Omahub
← All plugins
K

OmaVLESS

by kdk

OmaVLESS is a VPN app for Omarchy that puts everyday connection controls directly in the bar. Import your own compatible VLESS profile or HTTPS subscription, choose Full VPN, Routing or Direct, connect to a profile, switch profiles, or disconnect, and refresh subscription server lists. Free and open source; VPN servers and service subscriptions are not included.

Security review

Potentially dangerous behavior detected · 53 findings

Deterministic scan — not a security guarantee

High
Risk level
High
Analyzed commit
d620c30
Scanned
1 week ago

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
d620c30
Reviewed
1 week ago

The plugin is a QML bar widget that wraps a native Rust VPN runtime; the plugin code itself is a strict dispatcher (backend.sh) with a whitelist of commands and benign QML UI. The deterministic scan's high findings are largely false positives: chown in CI workflows, systemd units in packaging, and sudo mentions in documentation/tests are not part of the executable plugin path. The plugin install script requires the native package and does not start a tunnel or run destructive commands.

  • The plugin depends on an external native `omavless` binary and Mihomo core; users must ensure these are from a trusted source and that the native package is reviewed separately.
  • The plugin's Panel.qml may display or guide the user to run `sudo setcap` for Mihomo capabilities, but it requires explicit user confirmation and is not executed automatically by the plugin.
  • The plugin's install script (install.sh) modifies the user's Omarchy plugin directory and enables the plugin; it is non-destructive but does require the native owner to be installed first.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/k-kostin/omavless --enable
System #bar #quickshell #security

OmaVLESS

OmaVLESS is a VPN app for Omarchy that puts everyday connection controls directly in the bar.

Bring your own compatible VLESS profile or HTTPS subscription, choose Full VPN, Routing or Direct, and connect from the panel. Switch between profiles or disconnect without leaving the desktop; one VPN connection is active at a time.

Expand subscriptions and refresh their server lists beside your profiles. Profile management, routing tools, English/Russian language settings and privacy-safe support reports stay close at hand in a compact, terminal-style interface.

Free and open source. OmaVLESS is not a VPN provider: VPN servers, accounts and service subscriptions are not included.

OmaVLESS panel, disconnected, showing demonstration profiles and the three connection modes

Native interface with demonstration data; no live connection is shown.

Installation

OmaVLESS 0.8.2 is available. New users: add the plugin, then open its panel. Already using 0.7.0? Follow the migration guide before updating.

omarchy plugin add https://github.com/k-kostin/omavless --enable

If the application or Mihomo is missing, Required components offers guided installation. Confirm the steps in its terminal, return to the panel and follow onboarding. You can finish setup later; it never connects a VPN automatically.

This command follows upstream main. The marketplace's reviewed snapshot is updated separately; its older 0.7.0 listing is not the native release.

Follow the installation and upgrade guide, including migration instructions before updating an existing 0.7.0 installation. It covers the matching application package, Mihomo VPN core, TUN permissions and optional clipboard, file-picker and QR tools. Package installation and permission changes require your confirmation.

For manual downloads, use the matching 0.8.2 application and frontend from GitHub Releases. Do not pair this frontend with older 0.8.0/0.8.1 packages.

Everyday use

  1. Import a profile link or subscription URL from the clipboard or a file. Review the preview before saving.
  2. Choose Full VPN, Routing or Direct.
  3. Press Connect beside the profile you want. Selecting a profile for management is not the same as connecting it.

On the native main screen, expand a subscription to browse its profiles. Press ↻ beside the subscription's server count to download its updated server list. Profile management stays in the separate action bar below the list.

  • Full VPN sends traffic through the connected profile.
  • Routing uses the selected country policy and your domain/IP rules.
  • Direct keeps the TUN running while bypassing the proxy.

Settings contains language selection, routing tools, diagnostics, subscription management and shutdown controls. Changing the UI language does not restart the VPN. Automatic connection at login is Off by default; see the usage guide for its current limitations.

See controls and everyday use.

View the expanded subscription · View Settings

Supported inputs

Family Status
VLESS Supported; includes TCP, WebSocket, HTTP, H2, gRPC and XHTTP, with TLS/REALITY where compatible
Trojan, Hysteria2, TUIC v5 Experimental; real-server coverage is incomplete
Subscriptions HTTPS raw/base64 lists of supported profile links

Advanced VLESS Encryption/REALITY PQ and XHTTP combinations retain their experimental limitations. WireGuard, AmneziaWG and vpn:// inputs are not currently supported by the application.

See protocol support and limitations.

Privacy and help

Profiles and subscription URLs stay in a private local store. Imports accept supported profile links, not arbitrary remote configuration or executable content.

For support, use Copy report or Save report in Settings. Do not post profile files, subscription URLs, private configuration or unredacted screenshots.

Credits and license

Maintained by kdk. Community project; not affiliated with Omarchy, MetaCubeX or a VPN provider.

The interface builds on Omarchy VPN by Justin Köstinger. Routing data comes from RoscomVPN, MetaCubeX and Chocolate4U. See third-party notices.

MIT License · Contributing.