Free to scan. Pay for deeper care.
Checking a plugin before you run it should never cost anything. Pay when you want it automated or audited.
Pricing
Free
Beta$0forever
For anyone about to install a plugin. Live now in beta.
- Scan any public plugin or .jar link
- Full report with severity and fixes
- Shareable report links
Pro
Coming soonSoonpricing at launch
For networks that install a lot of plugins and can't check each update by hand.
- Scan your whole plugins folder at once
- Alerts when an update changes behaviour
- Discord alerts and scan history
- Team access
Developer
Coming soonSoonpricing at launch
For plugin authors who want to ship clean and prove it.
- Upload your codebase for a quick audit
- Private pre-release scans and CI checks
- Verified badge for clean releases
Upload your code, get an audit
For plugin developers. Upload your source or connect a GitHub repo and get a quick audit of security, performance and API use. Want a person to look too? Ask for a manual review by Simon Foy, a networking engineer and IT professional.
Upload or connect
Upload a zip of your source or connect a GitHub repo. Private repos stay private.
Automated review
Security, main-thread work, dependency vulnerabilities and deprecated API, checked across your whole codebase.
Report with fixes
Findings ranked by severity, pointing to the exact file and line, with the fix.
Optional manual review
A person reads the risky parts and talks you through what to change.
Pricing questions
Will scanning stay free?
Yes. Scanning public plugins and sharing reports is the free plan. Paid plans add automation, code audits and the badge.
When do Pro and Developer launch?
They're in progress. Join the Discord to hear first and help shape them.
How do I get a code audit?
Use the Request a code audit button and tell us about your plugin. During early access we'll reply by email.
Found something nasty in a plugin?
Don't run it. Bring the jar to the Discord, tell us where you got it, and we'll help you work out what it does.
Scan it before you run it.
It takes seconds and it's free. Better you find the backdoor than they use it.