BetaThe scanner is live. Code audits and Pro are coming soon.Join the Discord

The checkup for Minecraft plugins.

PluginDoctor finds the backdoor, the leaked build and the main-thread lag before a plugin reaches your server, or before you ship it.

Free · no signup · Modrinth, Hangar or GitHub link

plugindoctor.gg/scan/AuctionPlus-4.2.jarExample report
Patient
AuctionPlus-4.2.jar
Method
Static scan + hash check
Ref
PD-9F2A

Safety score

18 out of 100

Do not install

FindingResultExpectedFlag
DependenciesBundles an old Gson2.2.4≥ 2.10Low
PerformanceSaves to MySQL on main threadsyncasyncMedium
IntegrityHeavily obfuscated classes61%< 5%Medium
IntegrityJar doesn't match official 4.2unknownmatchHigh
BehaviourDownloads code at runtimeyesneverHigh
BackdoorHidden op on chat triggersetOpnoneCritical

The usual suspects

Most plugin disasters start with one of these. We look for all of them.

  • Backdoors

    A hidden command or chat trigger that quietly hands operator to someone you've never met.

    Caught by Scan

  • Leaked and cracked builds

    Jars that don't match the author's release, usually with something extra injected.

    Caught by Scan

  • Remote code loading

    Plugins that download and run code after you've installed them, so what you scanned isn't what runs.

    Caught by Scan

  • Vulnerable dependencies

    Old shaded libraries with known exploits, and plugins that haven't been updated in years.

    Caught by Scan + code audit

  • Main-thread lag

    Database calls, file I/O and web requests on the tick thread, the classic cause of mystery lag.

    Caught by Code audit

From jar to verdict in three steps

  1. Triage: Paste a link or drop a jar

    Point PluginDoctor at a Modrinth, Hangar or SpigotMC page, a .jar download, or a GitHub repo. Nothing gets installed and nothing runs on your server.

  2. Examine: We take it apart

    The jar is decompiled and analysed without being run: hashes against official releases, known malware patterns, suspicious behaviour, dependencies and main-thread work.

  3. Prescribe: Get the verdict and the fixes

    A shareable report with a safety score and findings ranked by severity. Owners learn whether to install it. Developers get the exact class and the fix.

The scanner is live in beta. Code audits are coming soon. Join the Discord to help shape it.

Watch it catch a backdoor

Three files from a fictional leaked plugin. The scan reads each one line by line, flags what's wrong, and shows the fix.

Sample code. The plugin is fictional.

One report. Exactly what's inside the jar.

Every scan ends in a shareable report. Findings are ranked Critical to Low, point to the exact class and method, and come with a fix in plain English.

plugindoctor.gg/r/9F2AExample report: sample data

Findings

CriticalA hidden chat trigger grants operator to anyone who knows it

com/auctionplus/listeners/ChatListener.class · onChat()

Result
setOp(true) on a hard-coded phrase
Expected
no operator changes

When a player sends a specific phrase in chat, the plugin cancels the message and makes that player an operator. The phrase isn't documented anywhere. This is a backdoor.

Prescription

  1. Don't install this jar. If it's already installed, stop the server and delete it.
  2. Check ops.json and your permissions plugin for accounts you don't recognise.
  3. Change your RCON and panel passwords, then download the plugin again from its official page.
HighDownloads and runs code from a remote server

com/auctionplus/u/Loader.class · init()

Result
URLClassLoader from a remote host
Expected
no remote code

On startup the plugin fetches a class file from an external address and loads it. Whatever that server sends is what runs, and it can change at any time.

Prescription

  1. Treat the plugin as compromised and remove it.
  2. Report the jar to the site you downloaded it from.
HighThe jar doesn't match the official 4.2 release

AuctionPlus-4.2.jar · sha256

Result
unknown hash
Expected
matches official build

None of the author's published builds have this hash, and it contains classes that aren't in the real release. That's the usual sign of a leaked or cracked copy.

Prescription

  1. Get the plugin from the author's official page or a trusted platform.
  2. Re-scan the new jar to confirm it matches.
MediumSaves player data to MySQL on the main thread

com/auctionplus/storage/SqlStore.class · onQuit()

Result
blocking JDBC call
Expected
async

Every time a player leaves, the server waits for the database. With a slow database or a busy server that's a visible lag spike. (For developers: this one's yours to fix.)

Prescription

  1. Move the save into Bukkit.getScheduler().runTaskAsynchronously(...).
  2. Use a connection pool such as HikariCP instead of opening a connection per save.

+ 4 more findings

Scanning is free.

Scanning plugins and sharing reports is free, and live now in beta. Pro for networks and the Developer plan, with code audits and the verified badge, are coming soon.

  • Free$0Beta
  • ProSoonComing soon
  • DeveloperSoonComing soon
See pricing

Who's behind the diagnosis

Built by

Simon Foy

Networking engineer and IT professional

I design, run and troubleshoot networks for a living. PluginDoctor exists because one bad plugin can undo everything else you've done to secure a server. It's the sister tool to ServerDoctor.

simonfoy.com
STAT

Found something nasty in a plugin?

Don't run it. Bring the jar to the Discord, tell us where you got it, and we'll help you work out what it does.

Get help on Discord

Scan it before you run it.

It takes seconds and it's free. Better you find the backdoor than they use it.

Free · no signup · Modrinth, Hangar or GitHub link