PluginGuard

Find compatibility problems before your server does.

ReleasedPaidOperations

Scans every jar in plugins/ at the bytecode level and reports Java mismatches, missing dependencies, broken shaded libraries and command collisions.

  • Paper
  • Spigot
  • Folia

Features

  • Reads the real bytes of every jar: class-file version, descriptors, shaded libraries and native binaries. Nothing is executed or modified.
  • Catches a plugin compiled for a newer Java than your server runs, before it fails with UnsupportedClassVersionError.
  • Finds a relocated SQLite driver, missing hard dependencies, circular dependencies and duplicate plugins.
  • Reports in txt, json, yaml, md or html; a fix list ordered by severity; ignore rules for findings you reviewed.
  • Optional Discord alert for critical findings; each finding is announced once.

Usage example

Scan every jar, list what needs fixing and export the report.

text
/pluginguard scan
/pluginguard fixlist
/pluginguard export html

Requirements and compatibility

Platforms
Paper, Spigot, Folia
Minecraft
1.21 to 1.21.11, 26.1, 26.2
Java
21
Required
None
Optional
None
Category
Operations
Documented version
1.2.1

The documentation describes version 1.2.1.

Limitations

  • It does not detect runtime conflicts that only appear from behaviour.
  • Commands registered at runtime through Brigadier are not visible to a static scan.
  • It is not a malware scanner.

Frequently asked questions

Does it send anything anywhere?

Only if you turn it on. The optional update check and the Discord webhook are off until you configure them.

Can it break my plugins?

No. It only reads jars and never changes them.

Changelog

Version 1.2.1

  • Defined the supported Minecraft range as 1.21 through 1.21.11, plus 26.1 and 26.2.
  • Version parsing and API comparison verified for Minecraft 26.2.
  • Behaviour, configuration and saved reports stay compatible with 1.2.

Version 1.2

  • New /pluginguard fixlist: a numbered list of what needs fixing.
  • New ignore rules to silence reviewed findings without editing config.yml.
  • Discord alerts announce each critical finding once.
  • Optional update check (off by default): Modrinth by file hash; SpigotMC and BuiltByBit only for plugins that link their page.
  • Descriptors are read the way the server reads them; text taken from jars is sanitised in chat, console and exports.

Support

Ask in the Discord or in the plugin's discussion area on BuiltByBit.

Get PluginGuard

Purchases, downloads and updates are handled by BuiltByBit.

More plugins

VeloRoad

Operations

Replace a plugin live. Roll back automatically.

Awaiting approvalPaid
  • Spigot
  • Paper
  • Purpur
  • Folia
Coming soonView details

Migrate

Operations

Switch plugins, keep your data.

Coming soon
  • Announced with the release
Coming soonView details