What it does not do

Scope #

Being upfront about scope is part of doing this right:

  • It does not detect runtime conflicts that only show up from actual behavior (e.g. two plugins both cancelling the same event in incompatible ways). Those require live testing, not static analysis.
  • Command-collision detection only sees commands declared the classic way, in plugin.yml's commands: section. Paper plugins that register commands dynamically at runtime (via the Brigadier lifecycle API) aren't visible to a static scan and won't be flagged.
  • It is not a malware/virus scanner - it checks structural compatibility facts, not plugin intent or behavior.
  • The PLUGIN_* findings compare the jars with the server's plugin list at the moment of the scan. The automatic startup scan runs after the server finished starting, so they are meaningful there; a plugin added to the folder while the server is running is reported as not loaded until the next restart.
  • SHADED_LIBRARY_COLLISION findings are a heads-up, not proof of an actual bug - Paper's per-plugin classloader isolation means most of these are completely harmless in practice.