Omahub
← All plugins
R

WireGuard

by Remco

WireGuard VPN status icon with a details panel and .conf import

Security review

No obvious issues detected

Deterministic scan — not a security guarantee

None
Risk level
None
Analyzed commit
0bbe737
Scanned
1 month ago

No potentially dangerous behavior detected in the analyzed commit.

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

None
AI risk level
None
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
0bbe737
Reviewed
1 month ago

The plugin is a straightforward WireGuard status widget that runs user-level commands via nmcli, ip, and ping. All scripts are transparent, well-commented, and include appropriate safeguards (output caps, input validation, no sudo). No malicious behavior, hidden persistence, or destructive actions were found.

How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/r3mcos3/remco.wireguard --enable
System #bar #system #security

WireGuard

A WireGuard VPN status icon for the Omarchy bar. Click it to open a details panel with connection state, ping/packet-loss, live throughput, IP address and endpoint — the same kind of at-a-glance info as the built-in network panel, just for a WireGuard tunnel instead of Wi-Fi/Ethernet.

No wg0 NetworkManager connection yet? The panel swaps in an in-panel file browser so you can import a .conf without leaving the bar.

Screenshots

<p> <img src="assets/panel-connected.png" alt="Details panel while connected, showing ping, packet loss, throughput, IP address and endpoint" width="360"> <img src="assets/panel-import.png" alt="In-panel .conf file browser shown when no wg0 profile exists yet" width="360"> </p>

Features

  • Status icon that reflects the real wg0 connection state, polled every 5s regardless of whether the panel is open.
  • Details panel: ping/packet-loss (rolling 10-sample window), live download/upload throughput, total bytes transferred, tunnel IP, and peer endpoint.
  • One-click connect/disconnect toggle that reacts as soon as NetworkManager has actually applied the change — no polling delay.
  • In-panel .conf import with a plain directory browser (no external file-dialog tool required) for when no profile exists yet.
  • Autoconnect is an explicit opt-in, off by default. Importing a profile never silently sets it up to connect on every boot unless you turn on "Connect automatically at startup" for that import.
  • Remove profile, with a confirmation prompt, to delete the wg0 connection and start over without touching a terminal.

Dependencies

All of these ship with Omarchy itself, so there is nothing extra to install:

  • nmcli (networkmanager) — reads/toggles/imports the wg0 connection. Listed in omarchy-base.packages, so every Omarchy install has it.
  • jq — JSON glue between the shell scripts and the QML widget. Also listed in omarchy-base.packages.
  • ip (iproute2) — interface state and IP address. A hard dependency of networkmanager itself.
  • ping (iputils) — latency/packet-loss through the tunnel. Part of Arch's base package group.

No wireguard-tools (wg/wg-quick) and no file-dialog tool (zenity/kdialog/etc.) are used — NetworkManager talks to the kernel WireGuard module directly, and the "no profile yet" import browser is a plain script + Process, not a native dialog.

The helper scripts in scripts/ ship inside this repo and are invoked by path relative to the plugin's own install directory (~/.config/omarchy/plugins/remco.wireguard/scripts/...) — nothing is expected to already exist elsewhere on your system. Every script output that reaches the panel is size-capped (directory listings, nmcli error text, endpoint) and every dynamic string rendered in the UI is displayed as plain text, never interpreted as rich text/HTML.

Privilege boundary

Every command runs as your own user through NetworkManager's D-Bus API (nmcli) — no sudo. Whether creating or importing a connection profile needs a polkit prompt depends on your system's polkit rules; on a default Omarchy install the active local user can usually do this without one.

Setup

Nothing to configure up front. If you don't have a wg0 NetworkManager connection yet, open the panel and use the file browser to pick a WireGuard .conf — it gets imported and renamed to wg0 automatically. Before picking a file, you can turn on "Connect automatically at startup" if you want this particular profile to come up on every boot; leave it off (the default) to keep the tunnel fully manual.

Install

omarchy plugin add https://github.com/r3mcos3/remco.wireguard.git --enable

Usage

Click the icon to open the details panel. Use the toggle to connect or disconnect. If no profile exists yet, browse to and click a .conf file to import it.

To start over with a different profile, use "Remove profile" at the bottom of the panel (asks for confirmation first) — this deletes the wg0 NetworkManager connection only, not the original .conf file, and the panel falls back to the import browser.

Configure

omarchy bar move remco.wireguard --section right

Uninstall

omarchy plugin remove remco.wireguard

Uninstalling the plugin does not touch the wg0 NetworkManager connection itself — your VPN profile stays intact. Use "Remove profile" in the panel (see Usage) if you want the connection gone too.