Omahub
← All plugins
E

BlueFerry

by Erik Bourget

Send and receive iMessage and SMS through your iPhone

Security review

Review recommended · 1 finding

Deterministic scan — not a security guarantee

Medium
Risk level
Medium
Analyzed commit
a384538
Scanned
3 weeks ago
  • medium external_hosts Panel.qml:144

    Downloads or connects to an external HTTP(S) host.

    git clone https://github.com/erikwb/blueferry.git ~/src/blueferry' "

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
a384538
Reviewed
3 weeks ago

The plugin is a QML bar widget that communicates with a locally installed BlueFerry backend over stdin/stdout JSON; no malicious, obfuscated, or destructive behavior was found. The deterministic scan flagged a `git clone` URL in Panel.qml, but that code only displays build instructions in a terminal when the user clicks the widget while BlueFerry is missing, and does not execute the clone or build automatically. The remaining processes and commands are limited to checking for expected binaries, launching the official client, and sending reply requests to the backend.

  • The `external_hosts` finding refers to a hardcoded `git clone https://github.com/erikwb/blueferry.git` command shown to users as installation instructions; it is not run automatically by the plugin.
  • The widget relies on and launches system binaries under `/usr/bin/blueferry*`, so users should trust the separately installed BlueFerry backend; this is consistent with the documented purpose and not a plugin-level risk.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/erikwb/omarchy-blueferry --enable
Productivity #bar #quickshell

BlueFerry for Omarchy Quattro

This is the native Omarchy panel for BlueFerry. It allows you to send and receive iMessages over Bluetooth while paired to your iPhone with no special software running on your phone, no proxies, and no cloud tricks.

This widget shows connection health and unread conversations in the bar popup. Write directly in the reply field beneath each unread conversation, then press Enter or click Send. Press Escape to leave the field; drafts stay available until sent or the shell restarts. Click a conversation's name or preview to open it in the full client, which also handles pairing and preferences.

Group replies use the members saved in BlueFerry. If a group's members need review, open it in the full client before replying. Failed sends keep your draft, and replies are never automatically retried.

BlueFerry for Omarchy Quattro

Install it through Omarchy:

omarchy plugin add https://github.com/erikwb/omarchy-blueferry.git

Omarchy adds third-party plugins disabled. Review it, then enable BlueFerry from Setup › Plugins and place it on the bar.

Remove it with:

omarchy plugin remove io.weirdware.blueferry

The widget expects blueferry-backend and blueferry-quickshell 0.8.0 or newer. If they are missing, clicking it opens a terminal with the source-build commands; it does not run them for you.

Run the reply tests with python -m pytest -q tests (requires pytest and PySide6). On Omarchy, the UI test also uses Quickshell and bubblewrap to test the native controls in isolation with a fake backend. It cannot send messages or access the running desktop.

Licensed under GPL version 2 only.