Plugin metadata
Reads plugin.yml, paper-plugin.yml, bungee.yml, velocity-plugin.json, entry points, commands and permissions.
Upload the actual plugin JAR to recover its metadata, commands, permissions, resources, strings, endpoints and verified JVM behavior—without running it.
Large or obfuscated archives may take longer.
Uploads are inspected in an isolated temporary workspace and are never executed. Analysis depth depends on file size, archive complexity and available recovery engines.
Reads plugin.yml, paper-plugin.yml, bungee.yml, velocity-plugin.json, entry points, commands and permissions.
Maps real method calls, runtime strings, URLs, process access, file access and network capabilities.
Computes cryptographic hashes and performs an exact published-file lookup where supported.
Minecraft server plugin
This searches decompiled source and extracted text resources, not a predefined suspicious-word list.
Choose a file from the left to inspect its recovered source or JVM bytecode.
These calls were parsed from compiled class bytecode.
| Caller class | Caller method | Invoked owner | Invoked method |
|---|
Strings loaded by compiled methods, with their originating class and method.
Every readable archive entry, including classes, resources, nested JARs and embedded binaries.
| Path | Type | Size | Compressed | View |
|---|
Findings require verified capabilities or behavior chains; loose words in metadata do not create critical verdicts.