Configuration
config.yml reference #
| Key | Default | Meaning |
|---|---|---|
language | en | Language of all messages and finding explanations: en, tr, es, de, fr, or ru. Finding explanations use the same language; codes and severities stay English. |
auto-scan-on-startup | true | Run a full scan automatically a few seconds after the server finishes starting. |
auto-scan-delay-seconds | 5 | How long to wait after startup before the automatic scan runs. |
report.save-to-file | true | Save every scan's full report to plugins/PluginGuard/reports/. |
report.default-format | txt | Format used for the auto-saved report file: txt, json, yaml, md, or html. |
report.keep-last | 30 | Number of saved reports to keep in plugins/PluginGuard/reports/; older ones are deleted. 0 keeps all. |
discord-webhook-url | (blank) | If set, PluginGuard posts a short message to this Discord webhook when a scan finds CRITICAL issues. Blank = disabled, nothing is ever sent unless you set this yourself. |
show-optional-dependencies | false | Chat and console lists leave out the notes about missing optional dependencies (MISSING_SOFT_DEPENDENCY), which are normal on almost every server; a line tells how many were left out. The saved report and /pluginguard export always contain them. true = list them everywhere. |
discord-only-new-findings | true | Announce only critical findings that were not announced before (remembered in discord-state.txt). false = announce on every scan that has critical findings. |
integrations.plugin-updates.enabled | false | Looks up newer versions of your plugins (UPDATE_AVAILABLE, info level). See "Update check" below for what each source can and cannot recognise. |
integrations.plugin-updates.modrinth | true | With the update check on: identify plugins on Modrinth by file hash. Sends the SHA-1 hash of every plugin jar and your Minecraft version to api.modrinth.com on each scan - nothing else. |
integrations.plugin-updates.spigotmc | true | With the update check on: look up plugins that name their spigotmc.org page as website in plugin.yml (through the public Spiget mirror). Only the resource number is sent. |
integrations.plugin-updates.builtbybit-api-token | (blank) | Your own BuiltByBit "Shared" API token. With it, plugins that link their builtbybit.com page in plugin.yml are checked too. Blank = BuiltByBit is skipped. |
ignore | [] | A list of "CODE:PluginName" (or "CODE:*" / "*:PluginName") rules to permanently silence specific findings you've reviewed and are fine with. |
checks.* | all true | Turn off an entire category of check if it doesn't apply to your setup: java-version, api-version, dependencies, shaded-library-collision, native-library-duplicate, sqlite-jni-relocation, command-collision, bundled-server-api, loaded-state. |
integrations.update-checker.* | disabled | Optional BuiltByBit update notification - needs your own "Shared" API token, never a Private one. |
Update check #
Turn it on with integrations.plugin-updates.enabled: true. Every scan then ends with a line saying how many of your plugin jars could be matched, and each outdated plugin gets an UPDATE_AVAILABLE finding with a link.
What can be matched, and what cannot:
- Modrinth: exact match by file hash. Any plugin (and exact file) published on Modrinth is recognised.
- SpigotMC and BuiltByBit: there is no way to identify a jar by its file, and PluginGuard never guesses plugins by name (a wrong guess would report an "update" for a different plugin). A plugin is only checked when its own
plugin.ymlcontains awebsite:link to its spigotmc.org or builtbybit.com page. Plugins that do not list one - many do not - stay unchecked, and so do plugins that are not published on any of these sites (for example ones sold elsewhere). - Version numbers are compared as numbers (1.9 is older than 1.10). Versions that cannot be read as numbers are never reported.
- These sites do not tell which Minecraft versions an update supports, so read the plugin's page before updating.
- Answers from SpigotMC and BuiltByBit are cached for a few hours; a scan makes at most 40 such requests and gives up after about 25 seconds. Plugin jars are never uploaded anywhere.
Languages #
Findings, command messages and exported reports use the language from config.yml (en, tr, es, de, fr, ru). Finding codes (for example SQLITE_JNI_RELOCATED) and severities always stay in English so that ignore rules, support requests and search results look the same on every server. Every finding says what is wrong, when it matters and what to do about it. You can edit the texts in plugins/PluginGuard/lang/; a text that is missing in your file is taken from the copy inside the jar.