Omahub
← All plugins
5

Borg

by 5t0ll1

Vorta/Borg backup status and one-click backup for the Omarchy bar.

Security review

No obvious issues detected

Deterministic scan — not a security guarantee

None
Risk level
None
Analyzed commit
c777877
Scanned
1 week ago

No potentially dangerous behavior detected in the analyzed commit.

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
c777877
Reviewed
1 week ago

The plugin is a benign bar widget that reads local Vorta/Borg status and can trigger backups. It does not exfiltrate data, contains no obfuscation or destructive commands, and the helper script only performs a TCP reachability check. The only minor concern is that it reads Vorta's local SQLite database and log files, but it only extracts non-sensitive status fields and sanitizes error hints.

  • Reads Vorta's settings.db and log files, which could contain sensitive metadata, but only extracts non-secret fields (profile name, repo URL host, schedule) and sanitizes error messages.
  • Can start backups via Vorta, which is expected functionality and requires user action (clicking Backup now or pressing 'b').
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/5t0ll1/omaborg --enable

omaborg

Omarchy bar widget for Vorta / Borg.

Shows last-backup freshness on the bar and lists recent archives in a panel. Left click opens basic stats; right click opens the full view with archive history and a one-click Backup now button. Status is read from Vorta's local SQLite database and /proc. The widget never SSHs to a backup server and never reads Borg passphrases or SSH keys.

omaborg panel

Install

omarchy plugin add https://github.com/<you>/omaborg.git --enable

Place it on the bar if needed:

omarchy plugin enable oma.borg --section right

Requirements

  • Omarchy (Quickshell bar)
  • vorta and borg on PATH
  • A Vorta profile already configured

If you have more than one Vorta profile, set Vorta profile name in the widget settings (or in ~/.config/omarchy/shell.json on the bar entry). Leave it empty to use the first profile.

The widget greys the Backup now button out and dims the bar icon while the repository host is not answering, so a missing backup does not look like a failure. Nothing to configure: it probes the host from the repository URL that Vorta already stores.

To stop Vorta from even starting a backup it cannot finish, point the pre-backup command at scripts/vorta-require-repo:

# In Vorta -> profile -> pre-backup command:
~/.local/bin/vorta-require-repo my-nas.example.lan 6666

Both ask the same question - can the repository be reached - so a backup over a VPN tunnel works exactly like one on the home LAN. An earlier version compared the Wi-Fi SSID instead, which asked about location: it blocked backups over a tunnel, and it could not tell apart two places that broadcast the same network name.

When the host is unreachable, scheduled and manual backups are skipped with a message instead of failing halfway through. The bar stays quiet (not red) while homeSsid says you are away.

Bar colors

Appearance Meaning
Normal Last backup within 24 hours
Dim Older than 24 hours
Red with ! Last backup failed, overdue (> 48 hours), or no backup yet
Pulse A backup is running

When the icon is red, right-click for the full panel with a short what to do list (usually: get on the home network, then Backup now).

Thresholds are widget settings (staleAfterHours, failedAfterHours).

Clicks and keys

Bar:

  • Left click: open basic stats (no archives)
  • Right click: open full view with archive history
  • Middle click: no action

Panel:

  • b: backup now
  • Esc: close

What this repo does not contain

This project is meant to be public. It must not include:

  • SSH private keys, authorized_keys, or known_hosts
  • Borg passphrases or key files
  • Vorta settings.db (passwords, repo URLs)
  • Hostnames, IPs, ports, or remote repo paths

Runtime status (profile name, last archive names) is read on your machine from Vorta. It is not stored in this repository.

Remove

omarchy plugin remove oma.borg

Development

Repo root is the plugin folder (manifest.json at the top level), which is what omarchy plugin add expects.

omarchy plugin validate .

To run a local checkout on Omarchy without publishing:

rsync -a --delete --exclude .git --exclude .gitignore \
  ./ ~/.config/omarchy/plugins/oma.borg/
omarchy-shell shell rescanPlugins