Omahub
← All plugins
T

Espanso

by taisau

Espanso text expander controls, expansion toggle, native search launcher, and live snippet explorer for the Omarchy top bar.

Security review

Review recommended · 2 findings

Deterministic scan — not a security guarantee

Medium
Risk level
Medium
Analyzed commit
db3121b
Scanned
1 week ago
  • Command runs with sudo, elevating the process beyond the plugin environment.

    sudo pacman -S --needed espanso-wayland
  • Docs external_hosts README.md:29

    Downloads or connects to an external HTTP(S) host.

    git clone https://github.com/taisau/omarchy-espanso.git ~/.config/omarchy/plugins/io.github.taisau.espanso

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
db3121b
Reviewed
1 week ago

This is a straightforward QML bar widget that controls the Espanso daemon through its CLI, reads match data with bounded buffers, and copies snippets via wl-copy. The only system-modifying code is an explicit, user-triggered install helper that installs espanso-wayland through normal package managers and enables the user service; no obfuscation, credential theft, or hidden persistence was found. The deterministic medium findings are explained by the README's git clone example and the sudo line in that opt-in install script, not by malicious behavior.

  • The install helper can invoke sudo pacman, yay, or paru to install espanso-wayland and enables a user systemd service; this is a system-level change but only occurs when the user explicitly clicks the install action and sees the terminal output.
  • Runtime code executes espanso, systemctl, xdg-open, and wl-copy via absolute paths with no shell injection or network exfiltration observed.
  • The external-host finding refers to the README's documented git clone installation method, which is illustrative documentation rather than executable plugin code.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/taisau/omarchy-espanso --enable
Productivity #bar #quickshell

Espanso for Omarchy Top Bar

Control Espanso directly from the Omarchy status bar.

Features

  • Status & One-Click Toggle: View daemon health and instantly enable or disable text expansions with a toggle switch.
  • Native Search Launcher: Open Espanso's native GUI modal (espanso cmd search) to search and inject snippets into active windows.
  • In-Panel Snippet Explorer: Instant live filtering and preview of all defined matches (sorted alphabetically A-Z); click any snippet to copy its replacement text to the clipboard.
  • Bar Shortcuts:
    • Left-Click: Open/close the dropdown panel.
    • Right-Click: Instantly trigger native search.
    • Middle-Click: Instantly toggle expansions on/off.

Dependencies

  • espanso or espanso-wayland
  • wl-clipboard (for snippet clipboard copying)

Installation

omarchy plugin add https://github.com/taisau/omarchy-espanso.git --enable

Or manually clone into your user plugins:

git clone https://github.com/taisau/omarchy-espanso.git ~/.config/omarchy/plugins/io.github.taisau.espanso

And add to ~/.config/omarchy/shell.json in bar.layout.right:

{ "id": "io.github.taisau.espanso" }

Removal

omarchy plugin remove io.github.taisau.espanso

License

MIT