Omahub
← All plugins
P

Network Scanner

by Paolo Pellicori

See who is on your network: one click sweeps the local subnet and lists every device with IP, latency, mDNS name, MAC and vendor — compact or extended, straight from the bar. Scans only when you ask, nothing leaves your LAN, no root needed.

Security review

Potentially dangerous behavior detected · 1 finding

Deterministic scan — not a security guarantee

High
Risk level
High
Analyzed commit
844a381
Scanned
1 month ago
  • high persistence bin/netscan-ctl:120

    Registers scheduled or boot-time system tasks.

    systemctl enable --now avahi-daemon.service; fi

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
844a381
Reviewed
1 month ago

The plugin is a well-written, transparent network scanner that runs unprivileged and only scans on explicit user action. The flagged `systemctl enable --now avahi-daemon.service` is a legitimate, user-consented action to enable mDNS name resolution (a core feature), executed only when the user clicks the setup/fix button and authorizes via polkit — not malicious persistence. The code shows strong security hygiene: input validation, output caps, no shell injection, and no hidden behavior.

  • The `fix-deps` command runs `pacman -S --noconfirm` and `systemctl enable` with root privileges via pkexec; while the package list is hardcoded and safe, a human reviewer should confirm the polkit prompt clearly explains what is being installed/enabled.
  • The deterministic scan's 'high' rating overstates the risk: enabling avahi-daemon is a standard, documented dependency step, not a persistence backdoor.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/dicemans/omarchy-plugin-network-scanner --enable
System #bar #system #security

Network Scanner — Omarchy bar plugin

See who is on your network, straight from the bar. One click sweeps the local subnet and lists every device found — compact (IP and latency) or extended (mDNS name, MAC address, vendor, reverse DNS).

preview

What it does

  • On-demand scan — nothing runs periodically. The panel has one button; the sweep takes a few seconds and touches only your own subnet.
  • Compact view: one line per device — IP on the left, ping latency on the right. Extended view (toggle in the panel, key v): adds the device's mDNS name, MAC address, vendor from the OUI registry, and reverse DNS.
  • Finds quiet devices too: a device that filters ping but answers ARP is listed with a – latency instead of being missed.
  • Wide networks handled honestly: a /24 or smaller is swept whole; a wider subnet would mean thousands of probes, so the scan covers your own /24 plus every device the kernel's neighbour table and mDNS already know about across the full subnet. The panel says which mode applies.
  • Your own machine and the gateway are badged; clicking a device (or Enter) opens a small menu to copy its IP or MAC address to the clipboard, showing the exact value before it is copied.

How it works

Everything runs unprivileged: ping for the sweep and latency, ip neigh for MAC addresses, avahi-browse/avahi-resolve for mDNS names (skipped if Avahi is absent), getent for reverse DNS, and nmap's OUI table for vendor names when it is installed. No root, no raw sockets, no packet capture, and no traffic beyond the link you are already on.

The QML panel is a thin renderer: every probe lives in bin/netscan-ctl, a bash script you can run and debug in a terminal:

bin/netscan-ctl network   # what would be scanned: cidr, iface, own ip, mode
bin/netscan-ctl scan      # TSV, one line per discovered device

Settings

  • Open in extended view — start on the detailed list instead of the compact one.
  • Show device count in the bar — paint the last scan's device count next to the bar icon (a snapshot, not a live figure).

Keys

s scan · v toggle compact/extended · arrows move · Enter open the copy menu (IP or MAC) · Esc close

IPC

omarchy-shell ipc call io.github.dicemans.network-scanner toggle
omarchy-shell ipc call io.github.dicemans.network-scanner scan

Requirements

iproute2 and ping (both ship with Omarchy). For the full experience the plugin also uses avahi (mDNS device names), nmap (the vendor table) and wl-clipboard (copying). On a machine where any of these are missing — or avahi-daemon is not running — the panel shows a setup card that installs and activates everything behind a single polkit authorization; the scan itself works either way, just with fewer columns filled.

A note on etiquette

A ping sweep is ordinary, low-volume traffic, but on a network you do not own it can still be unwelcome. Scan networks you administer or have leave to probe.

License

MIT — see LICENSE.