Free to scan. Pay for deeper care.

Checking a plugin before you run it should never cost anything. Pay when you want it automated or audited.

Pricing

  • Free

    Beta

    $0forever

    For anyone about to install a plugin. Live now in beta.

    • Scan any public plugin or .jar link
    • Full report with severity and fixes
    • Shareable report links
    Scan a plugin
  • Pro

    Coming soon

    Soonpricing at launch

    For networks that install a lot of plugins and can't check each update by hand.

    • Scan your whole plugins folder at once
    • Alerts when an update changes behaviour
    • Discord alerts and scan history
    • Team access
    Get notified on Discord
  • Developer

    Coming soon

    Soonpricing at launch

    For plugin authors who want to ship clean and prove it.

    • Upload your codebase for a quick audit
    • Private pre-release scans and CI checks
    • Verified badge for clean releases
    Request a code audit

Upload your code, get an audit

For plugin developers. Upload your source or connect a GitHub repo and get a quick audit of security, performance and API use. Want a person to look too? Ask for a manual review by Simon Foy, a networking engineer and IT professional.

  1. Upload or connect

    Upload a zip of your source or connect a GitHub repo. Private repos stay private.

  2. Automated review

    Security, main-thread work, dependency vulnerabilities and deprecated API, checked across your whole codebase.

  3. Report with fixes

    Findings ranked by severity, pointing to the exact file and line, with the fix.

  4. Optional manual review

    A person reads the risky parts and talks you through what to change.

Request a code audit

Pricing questions

Will scanning stay free?

Yes. Scanning public plugins and sharing reports is the free plan. Paid plans add automation, code audits and the badge.

When do Pro and Developer launch?

They're in progress. Join the Discord to hear first and help shape them.

How do I get a code audit?

Use the Request a code audit button and tell us about your plugin. During early access we'll reply by email.

STAT

Found something nasty in a plugin?

Don't run it. Bring the jar to the Discord, tell us where you got it, and we'll help you work out what it does.

Get help on Discord

Scan it before you run it.

It takes seconds and it's free. Better you find the backdoor than they use it.

Free · no signup · Modrinth, Hangar or GitHub link