Omahub
← All plugins
N

OmaLive Lock

by Nik

Omarchy lock screen that plays the OmaLive aerial footage behind the stock lock UI (macOS Sonoma style). Fork of omarchy.lock; enabling it disables the stock lock, removing it restores it.

Security review

Review recommended · 1 finding

Deterministic scan — not a security guarantee

Low
Risk level
Low
Analyzed commit
80e7eaf
Scanned
1 month ago

Flagged patterns appear only in documentation files (README / docs) — descriptive examples, not executable code.

  • Docs external_hosts README.md:29

    Downloads or connects to an external HTTP(S) host.

    git clone https://github.com/nikbos/OmaLiveLock ~/Projects/omalive/OmaLiveLock

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
80e7eaf
Reviewed
1 month ago

The plugin is a straightforward QML lock-screen enhancement that plays aerial footage behind the stock lock UI. The only deterministic finding is a `git clone` URL in the README, which is documentation and not executed by the plugin. No obfuscation, destructive commands, credential theft, or hidden persistence were found in the sampled source.

  • The README contains a `git clone` command pointing to an external host, but it is illustrative install documentation and not part of the plugin's executable code.
  • As with all Omarchy plugins, the code runs unsandboxed; however, the reviewed QML files only interact with the lock screen and the OmaLive service, with no system-level operations beyond standard Quickshell APIs.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/nikbos/OmaLiveLock --enable
System #Hyprland #quickshell

OmaLive Lock

The lock screen companion for OmaLive — plays the OmaLive aerial footage behind the stock Omarchy password UI (macOS Sonoma style). Fork of the first-party omarchy.lock; enabling it automatically disables the stock lock screen, and removing it restores the stock lock.

  • Continuity — locking resumes the aerial exactly where the wallpaper froze, it keeps drifting while locked, and on unlock the wallpaper parks on the exact frame the lock last showed.
  • Safe by design — the real lock stays on the ext-session-lock-v1 protocol with the stock PAM gate; when OmaLive is absent or a player fails, the view falls back to the stock blurred wallpaper. It never degrades to a black/broken surface.

Requirements

  • Omarchy 4 (Quickshell / Hyprland)
  • The OmaLive plugin for the aerial footage (https://github.com/nikbos/Omalive) — optional but recommended; without it the lock shows the stock blurred wallpaper.

Install

omarchy plugin add executes the plugin's code unsandboxed, so install from a reviewed local checkout — never from a moving remote URL:

git clone https://github.com/nikbos/OmaLiveLock ~/Projects/omalive/OmaLiveLock
git -C ~/Projects/omalive/OmaLiveLock checkout 9f160be35a0d15eede0f4cb0f63d9a4c1d20933d
# review the pinned commit, then add the local checkout:
omarchy plugin add ~/Projects/omalive/OmaLiveLock --enable
omarchy restart shell

Installing OmaLive via its install.sh also installs and enables this lock plugin automatically.

Locked? Avoid plugin commands while the session is locked — writing into the plugin folder hot-reloads the shell and tears down the active lock screen. Unlock first.

Removal

omarchy plugin remove omalive-lock
omarchy restart shell

Because this plugin declares omarchy.clonedFrom: omarchy.lock, removing it restores the stock Omarchy lock screen.

Development

Symlink the plugin folder to this checkout and restart the shell after edits:

ln -s /path/to/this/checkout ~/.config/omarchy/plugins/omalive-lock
omarchy restart shell

Never write into ~/.config/omarchy/plugins/ while the session is locked.

License

MIT