Everything PluginDoctor examines

Two sides of the same problem. Server owners find out whether a jar is safe before they run it. Developers find the problems before they ship.

Backdoors & malware

Know what a plugin really does

Malicious plugins look normal until someone types the right phrase. PluginDoctor reads every class for the behaviour that matters: operator grants, remote code loading, outbound connections, token theft and file deletion.

  • Hidden commands and chat triggers that grant operator
  • Code downloaded and run after install
  • Outbound connections, file wipes and credential theft
plugindoctor scan
> plugindoctor scan AuctionPlus-4.2.jar
       Decompiling 214 classes…
[ OK ] file access        plugins/AuctionPlus only
[ OK ] outbound traffic   api.auctionplus.example (declared)
[HIGH] u/Loader           URLClassLoader → remote host
[CRIT] ChatListener       setOp(true) on hidden chat phrase
       1 critical, 2 high. Full report: plugindoctor.gg/r/9F2A

Integrity

Make sure it's the real release

Leaked and cracked plugins are the most common way malware reaches a server. Every jar is hashed and compared against the author's official builds, so a modified copy can't pass as the original.

  • Hash match against Modrinth, Hangar, SpigotMC and GitHub releases
  • Extra or modified classes compared to the official build
  • Obfuscation measured and located

plugins/ · integrity

JarVersionStatus
AuctionPlus-4.2.jar4.2Critical Hash mismatch
QuickWarps-3.1.0.jar3.1.0 → 3.4.2High Known exploit
MegaKits-1.9.jar1.9 → 2.3Medium Outdated
TabHeaders-1.2.jar1.2 Official build
ChatFilter-5.0.1.jar5.0.1 Official build

Plugin names are fictional sample data.

Performance

Find the lag before you ship it

For developers: PluginDoctor finds the work that blocks the tick thread, such as database calls, file I/O, web requests and heavy listeners, and points to the exact method, with the async fix.

  • Blocking I/O and network calls on the main thread
  • Hot event listeners and scheduled tasks
  • Upload your codebase for a deeper audit

Main-thread analysis · test server, 50 players

Tick cost6.4 ms

Worst spike41 ms

Hotspots

  • SqlStore.onQuit()blocking JDBC41 ms
  • PriceTask.run()every tick2.1 ms
  • MoveListener.onMove()no early return1.4 ms

Dependencies & API

Ship on solid ground

Old shaded libraries carry old vulnerabilities, and deprecated API breaks on the next Minecraft update. PluginDoctor checks both and tells you which server versions your plugin will actually run on.

  • Shaded libraries with known vulnerabilities
  • Deprecated and removed Bukkit and Paper API
  • Real compatibility across Paper and Spigot versions

dependencies & API

  • commons-collections 3.2.1known deserialisation CVECritical
  • gson 2.2.4 (shaded)outdatedMedium
  • AsyncPlayerChatEventdeprecated on PaperLow
  • plugin.yml api-versionmissingMedium
  • paper-apiruns on 1.20 – 1.21OK

What the free scan checks

Paste a link or a jar. Nothing is installed or run; the jar is taken apart and read.

Official release match
Compared against the author's builds on Modrinth, Hangar, SpigotMC and GitHub.
Known malware
Signatures of known Minecraft plugin malware and injected loaders.
Suspicious behaviour
Operator grants, remote code loading, file deletion and outbound connections.
Obfuscation
How much of the jar is deliberately hidden, and where.
Dependencies
Shaded libraries and their known vulnerabilities.
Compatibility
Declared API version and the server versions it will actually run on.

Developers can verify they own a plugin to unlock private pre-release scans, code audits and the verified badge.

Scan it before you run it.

It takes seconds and it's free. Better you find the backdoor than they use it.

Free · no signup · Modrinth, Hangar or GitHub link