Omahub
← All plugins
D

SimpleOpenVPN

by Diogo

Simple OpenVPN toggle switch, profile selector, credentials manager, and live stats in the Omarchy bar.

Security review

No obvious issues detected

Deterministic scan — not a security guarantee

None
Risk level
None
Analyzed commit
bb51d0f
Scanned
1 month ago

No potentially dangerous behavior detected in the analyzed commit.

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
bb51d0f
Reviewed
1 month ago

The plugin is a well-structured OpenVPN manager with careful security practices: credentials are passed via stdin rather than argv, file operations use O_NOFOLLOW/O_DIRECTORY with descriptor-relative validation, and the privileged Python helper blocks dangerous OpenVPN directives. The install script is standard and non-malicious. The main residual risks are inherent to the functionality: storing VPN credentials in plaintext under ~/.local/state and running OpenVPN as root via pkexec, though the code appears to handle these boundaries responsibly.

  • VPN credentials are stored in plaintext files under ~/.local/state (mode 0600, user-owned), which is common but means any process running as the user can read them.
  • The plugin uses pkexec to run OpenVPN as root; while the validation logic appears robust, the full Python helper is truncated in the sample and cannot be completely audited.
  • The install.sh script installs system packages (openvpn, jq, zenity, python) which requires user consent via the --yes flag, but is standard for Omarchy plugins.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/diogogc/simple-openvpn --enable
Widgets #bar #quickshell #security

SimpleOpenVPN

SimpleOpenVPN is an Omarchy bar widget for running a single OpenVPN tunnel from the Omarchy shell. It provides a compact status icon, a profile picker, profile-specific credentials, connect/disconnect controls, live tunnel details, and recent OpenVPN log output.

The plugin is intentionally small: it does not manage NetworkManager VPN profiles, systemd services, or multiple concurrent tunnels. It is built for users who already have .ovpn or .conf files and want a direct bar control for them.

SimpleOpenVPN panel

Features

  • Add .ovpn or .conf profiles with a graphical file picker
  • Remember profiles across restarts
  • Save login credentials per profile file
  • Connect or disconnect from the bar
  • Right-click the bar icon for quick connect/disconnect
  • Show active tunnel interface, IPv4 address, and traffic counters
  • Show recent OpenVPN log lines inside the panel
  • Keep profile state under ~/.local/state

Requirements

SimpleOpenVPN is designed for Omarchy and its Quickshell-based shell.

Install these packages before enabling the plugin:

omarchy pkg add openvpn jq zenity python

It also uses tools that are normally present on Omarchy or Arch Linux:

  • pkexec
  • ip
  • ps
  • find
  • awk
  • grep
  • sed
  • python3
  • GNU coreutils

Install

Install dependencies:

omarchy pkg add openvpn jq zenity python

Add and enable the plugin:

omarchy plugin add https://github.com/diogogc/simple-openvpn.git --enable

Move it to the right side of the bar if needed:

omarchy bar move io.github.diogogc.simple-openvpn --section right

You can also use the included installer from a checked-out copy:

./install.sh

omarchy plugin add does not run plugin install hooks or privileged setup. The installer script is only a convenience wrapper that installs packages first and then calls omarchy plugin add.

Usage

Click the SimpleOpenVPN bar icon to open the panel.

Use Add Profile to select an OpenVPN .ovpn or .conf file. The selected file is remembered as a profile and becomes the active profile.

Enter your VPN username and password, then click Save for Profile. Credentials are linked to the selected profile path, so switching profiles also switches the saved credentials.

Use the switch in the panel to connect or disconnect. You can also right-click the bar icon to toggle the VPN without opening the panel.

Security

SimpleOpenVPN runs inside the unsandboxed Omarchy shell as the desktop user, then uses pkexec only for the OpenVPN launch/stop operations that need elevated privileges.

Security hardening in the current implementation was shaped by review from HANCORE-linux. Their feedback identified command-line credential exposure, predictable shared temporary paths, descriptor/path race conditions, and root OpenVPN execution of user-owned profiles.

The plugin now keeps credentials off process argv, stores profile auth files with private permissions, keeps privileged runtime files under a root-owned /run directory, performs descriptor-relative file publication, opens user-supplied files with O_NOFOLLOW and fstat() validation, and rejects OpenVPN profile directives that would add privileged code execution or control surfaces such as plugin, nested config, iproute, management sockets, script hooks, and runtime output overrides.

References:

Remove

omarchy plugin remove io.github.diogogc.simple-openvpn

License

MIT