Omahub
← All plugins
E

Syncthing

by explify

Syncthing status, folder sync progress, device connectivity, and quick actions in the Omarchy bar.

Security review

No obvious issues detected

Deterministic scan — not a security guarantee

None
Risk level
None
Analyzed commit
d92323f
Scanned
1 month ago

No potentially dangerous behavior detected in the analyzed commit.

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
d92323f
Reviewed
1 month ago

The plugin is a transparent Syncthing monitor/controller that reads local config, queries the local REST API, and performs user-initiated actions like toggling the service, rescanning folders, and opening the web UI. No obfuscation, hidden network calls, or credential exfiltration were found; all operations are local and expected for the widget's purpose.

  • Uses curl -k to disable TLS verification for the local Syncthing GUI, which is standard for self-signed certs but slightly lowers security.
  • Reads the Syncthing API key from config and sends it via stdin to curl, which is good practice, but the key is still accessible to the plugin process.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/Pillumz/omarchy-syncthing --enable
Widgets #bar #quickshell #system

Syncthing for Omarchy

Bar widget for the Omarchy 4.0 shell: Syncthing status at a glance, with a popup panel for folders, devices, and quick actions.

<img src="preview.png" alt="Panel preview" width="380">

What it does

  • Bar icon: the Syncthing mark, drawn natively. Dimmed + crossed when the service is stopped, spinning while syncing/scanning, ! badge on sync errors.
  • Panel (left-click the icon):
    • Hero with device name, overall status, and a start/stop toggle for syncthing.service (systemd user unit).
    • Folders with per-folder state, completion, rescan and pause/resume buttons. Click a folder to open it in the file manager.
    • Devices with connection state, address or last-seen time, and a copy-device-ID button.
    • Open Web UI shortcut.
  • Mouse on the bar icon: left = panel, right = open Web UI, middle = refresh.
  • Keyboard in the panel: arrows/jk navigate, Enter activates, t toggle service, o open Web UI, r rescan (selected folder, else all), p pause/resume selected folder.
  • IPC: omarchy-shell explify.syncthing <open|close|show|hide|toggle|refresh|toggleService|status>

How it works

syncthingctl (bash + curl + jq) reads the GUI address and API key from ~/.local/state/syncthing/config.xml (or ~/.config/syncthing/config.xml) and assembles one JSON blob from the Syncthing REST API. Service.qml polls it on refreshIntervalSec (default 10s, 3s while syncing) and exposes state to Panel.qml. No credentials are stored in the plugin.

Requirements

  • Omarchy 4.0+ (quickshell-based omarchy-shell)
  • syncthing running as the systemd user unit syncthing.service (systemctl --user enable --now syncthing)
  • bash, curl, jq (all present on a stock Omarchy install)

Install

omarchy plugin add https://github.com/Pillumz/omarchy-syncthing.git --enable

Or manually: copy the plugin directory to ~/.config/omarchy/plugins/explify.syncthing/, then:

omarchy-shell shell rescanPlugins
omarchy bar put explify.syncthing --section right

Remove

omarchy plugin remove explify.syncthing

License

MIT — see LICENSE.