What it does not do
Scope #
Being upfront about scope is part of doing this right:
- It does not detect runtime conflicts that only show up from actual behavior (e.g. two plugins both cancelling the same event in incompatible ways). Those require live testing, not static analysis.
- Command-collision detection only sees commands declared the classic way, in
plugin.yml'scommands:section. Paper plugins that register commands dynamically at runtime (via the Brigadier lifecycle API) aren't visible to a static scan and won't be flagged. - It is not a malware/virus scanner - it checks structural compatibility facts, not plugin intent or behavior.
- The
PLUGIN_*findings compare the jars with the server's plugin list at the moment of the scan. The automatic startup scan runs after the server finished starting, so they are meaningful there; a plugin added to the folder while the server is running is reported as not loaded until the next restart. SHADED_LIBRARY_COLLISIONfindings are a heads-up, not proof of an actual bug - Paper's per-plugin classloader isolation means most of these are completely harmless in practice.