

Orbital Lock

by Dumidu

A theme-aware orbital lock screen that preserves Omarchy's native PAM and fingerprint authentication.

Security review

No obvious issues detected

Deterministic scan — not a security guarantee

None
Risk level
None
Analyzed commit
6639304
Scanned
1 month ago

No potentially dangerous behavior detected in the analyzed commit.

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

None
AI risk level
None
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
6639304
Reviewed
1 month ago

Sampled code is a presentation-layer lock screen that delegates authentication to Omarchy's native PAM/Wayland session-lock and gates power actions behind two-click user confirmation while the session is secure. No obfuscation, credential exfiltration, persistence mechanisms, or destructive install-time commands were found. This matches the deterministic scan's 'none' rating.

How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/dumidulkdev/omarchy-orbital-lock --enable
System #quickshell

Orbital Lock

Orbital Lock screenshot

A theme-aware Omarchy 4 lock screen with smoothly rotating minute and second rings, an hour readout inside the orbit, and a centered date. It keeps Omarchy's native PAM, fingerprint, idle, and Wayland session-lock implementation and replaces only the presentation layer.

When an enrolled fingerprint reader is available, the password pill shows a fingerprint icon with a scanning halo driven by the live fingerprint PAM state.

The composition is visually inspired by qylock's GPL-3.0 Clockwork/Orbital skin by Darkkal44. Orbital Lock is an original QML implementation and includes none of qylock's code, fonts, or assets.

Install

omarchy plugin add https://github.com/dumidulkdev/omarchy-orbital-lock.git --enable

Enabling this plugin disables omarchy.lock. Disabling or removing it restores the stock lock screen automatically:

omarchy plugin disable dumidu.orbital-lock
omarchy plugin remove dumidu.orbital-lock

Preview

Preview while the desktop is unlocked:

omarchy-shell lock preview

Click anywhere to close the preview. The preview simulates the fingerprint scan animation, but authentication, password submission, and power actions remain disabled. Do not edit or update lock-plugin QML while the session is actually locked.

Settings

Settings live inline with the plugin entry in ~/.config/omarchy/shell.json:

{
  "id": "dumidu.orbital-lock",
  "backgroundMode": "wallpaper",
  "dimOpacity": 0.48,
  "screenBlankSeconds": 300,
  "hourFormat": "24",
  "showSecondsRing": true,
  "showPowerActions": true,
  "identityLabel": ""
}
  • backgroundMode: wallpaper or solid
  • dimOpacity: 0 through 0.85
  • screenBlankSeconds: seconds after locking before displays power off; 5 through 3600 (default: 300)
  • hourFormat: 24 or 12
  • showSecondsRing: show the outer seconds ring
  • showPowerActions: show reboot and shutdown actions
  • identityLabel: custom lower-right label; empty uses the current username

Reboot and shutdown require two clicks within five seconds and are available only after Wayland confirms that the session is securely covered.

Development

scripts/test.sh
omarchy-shell lock preview

The upstream lock service is security-sensitive. scripts/check-upstream.sh alerts maintainers when the installed Omarchy service no longer matches the reviewed baseline documented in UPSTREAM.md.

License

MIT. Omarchy portions retain their upstream MIT terms. See LICENSE and UPSTREAM.md.