Omahub
← All plugins
U

OmaScan

by ucmz851

URL & domain threat scanner integrating urlscan.io and VirusTotal for Omarchy Quattro.

Security review

No obvious issues detected

Deterministic scan — not a security guarantee

None
Risk level
None
Analyzed commit
9bce322
Scanned
1 month ago

No potentially dangerous behavior detected in the analyzed commit.

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
9bce322
Reviewed
1 month ago

OmaScan is a legitimate threat-intelligence bar widget that queries urlscan.io and VirusTotal APIs. It stores API keys locally with chmod 600, avoids SSRF by never connecting to user-supplied targets, and does not execute arbitrary code. The only data exposure is the intended sending of user-initiated scan targets to third-party services.

  • The plugin reads the clipboard (via wl-paste) and sends its contents to external APIs, but only when the user explicitly triggers a clipboard scan.
  • API keys are stored in plaintext at ~/.config/omarchy/omascan.json, though file permissions are locked to 600.
  • Network requests are made to external services (urlscan.io, VirusTotal) as the core functionality; users should be aware their scan targets are shared with these providers.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/ucmz851/omascan --enable
System #system #security

OmaScan (ucmz851.omascan)

OmaScan is a lightning-fast, native threat intelligence scanner designed for the Omarchy Quattro desktop environment (omarchy-shell / Quickshell).

Powered by VirusTotal and urlscan.io, OmaScan lets you instantly inspect suspicious URLs, unknown domains, IP addresses, and file hashes directly from your top bar without having to visit dangerous websites or execute unverified files.


<p align="center"> <img src="preview.png" alt="OmaScan Preview" width="420" /> </p>

Installation & Removal

Installation

Install directly with the Omarchy plugin manager:

omarchy plugin add https://github.com/ucmz851/omascan.git --enable

Removal

To disable and remove the plugin from your system:

omarchy plugin remove ucmz851.omascan

Supported Target Types

Target Type Example What OmaScan Analyzes
Web URLs https://suspicious-login.com/auth Live sandbox crawl, screenshot, 90+ antivirus engines, phishing verdicts
Domains malicious-domain.xyz Domain reputation, web server stack, IP address, country, SSL details
IP Addresses 185.220.101.5 Geolocation, ASN / ISP, network owner, abuse detection, open ports
File Hashes (SHA-256) 275a021bbfb6489e54d471... Malware classification (Trojan, Ransomware), file name, size, vendor detections
File Hashes (MD5 / SHA-1) d41d8cd98f00b204e980... Antivirus engine signatures and file reputation

Free Default Mode vs Enhanced API Key Mode

OmaScan is designed to be 100% useful out of the box with zero setup, but also provides an optional Enhanced Mode if you add free personal API keys:

Feature Default Mode (No Keys Needed) Enhanced Mode (With Free API Keys)
Cost 100% Free 100% Free
Setup Required None (Works immediately) 60 seconds (Paste free key once)
Live Sandboxed Screenshots ✅ Yes (from urlscan.io cloud search) ✅ Yes + on-demand live browser crawls
TLS/SSL Health & Expiration ✅ Yes (Live probe with days remaining) ✅ Yes (Live probe with days remaining)
Server IP & Network ASN ✅ Yes (Live DNS & IP resolution) ✅ Yes (Live DNS & IP resolution)
Antivirus Vendor Breakdown Basic public threat reputation Full breakdown across 90+ Antivirus Engines (Google SafeBrowsing, Kaspersky, Microsoft Defender, BitDefender, Sophos, CrowdStrike)
Malware Family Names Basic detection Exact threat classifications (e.g. Trojan.Generic, Ransomware.LockBit)

How to Get Free API Keys (Optional)

Both VirusTotal and urlscan.io provide 100% free personal API keys:

1. Free VirusTotal API Key (500 free scans/day)

  1. Open virustotal.com/gui/join-us and create a free account (or sign in with Google).
  2. Click your profile avatar in the top right corner → click API key.
  3. Copy your key, open OmaScan's API Keys tab, paste it, and click Save API Keys.

2. Free urlscan.io API Key (5,000 free scans/month)

  1. Open urlscan.io/user/signup and register a free account.
  2. In the top navigation menu, click Settings → API Keys → click Create API Key.
  3. Copy your key, open OmaScan's API Keys tab, paste it, and click Save API Keys.

Privacy & Security

  • Safe Cloud Sandboxing: OmaScan queries safe cloud threat endpoints without performing unsafe direct host scraping of unverified destinations.
  • Local Network Isolation: Private and local IP destinations (127.0.0.1, localhost, 192.168.0.0/16, etc.) are recognized and safely isolated from external threat lookup queries.
  • 100% Local Storage: Your API keys and search history are stored exclusively on your local machine at ~/.config/omarchy/omascan.json.
  • Locked File Permissions (chmod 600): OmaScan strictly restricts configuration file permissions (-rw-------) so no other unprivileged process or user on your system can read your keys.
  • No Telemetry: OmaScan does not track users, log searches externally, or include analytics.

Controls & Shortcuts

Action How to Trigger
Open / Close Panel Left-click the globe icon (󰖟) on your top bar
Instant Clipboard Scan Middle-click the bar icon, or click the paste icon inside the panel
Scan Target Type or paste input and press Enter, or click the search icon
Clear Results Click the (Clear) button in the search bar
Switch Tabs Click Scan Results, History, or API Keys
Dismiss Panel Escape

File Structure

omascan/
├── BarWidget.qml       # Bar widget icon, dynamic color tinting, and tooltip
├── Panel.qml           # Anchored flyout panel with multi-target cards and tabs
├── manifest.json       # Omarchy Quattro plugin manifest (namespaced id: ucmz851.omascan)
├── LICENSE             # MIT License
├── README.md           # Documentation, usage guide, and API instructions
├── preview.png         # Marketplace preview thumbnail
├── screenshots/        # Additional UI screenshots
└── scripts/
    └── scanner.py      # Multi-target threat engine for VirusTotal & urlscan.io

License

MIT © ucmz851