Observed arrival · 2026-10-05
PluginDoctor checks Minecraft plugins before they reach a server
A beta scanner for Minecraft plugin jars that says it checks for backdoors, altered releases, vulnerable dependencies, and performance hazards.
○Open
⊠Login
$Paid
†Ads
✦Pretty
●Pro
◎Niche
◉Human
⚑Risk
ƒJS
- For
- Minecraft server owners and plugin developers
- Worth noticing
- Its illustrative report flags a hidden operator-grant trigger, runtime code loading, and a jar mismatch with severity labels.
Field notes
The page says the beta accepts Modrinth, Hangar, SpigotMC, and GitHub links, direct jar downloads, or uploaded .jar files. It describes decompiling the archive without running it, then checking release hashes, malware patterns, dependencies, suspicious behavior, and main-thread work. A displayed AuctionPlus report is explicitly illustrative, and the code-audit and Pro offerings are described as coming soon.
Observed signals
Read the marks
Editorial observations of this landing page, not a rating.
○OpenPublic substance visible
✦PrettyNotable craft visible
●ProPolished or operationally mature
◎NicheUnusually specific use
ƒJavaScriptBrowser-side code central
One card from the complete issue