Trust Center

Clear facts behind every plugin

Current network behaviour, storage, licence details and build evidence, reviewed against the shipped documentation and implementation.

Principles

Four rules this page is held to.

  • Data stays on your side

    Settings and plugin data are kept in files or in a database you run. The connections that leave your server are listed per plugin below.

  • Optional means optional

    Every optional connection is marked as on or off by default. Integrations absent from the inspected implementation are marked “None”.

  • Evidence with its limits

    Recorded builds include the exact file hash, tested platforms, completed checks and the precise scope of the run.

  • Maintained release record

    VelorSTUDIO keeps the evidence tied to exact versions and refreshes the record whenever a release artifact changes.

This website

What the site you are reading does and does not do.

  • No analytics, advertising scripts, cookies or tracking pixels.
  • Your theme and language choice stay in your browser (local storage) and are never sent anywhere.
  • The site has no forms, accounts or file uploads. Nothing you type here is sent to a server.
  • The comparison and finder run entirely in your browser. Their choices appear in the address bar only so you can share a link.
  • Purchases and downloads happen only on BuiltByBit. This site never takes payment details.
  • The site is static files served by Cloudflare Pages. As with any host, ordinary request logs may exist on the host’s side; this site adds nothing on top.

Network access per plugin

The outbound connections present in each current plugin implementation and whether they start enabled or require configuration.

  • On by defaultActive unless you switch it off.
  • Optional, offOptional; does nothing until you configure it.
  • NoneDocumented as absent, or no such code was found in the inspected build.
Network access per plugin
PluginbStats metricsUpdate checkDiscord webhookDownloads at runtimeLicence server
CrossMenuOn by defaultNoneNoneNoneNone
BountyBoardNoneNoneNoneNoneNone
VelorJourneyNoneNoneOptional, offNoneNone
NewbieShieldOptional, offOn by defaultNoneNoneNone
ReferralTrackNoneOptional, offOptional, offNoneNone
PluginGuardNoneOptional, offOptional, offNoneNone
VelorFailoverNoneNoneNoneNoneNone
VeloRoadOn by defaultNoneOptional, offOptional, offNone
MigrateNoneNoneNoneNoneNone

Runtime downloads are absent unless the table marks them optional. VeloRoad can use only administrator-configured HTTPS sources, and that feature is off by default.

Storage and multi-server use

Where each plugin keeps its data, and whether its documentation describes sharing it between servers.

Storage and multi-server use
PluginStorageMulti-server
CrossMenuYAML files, Plugin-folder files; no database usedSingle-server operation; no shared-database or proxy mode
BountyBoardSQLiteSingle-server operation; no shared-database or proxy mode
VelorJourneySQLite, MySQL / MariaDBDocumented, through a shared MySQL/MariaDB database
NewbieShieldYAML files, SQLite, MySQL / MariaDBDocumented, through a shared MySQL/MariaDB database
ReferralTrackSQLite, MySQL / MariaDBDocumented, through a shared MySQL/MariaDB database
PluginGuardPlugin-folder files; no database usedSingle-server operation; no shared-database or proxy mode
VelorFailoverYAML files, Plugin-folder files; no database usedVelocity proxy plugin with an optional backend companion
VeloRoadPlugin-folder files; no database usedStages updates to servers on the same machine
MigrateSQLiteReads and writes supported plugin data across configured files and databases

Licence and watermark facts

Each current implementation was reviewed for local fingerprints, remote validation, startup blocking and activation checks.

Licence and watermark facts
PluginLicence and watermark
CrossMenuBuiltByBit download placeholders produce a one-way fingerprint that is logged locally for support. It never blocks startup and contacts no licence server (documented).
BountyBoardThe inspected implementation contains no watermark, licence check, remote activation or startup block.
VelorJourneyA one-way support fingerprint derived from BuiltByBit’s download value, shown by /journey version. No licence server; it never disables the server (documented).
NewbieShieldThe inspected implementation contains no watermark, licence check, remote activation or startup block.
ReferralTrackThe inspected implementation contains no watermark, licence check, remote activation or startup block.
PluginGuardThe inspected implementation contains no watermark, licence check, remote activation or startup block.
VelorFailoverThe inspected implementation contains no watermark, licence check, remote activation or startup block.
VeloRoadThe inspected implementation contains no watermark, licence check, remote activation or startup block.
MigrateThe inspected implementation contains no watermark, licence check, remote activation or startup block.

“Supported” is not “verified”

These are three different statements, and this site keeps them apart.

  • Declared support

    What the developer says the plugin supports: platforms, Minecraft range, Java. It comes from the documentation and is not a test result.

  • Tested on a named build

    A recorded run of one exact build on named server software and versions. It proves what was run and nothing wider.

  • Test scope stays precise

    Only versions that were actually executed count as verified; declared compatibility remains clearly separate from recorded runtime tests.

