Omahub
← All plugins
Z

Deco Mesh

by ZestyBytes

See connected devices and mesh status for your TP-Link Deco network from the bar

Security review

Review recommended · 2 findings

Deterministic scan — not a security guarantee

Low
Risk level
Low
Analyzed commit
dd669cc
Scanned
1 month ago

Flagged patterns appear only in documentation files (README / docs) — descriptive examples, not executable code.

  • Docs external_hosts README.md:34

    Downloads or connects to an external HTTP(S) host.

    git clone https://github.com/ZestyBytes/omarchy-plugin-deco.git ~/.config/omarchy/plugins/io.github.zestybytes.deco-mesh
  • Docs package_manager requirements.txt:1

    System-wide Python package installation (not --user).

    pip install --require-hashes`

Automated analysis only — not a security guarantee.

AI advisory review

Review recommended

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
review
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
dd669cc
Reviewed
1 month ago

The plugin is a local-only Deco network widget with no evidence of obfuscation, external data exfiltration, or malicious install-time behavior; the deterministic findings are documentation and a pinned dependency list. The main residual risks are plaintext router-credential storage and disabling TLS verification for the local Deco API, both disclosed in the README, plus a reboot() method that conflicts with the README's read-only claim and should be confirmed unreachable from the QML.

  • Router admin credentials are stored in plaintext in ~/.local/state/omarchy/deco-mesh/config.json, and the Deco HTTPS connection uses verify=False; this is disclosed but still exposes the credentials to any process running as the same user or to a LAN attacker if TLS is not actually verified.
  • deco_status.py contains a reboot(macs) method even though the README says the plugin is read-only and cannot reboot the Deco; no call was visible in the sampled QML, but the full Panel.qml should be checked for any path that invokes it.
  • The deterministic scan flagged requirements.txt as a system-wide pip install, while the README says dependencies are installed into a local virtualenv only after explicit user action; the installDeps path should be verified to use that venv and not system pip.
  • The README's git clone one-liner is documentation only; the external_hosts finding does not reflect runtime plugin behavior.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/ZestyBytes/omarchy-plugin-deco --enable
Hardware #bar #quickshell #system

Deco Mesh — Omarchy Plugin

Preview

(mock data shown above — not a real network)

An Omarchy plugin that adds a bar icon for your TP-Link Deco mesh network. Click the icon to see every connected device grouped by which Deco node it's on, with live up/down speed, offline/online desktop notifications, and — for a node hopping its backhaul wirelessly through another one instead of straight to the main unit — the signal strength of that hop.

This is a bar-widget plugin: a single QML entry point (Panel.qml) that renders both the bar icon and its floating popup, with two views — the device tree, and a settings screen (the cog icon) for entering your Deco's IP/username/password, with a live connection test before it saves.

Requirements

  • Omarchy with plugin support (omarchy plugin commands)
  • Python 3 (already present on Omarchy) — the panel offers an "Install dependencies" button on first use, which builds a local virtualenv and installs requests and pycryptodome from pinned, hash-verified versions (a few seconds, once). Nothing is installed automatically or without that click
  • A TP-Link Deco mesh with local network access to it (tested on the X50; other Deco models use the same local API family and should work, but field names can vary by firmware — open an issue if something's off)

Install

git clone https://github.com/ZestyBytes/omarchy-plugin-deco.git ~/.config/omarchy/plugins/io.github.zestybytes.deco-mesh
omarchy plugin enable io.github.zestybytes.deco-mesh
omarchy bar put io.github.zestybytes.deco-mesh

Click the new bar icon, open settings (the cog), and enter your Deco's local IP (usually 192.168.68.1 or 192.168.0.1 — check your router or the Deco app), the admin username (admin), and your Deco admin password. Save runs a live test before confirming.

Remove

omarchy plugin disable io.github.zestybytes.deco-mesh
rm -rf ~/.config/omarchy/plugins/io.github.zestybytes.deco-mesh
rm -rf ~/.local/state/omarchy/deco-mesh

How it works

deco_status.py is a small headless Python helper that logs into the Deco's local /cgi-bin/luci/;stok=... HTTPS API — a self-signed cert, and a request/response format encrypted with RSA (for login) and AES (for everything after) — reverse-engineered from prior community work on this API family, notably amosyuen/ha-tplink-deco. Panel.qml runs it every 60 seconds via a background Process and renders whatever JSON comes back; it never talks to the Deco directly.

Your Deco's host/username/password are saved as plain JSON at ~/.local/state/omarchy/deco-mesh/config.json (0600 permissions) — outside the plugin's own directory, so editing it doesn't retrigger Omarchy's plugin hot-reload.

Limitations

  • Read-only: this shows your network, it doesn't change anything on your Deco (no reboot, no guest-wifi toggle). That's deliberate for now, not a missing feature — see the repo's issues if you'd like one added.
  • The per-node client breakdown, backhaul routing, and signal strength come from endpoints not officially documented by TP-Link; they've worked reliably in testing but could shift with a firmware update.