Omahub
← All plugins
T

Virtual Keyboard

by thesimonharms

Toggle the wvkbd on-screen keyboard from the bar

Security review

Review recommended · 2 findings

Deterministic scan — not a security guarantee

Low
Risk level
Low
Analyzed commit
da82454
Scanned
3 weeks ago
  • Augments a command with octal/hex escape sequences.

    \x7fELF' ]] &&
  • Docs external_hosts README.md:35

    Downloads or connects to an external HTTP(S) host.

    git clone https://github.com/thesimonharms/omarchy-wvkbd-plugin.git

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
da82454
Reviewed
3 weeks ago

The plugin is a simple bar widget that toggles the wvkbd on-screen keyboard. The build script clones a pinned upstream commit, applies custom layout headers, and installs to the user's home directory without root. The flagged external host is just the upstream repository URL, and the ELF check is a legitimate sanity check. No malicious or suspicious behavior was found.

  • The build script downloads and compiles code from an external repository, but it is pinned to a specific commit and the resulting binary is verified as an ELF before installation.
  • The QML code includes input validation (safeBinary, safeLayers) to prevent command injection, which is good practice.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/thesimonharms/omarchy-wvkbd-plugin --enable
Productivity #system

Moved. This GitHub copy is an archive. Use the Forgejo repository.

Canonical repository: https://git.simonharms.com/thesimonharms/omarchy-wvkbd-plugin

omarchy-wvkbd-plugin

An Omarchy shell plugin that adds a bar widget for toggling wvkbd, a lightweight on-screen keyboard for Wayland. Useful for laptops with detachable keyboards.

The keyboard is a custom wvkbd build (wvkbd-pcintl) with a traditional PC-style layout:

Esc  F1  F2  F3  F4  F5  F6  F7  F8  F9  F10 F11 F12 Del
`    1   2   3   4   5   6   7   8   9   0   -   =   Bksp
Tab  q   w   e   r   t   y   u   i   o   p   [   ]   \
Caps a   s   d   f   g   h   j   k   l   ;   '   Enter
Shift    z   x   c   v   b   n   m   ,   .   /     Shift
Ctrl Super Alt         Space        AltGr ←  ↑  ↓  →

The widget shows a keyboard icon in the bar:

  • Click to show/hide the on-screen keyboard
  • The icon highlights while the keyboard is running

Requirements

  • Omarchy (or any Hyprland + Quickshell setup using the Omarchy shell)
  • The custom wvkbd-pcintl binary. Build and install it to ~/.local/bin as your user (no root, no pkexec):
git clone https://github.com/thesimonharms/omarchy-wvkbd-plugin.git
cd omarchy-wvkbd-plugin/wvkbd-pcintl
./build.sh

~/.local/bin must be on your PATH.

Install

omarchy plugin add https://github.com/thesimonharms/omarchy-wvkbd-plugin.git --enable --yes

This clones the plugin into ~/.config/omarchy/plugins/omarchy-wvkbd/, enables it, and adds it to your bar (right section by default). If the widget doesn't appear immediately, restart the shell:

omarchy restart shell

Configuration

Settings are overrides on the layout entry in ~/.config/omarchy/shell.json:

{
  "id": "omarchy-wvkbd",
  "height": 500
}
  • height — landscape keyboard height in pixels (default 400)
  • layers — wvkbd layer(s), comma-separated (default full, the PC-style layout). The custom build only contains this one layer.
  • binary — wvkbd variant to launch. Default is wvkbd-pcintl (the custom PC layout build). Set to wvkbd-mobintl for the stock AUR package with its phone-style layouts (omarchy pkg aur add wvkbd provides it).

Uninstall

omarchy plugin remove omarchy-wvkbd --yes

This removes the plugin from ~/.config/omarchy/plugins/omarchy-wvkbd/, unloads it from the running shell, and drops it from your bar layout (shell.json keeps an automatic backup of the removed copy).

Remove the keyboard binary if you installed it with build.sh:

rm -f ~/.local/bin/wvkbd-pcintl

License

MIT