The checkup for Minecraft plugins.
PluginDoctor finds the backdoor, the leaked build and the main-thread lag before a plugin reaches your server, or before you ship it.
- Patient
- AuctionPlus-4.2.jar
- Method
- Static scan + hash check
- Ref
- PD-9F2A
Safety score
18 out of 100
Do not install
| Finding | Result | Expected | Flag |
|---|---|---|---|
| DependenciesBundles an old Gson | 2.2.4 | ≥ 2.10 | Low |
| PerformanceSaves to MySQL on main thread | sync | async | Medium |
| IntegrityHeavily obfuscated classes | 61% | < 5% | Medium |
| IntegrityJar doesn't match official 4.2 | unknown | match | High |
| BehaviourDownloads code at runtime | yes | never | High |
| BackdoorHidden op on chat trigger | setOp | none | Critical |
The usual suspects
Most plugin disasters start with one of these. We look for all of them.
Backdoors
A hidden command or chat trigger that quietly hands operator to someone you've never met.
Caught by Scan
Leaked and cracked builds
Jars that don't match the author's release, usually with something extra injected.
Caught by Scan
Remote code loading
Plugins that download and run code after you've installed them, so what you scanned isn't what runs.
Caught by Scan
Vulnerable dependencies
Old shaded libraries with known exploits, and plugins that haven't been updated in years.
Caught by Scan + code audit
Main-thread lag
Database calls, file I/O and web requests on the tick thread, the classic cause of mystery lag.
Caught by Code audit
From jar to verdict in three steps
Triage: Paste a link or drop a jar
Point PluginDoctor at a Modrinth, Hangar or SpigotMC page, a .jar download, or a GitHub repo. Nothing gets installed and nothing runs on your server.
Examine: We take it apart
The jar is decompiled and analysed without being run: hashes against official releases, known malware patterns, suspicious behaviour, dependencies and main-thread work.
Prescribe: Get the verdict and the fixes
A shareable report with a safety score and findings ranked by severity. Owners learn whether to install it. Developers get the exact class and the fix.
The scanner is live in beta. Code audits are coming soon. Join the Discord to help shape it.
Watch it catch a backdoor
Three files from a fictional leaked plugin. The scan reads each one line by line, flags what's wrong, and shows the fix.
Sample code. The plugin is fictional.
One report. Exactly what's inside the jar.
Every scan ends in a shareable report. Findings are ranked Critical to Low, point to the exact class and method, and come with a fix in plain English.
Findings
CriticalA hidden chat trigger grants operator to anyone who knows it
com/auctionplus/listeners/ChatListener.class · onChat()
- Result
- setOp(true) on a hard-coded phrase
- Expected
- no operator changes
When a player sends a specific phrase in chat, the plugin cancels the message and makes that player an operator. The phrase isn't documented anywhere. This is a backdoor.
Prescription
- Don't install this jar. If it's already installed, stop the server and delete it.
- Check ops.json and your permissions plugin for accounts you don't recognise.
- Change your RCON and panel passwords, then download the plugin again from its official page.
HighDownloads and runs code from a remote server
com/auctionplus/u/Loader.class · init()
- Result
- URLClassLoader from a remote host
- Expected
- no remote code
On startup the plugin fetches a class file from an external address and loads it. Whatever that server sends is what runs, and it can change at any time.
Prescription
- Treat the plugin as compromised and remove it.
- Report the jar to the site you downloaded it from.
HighThe jar doesn't match the official 4.2 release
AuctionPlus-4.2.jar · sha256
- Result
- unknown hash
- Expected
- matches official build
None of the author's published builds have this hash, and it contains classes that aren't in the real release. That's the usual sign of a leaked or cracked copy.
Prescription
- Get the plugin from the author's official page or a trusted platform.
- Re-scan the new jar to confirm it matches.
MediumSaves player data to MySQL on the main thread
com/auctionplus/storage/SqlStore.class · onQuit()
- Result
- blocking JDBC call
- Expected
- async
Every time a player leaves, the server waits for the database. With a slow database or a busy server that's a visible lag spike. (For developers: this one's yours to fix.)
Prescription
- Move the save into Bukkit.getScheduler().runTaskAsynchronously(...).
- Use a connection pool such as HikariCP instead of opening a connection per save.
+ 4 more findings
A full examination, inside and out
Four checks, one report. For the people running plugins and the people writing them.
- Backdoors & malwareHidden op grants, remote code, token theft and file wipers.
- IntegrityHash-checked against official releases on every major platform.
- PerformanceMain-thread I/O, heavy listeners and runaway scheduled tasks.
- Dependencies & APIVulnerable libraries, deprecated API and version compatibility.
Found something nasty in a plugin?
Don't run it. Bring the jar to the Discord, tell us where you got it, and we'll help you work out what it does.
Scan it before you run it.
It takes seconds and it's free. Better you find the backdoor than they use it.