Omahub
← All plugins
D

Mozilla VPN

by David Estes

Toggle Mozilla VPN and pick a city target from the Omarchy bar.

Security review

Review recommended · 3 findings

Deterministic scan — not a security guarantee

Medium
Risk level
Medium
Analyzed commit
2f2d48e
Scanned
1 month ago
  • medium external_hosts Service.qml:214

    Downloads or connects to an external HTTP(S) host.

    curl", "-fsS", "--max-time", "8", "https://ipinfo.io/json"]
  • Docs external_hosts README.md:16

    Downloads or connects to an external HTTP(S) host.

    curl https://ipinfo.io/json` while the VPN is disconnected. Privacy
  • Docs external_hosts PUBLISH.md:35

    Downloads or connects to an external HTTP(S) host.

    curl https://ipinfo.io/json` to pick a nearest default city — no sudo/root. Includes preview.png of the bar panel.

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
2f2d48e
Reviewed
1 month ago

The plugin is a bar widget that controls Mozilla VPN via its CLI and uses a single curl to ipinfo.io for geolocation to pick a default city, which is documented in the README. The Python helper edits the VPN config file atomically and safely. No obfuscation, destructive commands, or hidden persistence were found.

  • The plugin sends the user's public IP to ipinfo.io once when no city is saved, which is a privacy disclosure but is clearly documented and only used for selecting a nearest server.
  • The plugin modifies ~/.config/mozilla/vpn.moz via a Python script, but this is the same file the Mozilla VPN app uses and the change is limited to DNS privacy flags.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/davydotcom/omarchy-mozilla-vpn-plugin --enable
Widgets #bar #quickshell #security

Mozilla VPN

Bar widget for Omarchy Quattro that toggles Mozilla VPN and selects a city target through the mozillavpn CLI.

Requirements

  • Mozilla VPN installed with mozillavpn on PATH
  • An authenticated Mozilla account (mozillavpn status should show User status: authenticated)
  • Omarchy Quattro / omarchy-shell

This plugin shells out to mozillavpn (status, servers, select, activate, deactivate, ui) and, only when choosing a first-time default city, to curl https://ipinfo.io/json while the VPN is disconnected. Privacy toggles update dnsProviderFlags in ~/.config/mozilla/vpn.moz (the same settings the Mozilla VPN app uses). It does not require root or sudo.

Install

omarchy plugin add https://github.com/davydotcom/omarchy-mozilla-vpn-plugin.git --enable

To place it on the bar explicitly:

omarchy plugin enable io.github.davydotcom.mozilla-vpn --section right --after omarchy.network

Usage

  • Left click: open the panel
  • Right click: toggle VPN on/off
  • Middle click: refresh status
  • Panel switch: toggle VPN
  • Privacy: block ads, trackers, and malware (Mozilla DNS filters). If the VPN is connected, it reconnects so the change applies
  • City list: select a city and connect (remembers recent cities)
  • First run with no saved city: while disconnected, picks the nearest Mozilla VPN city from your public IP location
  • Keyboard: t toggles, / focuses search, arrows move, Enter activates, Escape closes

Trust mozillavpn status / the moz0 interface if the Mozilla GUI looks stale after a CLI connect.

Remove

omarchy plugin remove io.github.davydotcom.mozilla-vpn

License

MIT. See LICENSE.