Omahub
← All plugins
T

Proton VPN

by Tharin Fernando

Proton VPN status, connect/disconnect, and server info in the Omarchy bar.

Security review

No obvious issues detected

Deterministic scan — not a security guarantee

None
Risk level
None
Analyzed commit
3d1fc33
Scanned
1 month ago

No potentially dangerous behavior detected in the analyzed commit.

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
3d1fc33
Reviewed
1 month ago

The plugin is a well-structured QML/JavaScript bar widget that wraps the official Proton VPN CLI. It invokes standard commands (protonvpn, nmcli, notify-send, wl-copy, cat /proc/net/dev) with no obfuscation, no network exfiltration, and no destructive operations. The only minor concerns are that it executes a privileged VPN CLI on user actions and reads /proc/net/dev, which are expected for its stated purpose.

  • Executes `protonvpn connect/disconnect/status` and `nmcli` commands, which is expected functionality but means the plugin has control over VPN state.
  • Reads `~/.cache/Proton/VPN/serverlist.json` and parses it; a malicious or compromised server list could potentially inject data, though it is only rendered as text.
  • Uses `notify-send` and `wl-copy` if present; these are standard utilities and not a risk by themselves.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/tharinfernando/omarchy-protonvpn --enable
Widgets #bar #security

Proton VPN Omarchy bar widget

Status and one-click fastest-server connection for Proton VPN in the menu bar.

Proton VPN widget preview

Features

  • Bar icon: theme-colored Proton VPN mark with connected/disconnected state.
  • Details panel with:
    • Connected server and location
    • Server load and protocol
    • Session uptime ("Connected for 2h 13m")
    • Live download/upload rates
    • Tunnel IP
    • Collapsible list of free-server countries (click the header or press s)
    • Refresh action
  • Desktop notifications when the VPN connects, disconnects, or a command fails (goes through the shell's notification daemon, so do-not-disturb applies).
  • Left click opens the panel. The panel's on/off switch responds to the click instantly (optimistically) and reconciles with the real VPN state.
  • Right click connects to the fastest eligible Proton server or disconnects.
  • Middle click refreshes status.
  • Keyboard navigation: j/k, enter, t, c, s, r, and esc.

Backend

This plugin uses Proton's official Linux CLI. It does not use wg-quick, static WireGuard files, downloaded server configs, or custom DNS commands.

protonvpn connect       # fastest eligible server
protonvpn disconnect
protonvpn status

The official CLI performs server selection, NetworkManager setup, DNS, and firewall handling. On a Free plan, Proton selects the fastest available free server. The GUI and CLI cannot run simultaneously; close protonvpn-app before using the bar toggle with this backend.

Requirements

  • proton-vpn-cli installed and signed in
  • wl-copy for copy actions
  • notify-send for desktop notifications (disable with the notificationsEnabled setting if it is not installed)

Install the official Arch package with:

omarchy pkg add proton-vpn-cli
protonvpn signin

Setup

ln -s "$(pwd)" ~/.config/omarchy/plugins/tharin.protonvpn
omarchy plugin enable tharin.protonvpn
omarchy bar move tharin.protonvpn --section right

The shell hot-reloads changes. Force discovery if needed:

omarchy-shell shell rescanPlugins

Settings

Key Type Default Meaning
refreshIntervalSec integer 30 CLI status poll interval
notificationsEnabled boolean true Desktop notifications on connect/disconnect/failure

Set it with:

omarchy bar set tharin.protonvpn refreshIntervalSec 30

Removal

omarchy plugin disable tharin.protonvpn
rm ~/.config/omarchy/plugins/tharin.protonvpn   # symlink or copied folder

To also uninstall the CLI dependency:

omarchy pkg drop proton-vpn-cli