Omahub
← All plugins
L

Password Store

by lef

Quick launcher for your web password vault — Bitwarden, Vaultwarden (self-hosted), 1Password or LastPass. Stores no credentials, no master password, no secrets: sessions live in your browser.

Security review

No obvious issues detected

Deterministic scan — not a security guarantee

None
Risk level
None
Analyzed commit
11d3dcb
Scanned
1 month ago

No potentially dangerous behavior detected in the analyzed commit.

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
11d3dcb
Reviewed
1 month ago

The plugin is a well-secured password vault launcher that opens web vaults in a dedicated browser window. It stores no credentials, validates all config inputs (provider, URL, browser) with strict allowlists and path checks, and uses bounded/atomic file operations. The code shows careful security practices, and the deterministic scan found no issues.

  • The plugin launches a browser with a dedicated profile, which may persist cookies/sessions; this is intended but users should be aware.
  • The browser executable path is validated to prevent path traversal, but the plugin still executes an external program; the risk is minimal given the validation.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/Somnius/Password-Store-for-Omarchy --enable
System #bar #quickshell #security

Password Store for Omarchy

An Omarchy shell plugin that puts your password vault in a dedicated desktop window — Bitwarden, Vaultwarden (self-hosted), 1Password or LastPass — without installing anything from those vendors.

A key glyph sits in the bar (default: right side):

  • Left-click — panel: pick your provider, open the vault window.
  • Hover — tooltip with the active provider.
  • IPC launch — open the vault window immediately.
<img width="404" height="546" alt="Password Store panel" src="preview.png" />

Why a dedicated vault window

Browser-extension popups are bundles inside each vendor's extension runtime (1Password's even requires its native-messaging desktop app) and cannot be loaded standalone. But every supported vendor ships a full-featured web vault, and this plugin gives that web vault a proper home:

  • Standalone app window: Chromium --app mode — chromeless, no tabs, reads like a native vault app.
  • Isolated profile per provider: ~/.local/share/omarchy/password-store/<provider>-profile. Sign in once; the session persists across opens. Vault cookies never touch your daily browser profile.
  • Falls back to xdg-open when no Chromium-family browser is found.

Security model

The plugin is deliberately minimal:

  • No credentials stored. No passwords, no master password, no TOTP seeds, no encrypted blob, nothing — not in config, not in memory, not on disk.
  • Unlocking happens inside the web vault. Search, copy and autofill-within-the-vault are protected by your provider's own 2FA, device approvals and lock timers.
  • One file written: ~/.config/omarchy/password-store/config.json — provider name, optional self-hosted URL, optional browser override. Nothing else.
  • Bounded and validated inputs: config reads stop at 32 KiB. URLs and browser overrides are capped at 4,096 characters, validated before entering plugin state and checked again before process launch. Invalid replacements leave the last accepted state intact.

If a password-manager plugin offers you an "encrypted local cache" of secrets, it has also offered you a key-management problem. This one refuses the premise.

Install

omarchy plugin add https://github.com/Somnius/Password-Store-for-Omarchy.git --enable

Then place the widget in the bar:

omarchy bar put lef.password-store --section right

From a local checkout (development)

If you already have a copy of this repository on disk, link it into the plugins folder:

ln -s "$PWD" ~/.config/omarchy/plugins/lef.password-store
omarchy-shell shell rescanPlugins

Dev loop caveat: Quickshell's file watcher does not follow symlinks; after edits run omarchy restart shell.

Validate at any time with:

omarchy plugin validate "$PWD"

Configuration

~/.config/omarchy/password-store/config.json — hot-reloads:

{
  "primaryVault": "vaultwarden",
  "vaultUrl": "https://vault.example.com"
}
Key Values Notes
primaryVault bitwarden | vaultwarden | 1password | lastpass Default: bitwarden
vaultUrl absolute URL, max 4,096 characters HTTPS required except for loopback HTTP; required for Vaultwarden
browser executable name or absolute path, max 4,096 characters Default: auto-detect (chromium, then brave)

IPC & keybindings

omarchy-shell lef.password-store status    # JSON state incl. resolved URL + browser
omarchy-shell lef.password-store launch    # open the vault window now
omarchy-shell lef.password-store toggle    # panel

Hyprland binding example (~/.config/hypr/bindings.lua):

o.bind("SUPER + ALT + P", "Open password vault", "omarchy-shell lef.password-store launch")

External dependencies

  • Perl (provided by Omarchy) for bounded config reads and atomic writes.
  • A Chromium-family browser for the app window: chromium or brave (auto-detected), otherwise any browser via xdg-open.
  • Network access to your chosen vault provider (the web vault itself handles all cryptography).

Uninstall

omarchy plugin remove lef.password-store

(If installed via symlink, remove the symlink instead. The vault session lives under ~/.local/share/omarchy/password-store/<provider>-profile; delete it to log out everywhere at once.)

License

MIT