Security
By opsec
August 26, 2026
The risk of shady plugins and downloads
Running a server means running other people's code. A single backdoored plugin can hand your whole server – and your players' data – to a stranger. Here is what to watch for.
Where the danger hides
- Backdoored plugins. A “free” or leaked copy of a paid plugin often has extra code added: a hidden command or web callback that gives the author remote control, op, or the ability to run commands on your box.
- Malicious web shells. If an attacker gets one file onto a web-facing server, they can drop a “web shell” – a small script that lets them browse files and run commands through the browser. Outdated web software and uploaded “plugins” from unknown sources are the usual way in.
- Fake resource packs and mods. Same idea, different wrapper.
How to stay clean
- Only install plugins from the developer or a trusted marketplace. Leaked paid plugins are the number-one source of server backdoors.
- Keep your server software and plugins updated – most break-ins use a known, already-patched hole.
- Run the server as a limited user, not root, and keep backups you can actually restore.
- If a plugin asks for strange permissions, phones home to an unknown address, or ships obfuscated code with no source, do not run it.
Everything we sell is built in-house and shipped straight from your Licenses page – there is no reason to ever grab our plugins from a third-party “leak” site.