Omahub
← All plugins
S

PIA VPN

by SteveHNH

Connect/disconnect Private Internet Access VPN and pick a region from the Omarchy bar.

Security review

Review recommended · 1 finding

Deterministic scan — not a security guarantee

Low
Risk level
Low
Analyzed commit
6d7ec45
Scanned
1 month ago

Flagged patterns appear only in documentation files (README / docs) — descriptive examples, not executable code.

  • Docs external_hosts README.md:40

    Downloads or connects to an external HTTP(S) host.

    git clone https://github.com/SteveHNH/omarchy-pia-plugin.git \

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

None
AI risk level
None
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
6d7ec45
Reviewed
1 month ago

This is a clean, well-structured VPN control widget that shells out to the official `piactl` CLI using hardcoded array-form commands with timeouts. No obfuscation, network access, persistence, credential handling, or shell interpolation was found. The only deterministic finding is a `git clone` in the README, which is documentation only and not executed by the plugin.

  • The deterministic scan flagged a `git clone` command in the README, but this is documentation for manual installation and is not executed by the plugin.
  • The plugin requires the PIA client's `piactl` binary, which is an expected dependency clearly documented in the README.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/SteveHNH/omarchy-pia-plugin --enable
Widgets #bar #system #security

PIA VPN — Omarchy bar widget

A bar-widget plugin for Omarchy that connects and disconnects Private Internet Access VPN from the top bar, with a searchable region picker in the popup.

PIA VPN widget popup

Requirements

  • Omarchy with the Quickshell-based plugin system (omarchy plugin / omarchy bar commands available).

  • The PIA desktop client installed, providing the piactl CLI on PATH.

  • PIA background mode enabled, so the daemon stays controllable without the GUI open:

    piactl background enable
    

    Without this, connect from the widget will fail with "start the PIA client to activate the daemon" until you launch the PIA app once.

This plugin only shells out to piactl (get/set/connect/disconnect); it does not touch your PIA credentials, network configuration, or any files outside its own polling of piactl output.

Install

omarchy plugin add https://github.com/SteveHNH/omarchy-pia-plugin.git --enable

This clones the plugin, prompts for a bar section (pick right to match the built-in Bluetooth/Network/Audio widgets), and enables it.

To install manually instead:

git clone https://github.com/SteveHNH/omarchy-pia-plugin.git \
  ~/.config/omarchy/plugins/io.github.stevehnh.pia-vpn
omarchy plugin validate ~/.config/omarchy/plugins/io.github.stevehnh.pia-vpn
omarchy plugin enable io.github.stevehnh.pia-vpn --section right

Remove

omarchy plugin disable io.github.stevehnh.pia-vpn
rm -rf ~/.config/omarchy/plugins/io.github.stevehnh.pia-vpn
omarchy-shell shell rescanPlugins

Usage

  • Left-click the bar icon: open/close the popup.
  • Right-click the bar icon: force a status refresh.
  • Middle-click the bar icon: connect/disconnect without opening the popup.
  • In the popup: the switch connects/disconnects, and the region field is a searchable dropdown over every region piactl get regions reports.

The bar icon is a shield glyph — solid/bright when connected, dimmed when disconnected, and colored as an alert if piactl becomes unreachable (e.g. the PIA daemon isn't running and background mode isn't enabled).

Settings

  • refreshIntervalSec (2–60, default 5): how often the widget polls piactl for connection state and region. Configurable from Omarchy's plugin settings UI.

License

MIT — see LICENSE.