Omahub
← All plugins
J

KeePassXC

by Jaap van der Meer

Secure KeePassXC status and native tray actions in the Omarchy bar.

Security review

No obvious issues detected

Deterministic scan — not a security guarantee

None
Risk level
None
Analyzed commit
adc2ec0
Scanned
1 month ago

No potentially dangerous behavior detected in the analyzed commit.

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

None
AI risk level
None
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
adc2ec0
Reviewed
1 month ago

The plugin is a benign bar widget that interacts with KeePassXC via window/tray metadata and simple shell scripts. It only reads status information, launches or locks KeePassXC, and optionally locks the system session. No network access, privilege escalation, or sensitive data handling is present.

How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/japetheape/omarchy-keepassxc --enable
Widgets #bar #quickshell #security

KeePassXC for Omarchy

An unofficial Omarchy Quattro bar widget for KeePassXC. It shows a reduced application state, launches or focuses KeePassXC, locks open databases, and exposes top-level actions published by KeePassXC's native tray item.

Requirements

  • A current Omarchy Quattro installation
  • KeePassXC 2.7 or newer
  • bash, gtk-launch, hyprctl, jq, pgrep, setsid, timeout, and uwsm-app

Omarchy supplies the runtime commands above on a standard installation. KeePassXC is the only additional application dependency.

Install

omarchy plugin add https://github.com/japetheape/omarchy-keepassxc.git --enable

The widget defaults to the right section of the bar. Move it with Omarchy's bar settings if needed.

Use

  • Left click: open or close the status panel
  • Right click: launch or focus KeePassXC
  • Open/Launch action: show the running application or start it through uwsm-app
  • Lock action: ask KeePassXC to lock all open databases
  • KeePassXC actions: invoke available top-level actions from its native tray menu

The icon distinguishes stopped, running, locked, and unlocked states when KeePassXC publishes enough metadata. Ambiguous metadata is reported conservatively as running.

Privacy and security

The plugin does not read password databases, passwords, browser-integration messages, or KeePassXC configuration. It does not access the network, elevate privileges, install packages, or modify user configuration.

KeePassXC and Hyprland publish window and tray titles. The plugin compares those values in memory with KeePassXC's known locked and database-window formats, reduces them to a state, and never displays, logs, or stores the original title or database name.

Native tray actions are supplied and executed by KeePassXC. The plugin only renders and triggers the top-level actions KeePassXC publishes.

Optional integration

The plugin does not change keybindings, window rules, menus, or KeePassXC settings automatically.

Keybindings

Add equivalent bindings to ~/.config/hypr/bindings.lua if desired:

o.bind("SUPER + SHIFT + SLASH", "Passwords", "bash \"$HOME/.config/omarchy/plugins/io.github.japetheape.keepassxc/launch.sh\"")
o.bind("SUPER + CTRL + L", "Lock system", "bash \"$HOME/.config/omarchy/plugins/io.github.japetheape.keepassxc/lock-session.sh\"")

lock-session.sh waits for the bounded KeePassXC lock attempt before locking the Omarchy session. It still locks the session if KeePassXC returns an error, then reports that error to its caller.

Window privacy

The following optional rule keeps KeePassXC floating and excludes it from screen sharing:

o.window("^org\\.keepassxc\\.KeePassXC$", { no_screen_share = true, tag = "+floating-window" })

Add it to ~/.config/hypr/hyprland.lua, then run hyprctl reload and check hyprctl configerrors.

Close to tray

To make closing KeePassXC hide it without ending the current unlocked session, enable these settings in KeePassXC:

[GUI]
MinimizeOnClose=true
MinimizeToTray=true
ShowTrayIcon=true

[Security]
LockDatabaseMinimize=false
LockDatabaseScreenLock=true

Confirm the dedicated widget works before hiding the generic KeePassXC entry through Omarchy's tray management popup. Enabling LockDatabaseScreenLock ensures KeePassXC also locks when the desktop session locks.

Development

omarchy plugin validate ~/.config/omarchy/plugins/io.github.japetheape.keepassxc
node ~/.config/omarchy/plugins/io.github.japetheape.keepassxc/test-model.js
bash ~/.config/omarchy/plugins/io.github.japetheape.keepassxc/tests/test-scripts.sh
qmllint -I /usr/share/omarchy/shell ~/.config/omarchy/plugins/io.github.japetheape.keepassxc/Panel.qml

Remove

omarchy plugin remove io.github.japetheape.keepassxc

Optional keybindings, window rules, menu overrides, tray preferences, and KeePassXC settings are user configuration and must be removed separately.

License

MIT