Omahub
← All plugins
N

OmaLive

by Nik

macOS Sonoma-style aerial screensaver and live wallpaper for omarchy 4.

Security review

Review recommended · 7 findings

Deterministic scan — not a security guarantee

Medium
Risk level
Medium
Analyzed commit
7557501
Scanned
1 month ago
  • medium external_hosts install.sh:20

    Downloads or connects to an external HTTP(S) host.

    git clone https://github.com/nikbos/Omalive ~/Projects/omalive/OmaLive
  • medium external_hosts install.sh:221

    Downloads or connects to an external HTTP(S) host.

    git clone https://github.com/nikbos/OmaLiveLock ~/Projects/omalive/OmaLiveLock
  • medium sudo install.sh:87

    Command runs with sudo, elevating the process beyond the plugin environment.

    sudo pacman -S --needed "${MISSING_PKGS[@]}"
  • Docs external_hosts README.md:38

    Downloads or connects to an external HTTP(S) host.

    git clone https://github.com/nikbos/Omalive ~/Projects/omalive/OmaLive
  • Docs external_hosts README.md:54

    Downloads or connects to an external HTTP(S) host.

    git clone https://github.com/nikbos/Omalive ~/Projects/omalive/OmaLive
  • Docs external_hosts README.md:66

    Downloads or connects to an external HTTP(S) host.

    git clone https://github.com/nikbos/OmaLiveLock ~/Projects/omalive/OmaLiveLock
  • Docs external_hosts README.md:188

    Downloads or connects to an external HTTP(S) host.

    git clone https://github.com/nikbos/Omalive ~/Projects/omalive/OmaLive

Automated analysis only — not a security guarantee.

AI advisory review

Review recommended

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Medium
AI risk level
Medium
Recommendation
review
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
7557501
Reviewed
1 month ago

The OmaLive service/QML code itself is well-hardened and shows no malicious patterns; the README external-host hits are documentation and the sudo pacman call is a disclosed dependency install. The real review point is install.sh: it installs and enables the separate OmaLiveLock plugin (a lock-screen/password-UI component) from another repository, so the clone/pin behavior and that plugin's code must be verified before a user is told to run this installer.

  • install.sh installs and enables the companion `omalive-lock` plugin from `nikbos/OmaLiveLock`, whose code is not included in this review; since that plugin owns the lock screen/password UI, it needs a separate security review.
  • The flagged `git clone https://github.com/nikbos/OmaLiveLock ...` in install.sh must be confirmed to use a pinned reviewed commit (and not an unpinned remote branch) before running the unsandboxed `omarchy plugin add`.
  • install.sh runs `sudo pacman -S --needed ...` for missing dependencies; this is normal and disclosed, but it is an elevated action the user should explicitly consent to.
  • install.sh also suppresses the stock ttfx screensaver and changes shell/menu state; this is documented and reversible via uninstall.sh, but is broader than the plugin's entrypoints alone.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/nikbos/Omalive --enable
Desktop #launcher

OmaLive

<img width="2560" height="1440" alt="screenshot-2026-08-24_03-03-09" src="https://github.com/user-attachments/assets/ae2e017c-7fef-4df4-a732-92f8384cc7e4" />

A macOS Sonoma-style Aerial screensaver and live wallpaper for Omarchy 4 (Quickshell / Hyprland).

  • Screensaver — when the system is idle, fullscreen aerial footage plays above everything (cursor hidden, like the stock ttfx screensaver).
  • Live lock screen — the lock screen plays the aerial footage too (macOS Sonoma style): locking resumes the footage exactly where it was, it keeps drifting while locked, and on unlock the wallpaper freezes on the exact frame the lock last showed. The lock appears on the exact frozen aerial frame (no dark flash while the video decodes) and the screensaver yields the moment you lock — even a fast lock→unlock never leaves the aerial up over the desktop. Provided by the companion OmaLiveLock plugin (own repository), a fork of the stock omarchy.lock.
  • Sonoma freeze transition — when you dismiss it (or after unlocking), the footage keeps playing at normal speed for ~2 seconds, then freezes: the screensaver fades straight into the desktop with the same playback continuing on the wallpaper, and the wallpaper becomes the exact frozen frame where the footage stopped.
  • Live wallpaper — optionally keep the wallpaper slowly drifting instead of freezing (omalive live on).
  • Multi-monitor — one clip per screen or one clip everywhere.
  • No daemon, no systemd unit — it is one omarchy-shell plugin doing the rendering, idle detection, transition and state persistence.

Install

The installer (install.sh) and omarchy plugin add execute this repository's code unsandboxed, so always install from a reviewed, pinned checkout — never from a moving remote branch. git clone of a local dir copies exactly the checked-out commit, so review the pinned commit first, then:

git clone https://github.com/nikbos/Omalive ~/Projects/omalive/OmaLive
git -C ~/Projects/omalive/OmaLive checkout 0267a019845e2ad25b9e52dc03f24a6badee6579
~/Projects/omalive/OmaLive/install.sh

The installer installs dependencies (qt6-multimedia, jq, python3), suppresses the stock ttfx screensaver so OmaLive owns idle, adds the plugin, installs the omalive CLI, installs and enables the companion OmaLiveLock lock screen, and restarts the shell.

