Omahub
← All plugins
K

OmaMullvad

by kallupx

A theme-aware Mullvad VPN control and status widget for the Omarchy bar.

Security review

No obvious issues detected

Deterministic scan — not a security guarantee

None
Risk level
None
Analyzed commit
e8ea42f
Scanned
4 weeks ago

No potentially dangerous behavior detected in the analyzed commit.

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
e8ea42f
Reviewed
4 weeks ago

This is a well-structured Mullvad VPN control widget that interacts with the Mullvad CLI. The code shows strong security practices: input validation, output bounding, redaction of sensitive data (account numbers, tokens), and a comprehensive test suite covering edge cases like command timeouts and output overflows. The plugin only performs actions the user explicitly requests (connect/disconnect, settings changes) and the README's claim about the CLI contract test being read-only is accurate.

  • The plugin executes the Mullvad CLI with elevated privileges (VPN control), but this is the core, documented purpose of the plugin and requires explicit user action.
  • The plugin can install the AUR package `mullvad-vpn-bin` if Mullvad is missing, but only after user confirmation, which is a reasonable and transparent behavior.
  • The plugin sends account numbers to `mullvad account login` over stdin, but this is the standard, documented way to authenticate with the Mullvad CLI and the code explicitly redacts this data from logs and output.
  • The code is not obfuscated and is well-commented, making it auditable.
  • The test suite is thorough and includes tests for security-relevant behaviors like output limits, timeouts, and data redaction.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/kallupx/oma-mullvad --enable
Widgets #bar #quickshell #security

OmaMullvad

OmaMullvad preview

Mullvad VPN controls for the Omarchy Quattro bar.

  • Connect and disconnect from the bar or panel
  • Search relays and choose a specific server
  • Save up to nine favourite locations
  • Filter by provider, ownership, and IP version
  • Configure DNS, anti-censorship, LAN sharing, and lockdown mode
  • Launch apps outside the VPN
  • View Mullvad relay cities on a world map

OmaMullvad follows the active Omarchy theme and works with the stock bar and Shibumi.

Install

omarchy plugin add https://github.com/kallupx/oma-mullvad.git --enable

OmaMullvad targets Mullvad VPN 2026.4. If Mullvad is missing, the panel can install the AUR package mullvad-vpn-bin after confirmation.

Controls

  • Left-click: open the panel
  • Right-click: connect or disconnect
  • Middle-click: refresh

The panel has Overview, Locations, Advanced, and Excluded Apps pages. It is fully keyboard-accessible.

Hotkeys

OmaMullvad does not add keybindings automatically. Example ~/.config/hypr/bindings.lua entries:

o.bind("SUPER + SHIFT + V", "Toggle Mullvad", "omarchy-shell io.github.kallupx.oma-mullvad toggleTunnel")
o.bind("SUPER + ALT + V", "Next Mullvad favourite", "omarchy-shell io.github.kallupx.oma-mullvad nextFavorite")
o.bind("SUPER + SHIFT + ALT + V", "OmaMullvad panel", "omarchy-shell io.github.kallupx.oma-mullvad toggle")

Uninstall

omarchy plugin remove io.github.kallupx.oma-mullvad

Privacy

Account numbers are sent to mullvad account login over standard input and are never stored. OmaMullvad stores only favourites and recent locations; Mullvad remains responsible for VPN settings.

Verify

node --test
node tests/cli-contract.mjs
omarchy plugin validate .

The CLI contract check is read-only.

License

MIT © 2026 kallupx

The map uses public-domain Natural Earth data. Relay locations come from the Mullvad CLI.