Before you ask

The questions owners and developers ask before they hand over a jar or a codebase.

Does PluginDoctor run the plugin?

No. Scans are static: the jar is decompiled and read, never executed. That's what makes it safe to scan something you don't trust yet.

What happens to the jars I scan?

We don't keep them. The jar is read in memory and thrown away. We keep the report, filed under the file's fingerprint (its hash), so the next person who scans the same file gets the result instantly. Anyone with a report's link can view it, so treat the link like the file name: fine to share, not a secret.

What happens to my source code if I upload it for an audit?

It's designed to be used only for your audit and deleted afterwards. It's never shared, never published and never used to train anything. Private GitHub repos are read with access you can revoke at any time.

Does a clean scan mean a plugin is safe?

It means we found nothing suspicious, not that nothing could exist. Combined with a hash match against the official release, it's a strong signal. Still, only install plugins from authors and sites you trust.

I'm a plugin developer. What's in it for me?

Pre-release scans, a code audit of your whole project, and a verified badge for clean releases, so server owners can trust your plugin at a glance.

How is this different from ServerDoctor?

ServerDoctor checks a whole Minecraft server: network, config, permissions and performance. PluginDoctor goes deep on one thing, the plugins themselves. They work well together.

Is it free?

Yes. Scanning plugins and sharing reports is free. Pro for networks and the Developer plan with code audits will be paid.

Can I use it today?

Yes. The scanner is live in beta: paste a Modrinth, Hangar or GitHub link, or upload a .jar. SpigotMC links, code audits, the verified badge and Pro are coming soon.

STAT

Found something nasty in a plugin?

Don't run it. Bring the jar to the Discord, tell us where you got it, and we'll help you work out what it does.

Get help on Discord

Scan it before you run it.

It takes seconds and it's free. Better you find the backdoor than they use it.

Free · no signup · Modrinth, Hangar or GitHub link