Omahub
← All plugins
J

UniFi

by Jonny Heggheim

Watch your UniFi network from the Omarchy bar: access points, switches and gateways with their online state, the gateway's WAN graph and links, overall client counts, and a notification when a device drops.

Security review

No obvious issues detected

Deterministic scan — not a security guarantee

None
Risk level
None
Analyzed commit
d5e04c6
Scanned
1 month ago

No potentially dangerous behavior detected in the analyzed commit.

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

None
AI risk level
None
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
d5e04c6
Reviewed
1 month ago

The plugin is a legitimate UniFi network monitoring widget. It fetches read-only data from a UniFi controller using an API key stored in the system keyring, and performs no dangerous operations. The code is well-structured, includes security considerations (e.g., sanitizing controller data, avoiding shell injection), and the deterministic scan found no issues.

How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/hegjon/omarchy-unifi --enable
Hardware #bar

UniFi for Omarchy

Watch your UniFi network from the Omarchy bar: every access point, switch and gateway on a site with its online state, model, address and how many clients hang off it, plus wired/wireless client totals. The bar icon carries a badge with the number of offline devices, and a notification fires when a device drops or comes back. Under the gateway it shows what is flowing through the WAN — download and upload right now, each with a graph of the last twelve hours — plus CPU, memory, load and uptime, and the WAN: public address and upstream gateway, ISP, and each WAN link's latency, uptime and 24-hour availability, so a failed-over or dead backup link is visible. It is read-only.

The panel listing a gateway with its WAN rates, two 12-hour graphs, health line and WAN links,
then two access points and two switches with their state, address and client
counts; one access point offline and one switch unreachable

It talks to the UniFi Network application's official Integration API (Network 9.0 or newer) with an API key, so it works with UniFi OS consoles (UDM, UCG, Cloud Key Gen2+) and self-hosted controllers alike, on your LAN or over a VPN.

Install

omarchy plugin add https://github.com/hegjon/omarchy-unifi.git --enable
omarchy restart shell

If the widget is enabled but not visible, place it explicitly:

omarchy plugin enable hegjon.unifi --section right
omarchy restart shell

Update or remove:

omarchy plugin update hegjon.unifi --yes
omarchy plugin remove hegjon.unifi

Requires curl, jq and secret-tool (package libsecret), all present on a stock Omarchy system.

Setup

  1. In the UniFi Network application go to Settings → Control Plane → Integrations and create an API key.
  2. Click the widget and press Set up, or run ~/.config/omarchy/plugins/hegjon.unifi/unifi-login in a terminal.
  3. Enter the controller address (your default gateway is offered, which on a UniFi network is usually the console), say whether to accept its self-signed certificate (the default is to allow it), and paste the key. If the controller has more than one site you then pick one from a list.

The address and site are kept in ~/.local/state/omarchy/unifi/config; the key goes into the keyring under the plugin id and is never written anywhere else or passed on a command line. unifi-login --status shows what is configured, unifi-login --forget removes it all.

The controller URL is normally the console root: the plugin appends /proxy/network/integration/v1. If your deployment serves the API somewhere else, give the full URL ending in /integration/v1 and it is used as given.

The API this plugin uses is documented by the controller itself at https://<console>/unifi-api/network. The one exception is the twelve-hour traffic graph: the documented API only reports the current rates, so the graph reads the five-minute WAN buckets from the classic report endpoint (…/api/s/<site>/stat/report/5minutes.gw) that the UniFi UI's own charts use, and the WAN lines read the classic stat/health (link names come from the documented /wans). Both are undocumented; if they stop answering, the graph falls back to the samples the widget collects itself while the shell runs, and the WAN lines simply disappear.

Settings

Under the widget's settings in the bar:

  • Show the connected client count on the bar icon
  • Show the gateway's WAN graph, CPU, memory and uptime
  • Refresh interval while the panel is open, and the background poll interval
  • Notify when a device goes offline / comes back online, with a per-device cooldown

Middle-click the icon, or press R in the panel, to refresh. IPC: omarchy-shell hegjon.unifi open|close|toggle|refresh.

Development

test/test-manifest, test/test-normalize (fixtures under test/fixtures/) and test/lint (qmllint; needs an Omarchy machine). See CLAUDE.md.

License

MIT. Not affiliated with, endorsed by, or supported by Ubiquiti Inc.; UniFi is their trade mark.