Omahub
← All plugins
A

Mullvad

by achevalier-dev

Mullvad VPN state in the Omarchy bar, wired to the Mullvad menu.

Security review

No obvious issues detected

Deterministic scan — not a security guarantee

None
Risk level
None
Analyzed commit
a73db76
Scanned
1 month ago

No potentially dangerous behavior detected in the analyzed commit.

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
a73db76
Reviewed
1 month ago

This is a legitimate Mullvad VPN widget for Omarchy. It interacts with the Mullvad CLI and modifies user configuration with backups, but contains no malicious code or suspicious behavior. The deterministic scan found no issues, and manual review confirms the scripts are straightforward and safe.

  • The install script modifies the user's Omarchy menu configuration, but it creates a backup before editing and is re-runnable without duplication.
  • The shell scripts execute Mullvad CLI commands with user privileges, but only perform expected VPN actions.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/achevalier-dev/omarchy-mullvad --enable
System #bar #quickshell #security

omarchy-mullvad

Mullvad VPN for Omarchy: a bar widget with a popup panel, a full set of menu entries, and the CLI helper both are built on.

the bar widget and its panel

What you get

In the bar — the tunnel state at a glance. Bright icon while the tunnel is up, dimmed while it is down, accent colour while Mullvad is blocking traffic, and the exit country beside it (󱇱 FR).

  • Left click opens the panel
  • Right click connects or disconnects
  • Middle click sends the status as a notification

In the panel — the state, the exit relay, and every control: connect, reconnect, change location, and a live switch for lockdown mode, auto-connect, local network sharing, multihop, DAITA, and quantum resistance. An account section shows the device name and paid-through date, lists the devices on the account, and logs out. With no account logged in, the panel collapses to a single Log in… row. Keyboard: j/k or arrows to move, enter to activate, t connect, r reconnect, l location, s notify, esc to close.

In the Omarchy menu — the same actions, searchable. Super+Space then type vpn, or jump straight there:

omarchy menu summon mullvad
omarchy menu summon mullvad.location

Location drills down Country → City → Server, built from a live mullvad relay list.

Install

The bar widget, as an Omarchy shell plugin:

omarchy plugin add https://github.com/achevalier-dev/omarchy-mullvad.git --enable

Then the menu rows and the CLI helper:

~/.config/omarchy/plugins/io.github.achevalier-dev.mullvad/install.sh

install.sh symlinks bin/mullvad-menu into ~/.local/bin and merges the menu rows into ~/.config/omarchy/extensions/omarchy-menu.jsonc, backing the file up first. It is safe to re-run — the block is replaced, never duplicated.

Menu rows and CLI without the bar widget: clone anywhere and run ./install.sh.

Requirements

  • Omarchy 4.x
  • mullvad CLI with mullvad-daemon running (mullvad-vpn-daemon-bin)
  • jq

How it works

State comes from a single long-lived mullvad status -j listen, which emits one JSON line per change — the widget never polls.

Every action goes through bin/mullvad-menu, which waits for the daemon to agree before it reports. mullvad connect returns while the tunnel is still being built and mullvad tunnel set … returns before the value is stored, so the helper waits for the transition to start, then to finish, and reads settings back until they match. A switch only moves once the change actually took.

mullvad-menu is usable on its own:

mullvad-menu toggle          # connect or disconnect
mullvad-menu country         # pick a country from a menu
mullvad-menu toggle-lockdown # flip a setting, confirmed with the daemon
mullvad-menu login           # account number typed into a terminal
mullvad-menu account         # device and expiry as a notification

Signing in

Log in… opens a terminal running mullvad account login, which prompts for the number on stdin — so your account number never appears in a command line, the process list, or shell history. Logging out asks for confirmation first, because it revokes the device. Nothing here ever puts the account number in a notification or a log.

Uninstall

omarchy plugin remove io.github.achevalier-dev.mullvad
rm ~/.local/bin/mullvad-menu

Then delete the // >>> omarchy-mullvad … // <<< omarchy-mullvad block from ~/.config/omarchy/extensions/omarchy-menu.jsonc.

Note on plugins

Omarchy plugins run as unsandboxed code inside the long-lived omarchy-shell process. Read MullvadPanel.qml and bin/mullvad-menu before enabling — they are short on purpose.

License

MIT