To install only the plugin (no extras), register it from a pinned local checkout of the same reviewed commit:

# review the pinned commit first, then add the local checkout (git clone of a
# local dir copies exactly the checked-out commit — nothing newer)
git clone https://github.com/nikbos/Omalive ~/Projects/omalive/OmaLive
git -C ~/Projects/omalive/OmaLive checkout 0267a019845e2ad25b9e52dc03f24a6badee6579
omarchy plugin add ~/Projects/omalive/OmaLive --enable
omarchy restart shell

The companion lock screen is a separate plugin in its own repository (nikbos/OmaLiveLock). Review and add it from a pinned local checkout the same way — do not plugin add an unpinned remote URL:

git clone https://github.com/nikbos/OmaLiveLock ~/Projects/omalive/OmaLiveLock
git -C ~/Projects/omalive/OmaLiveLock checkout 9f160be35a0d15eede0f4cb0f63d9a4c1d20933d
# review the checked-out commit, then:
omarchy plugin add ~/Projects/omalive/OmaLiveLock --enable
omarchy restart shell

Locked? The installer and omarchy plugin add/update refuse or should be avoided while the session is locked: writing into the plugin folder hot-reloads the shell and tears down the active lock screen. Unlock first.

Quick start

omalive fetch                          # download aerial-style clips to ~/Videos/Aerial
omalive play ~/Videos/Aerial/clip.mp4  # play everywhere
omalive screensaver start              # preview the screensaver now
omalive freeze                         # glide to a stop; frozen frame becomes the wallpaper
omalive status

CLI

Command What it does
omalive status Current state, per monitor
omalive play <file> [screen] Play a clip everywhere, or on one monitor
omalive off <screen> Blank one monitor
omalive freeze Decelerate to a stop; the frozen frame is the wallpaper
omalive flourish Play from the frozen frame, then glide to a stop
omalive screensaver <on|off|start|stop|status> Control the screensaver
omalive live <on|off> Live wallpaper (keeps drifting) vs frozen frame
omalive transition <seconds> Length of the freeze transition (1–10)
omalive autopause <on|off> Pause under fullscreen windows
omalive shuffle <on|off> Rotate clips while the screensaver is up
omalive fetch [dest] Download aerial-style clips

Bar widget

Click the film glyph in the bar for the control panel: clip library, per-screen assignment, screensaver toggle, live-wallpaper toggle, transition length, and transport (Play / Freeze / Screensaver). Right-click the icon to flip between playing and frozen.

Keybinds

Add to ~/.config/hypr/bindings.lua:

o.bind("SUPER + ALT + W", "OmaLive toggle", "omalive toggle")
o.bind("SUPER + ALT + V", "OmaLive panel", "omarchy-shell shell toggle omalive")

Configuration

All options live in ~/.config/omarchy/shell.json under a plugins[] entry (optional; defaults apply without it):

{ "id": "omalive",
  "videoPath": "~/Videos/Aerial/any.mp4",
  "screenVideos": { "DP-1": "~/Videos/Aerial/a.mp4", "DP-2": "" },
  "videoDir": "~/Videos/Aerial",
  "transitionSeconds": 2,
  "pauseOnFullscreen": true,
  "liveWallpaper": false,
  "shuffle": true,
  "flourishOnLogin": true,
  "stopDelaySeconds": 2,
  "glideToStop": false }

Runtime changes from the panel/CLI persist to ~/.local/state/omalive/state.json and survive restarts — no autostart step.

Videos

Apple's Aerial footage is copyrighted and too large to bundle, so OmaLive plays whatever is in the video folder (default ~/Videos/Aerial, scanned at startup for shuffle). omalive fetch downloads a small starter set of openly-licensed aerial drone clips from Wikimedia Commons. Drop in your own .mp4 / .mkv / .webm / .mov / .avi files — the panel and shuffle pick them up.

Live lock screen (OmaLiveLock)

install.sh also installs and enables the companion OmaLiveLock plugin from its own repository (nikbos/OmaLiveLock) — a fork of the stock omarchy.lock that plays the OmaLive aerial footage on the lock screen:

  • Locking resumes the footage exactly where it was (screensaver or wallpaper). The lock surface first shows the exact frozen aerial frame OmaLive captured at lock time — no dark decode gap — then fades the live video in and keeps it playing behind the stock password UI with a light scrim.
  • Locking also force-exits the screensaver overlay immediately (it is hidden by the session lock anyway), so a fast lock→unlock never leaves the aerial covering the desktop.
  • While locked, the lock surfaces sample their playback position; on unlock it is handed back to OmaLive, which parks the wallpaper on the exact frame the lock last showed and then runs the usual login flourish from there.
  • Fallback: with OmaLive disabled, no clip assigned, or a player error, the lock shows the stock blurred wallpaper — it never degrades to a broken surface.

The manifest declares omarchy.clonedFrom: omarchy.lock, so enabling omalive-lock automatically disables the stock lock; disable or remove it to get the stock lock back:

omarchy plugin disable omalive-lock   # restores the stock lock screen
omarchy plugin enable omalive-lock    # back to the live aerial lock

Removal

install.sh installs more than the shell plugins, so a bare omarchy plugin remove omalive leaves the CLI helpers, the stock-screensaver suppression and the menu override behind. Run uninstall.sh from the checkout instead — it removes everything install.sh installed:

# from the same reviewed checkout you installed from:
git clone https://github.com/nikbos/Omalive ~/Projects/omalive/OmaLive
git -C ~/Projects/omalive/OmaLive checkout 0267a019845e2ad25b9e52dc03f24a6badee6579
~/Projects/omalive/OmaLive/uninstall.sh

uninstall.sh deletes ~/.local/bin/omalive{,,-fetch,-optimize}, removes the screensaver-off / omalive-screensaver-off toggles (restoring the stock ttfx screensaver), reverts the menu Screensaver-row override, removes ~/.local/state/omalive, removes the omalive-lock and omalive plugins (restoring the stock lock), and restarts the shell. Use uninstall.sh --files-only to keep the plugins, or --plugins-only for just the plugin removal. It refuses while the session is locked.

License

MIT# Omalive