Build evidence

The exact file recorded for each version, what was run on it and what was not.

Hashes belong to the files the developer recorded for these versions. BuiltByBit may re-pack or personalise a download, so a downloaded copy can differ byte for byte.

Build evidence
PluginVersionRecorded buildRecordedWhat was run
CrossMenu
Awaiting approval
1.6.1 CrossMenu-1.6.1.jar · 1.58 MB25747C4FE069EAC6D529129A64406C744B67D27DA8A3EC8BF62C3A0C3CF54FB9 2026-10-07

Console checks 43/43 on each of: Paper 1.20.6, Paper 1.21.11, Paper 26.2, Purpur 1.21.11, Folia 1.21.11, Folia 26.2, Spigot 1.20.6, Spigot 1.21.11, CraftBukkit 1.20.6.

  • Console smoke checks
  • Packaging tests
  • Upgrade from the previous version
  • Geyser-only detection
  • HeadDB 6.1.1 detection
  • Real Java client session (owner-led, partial)
  • Package contents inspected

Outside this test record: a Bedrock client check on this exact build (an earlier build was checked on a real Bedrock client on 2026-10-05).

BountyBoard
Released
1.2 BountyBoard-1.2.jar · 132.0 KB5E6071464060AC023671C4D9DD4570E2F9D9D7E39B612DA861A316ACD46D756A 2026-10-06

Recorded artifact inspection; the runtime matrix is outside this release record.

  • Package contents inspected
VelorJourney
Awaiting approval
1.0 VelorJourney-1.0.jar · 14.58 MB7169E1BD5BB1D2311D8E38908E6064EDAD1E2A100E6722B6DA37471EB25F853F 2026-10-06

Console checks 43/43 on each of: Paper 1.21.11, Paper 26.2, Folia 1.21.11, Folia 26.2, Purpur 1.21.11.

  • Console smoke checks
  • Packaging tests
  • MariaDB 11.8.9 storage checks
  • Real Java client session (owner-led, partial)

Outside this test record: real Discord report delivery.

NewbieShield
Awaiting approval
1.2.2 NewbieShield-1.2.2.jar · 16.36 MB7F72E6ED83975E10C09ED577D89D18509ACF9D4DF4EE61DA0C838B98526A3E22 2026-10-07

Console checks 12/12 on each of: Paper 1.21.11, Paper 26.2, Folia 1.21.11, Folia 26.2.

  • Console smoke checks
  • Upgrade from the previous version
ReferralTrack
Awaiting approval
1.3.0 ReferralTrack-1.3.0.jar · 19.15 MB6B2BB78889A2A8AB66BE96CBDA7E6D97DBEEDBE78013F71022E0FF7BF34247A8 Date not recorded

Console checks 58/58 on each of: Paper 1.21.11, Spigot 1.21.11, Folia 26.2.

  • Console smoke checks
  • Packaging tests
  • Two-server MariaDB delivery (owner-led)
  • Real Vault and EssentialsX payout (owner-led)
  • Real Java client session (owner-led, partial)

Outside this test record: automatic Discord scheduling and retry against the real service.

PluginGuard
Released
1.2.1 PluginGuard-1.2.1.jar · 153.5 KBE8D3DA1D9A3F1DF5BCC9D9E8675872B7640DD889A130A9AB649A042827E2539F 2026-10-06

Console smoke checks completed on: Paper 1.21.11, Paper 26.2, Spigot 1.21.11, Folia 1.21.11, Folia 26.2, Purpur 1.21.11.

  • Console smoke checks
  • Package contents inspected

Outside this test record: Minecraft 26.1, Minecraft 1.21.0 to 1.21.10, Spigot 26.2, any real-player session.

VelorFailover
Released
1.2.2 VelorFailover-1.2.2.zip · 84.2 KB457198693299AEB620CC215D5843D0BA59A40A2EC11C4289DB023B32BD812DBE 2026-10-06

Recorded artifact inspection; the runtime matrix is outside this release record.

  • Package contents inspected
VeloRoad
Awaiting approval
1.4.3 Veloroad-1.4.3.jar · 179.5 KB26E7E371A15087A79ACE5A75A6C5EB51D35D80008C19E8AC36FC346687BFEC69 2026-10-07

Console checks 19/19 on each of: Paper 1.21.11, Paper 26.2, Spigot 1.21.11, Purpur 1.21.11, Folia 1.21.11, Folia 26.2.

  • Console smoke checks
  • Packaging tests
Migrate
Coming soon
— No build published Date not recorded

Development build; release evidence is attached at publication.

Dates are the day of the recorded check. “Date not recorded” means the release record does not state one.

Report a vulnerability

Report a suspected vulnerability privately through BuiltByBit messages or a direct message on Discord, not in public channels.