ExploitShield is a free, open-source plugin for protecting Minecraft servers against packet exploits, crash attempts, invalid NBT data, malicious payloads, and duplication methods. It validates and filters packets, applies rate limits, detects malformed packets, and checks payloads and plugin messages. Its NBT checks include oversized content, invalid UTF-8, illegal characters, and invalid stack sizes. Listed crash protections cover books, signs, payloads, chat overflow, TabComplete, and invalid packet cancellation. Duplication protections span inventory, creative, hopper, container, piston, minecart, boat, and vehicle cases, with chunk duplication detection and item signature tracking. Administrators can configure protection modules, thresholds, packet and rate limits, alert messages, and punishments. Responses include alerts, cancellation, kicks, bans, IP bans, and custom commands. It supports Minecraft 1.17.x–1.21.x on Paper, Spigot, and Folia, and requires Java 17+, PacketEvents 2.13.0+, and ProtocolLib 5.4.0+.
Who it is for
ExploitShield suits administrators of compatible Minecraft servers who want configurable packet, crash, NBT, payload, and duplication protections. It requires both PacketEvents and ProtocolLib.
What is good
- Covers packet exploits, crash attempts, NBT, and duplication.
- Supports configurable alerts and enforcement actions.
- Compatible with Paper, Spigot, and Folia.
- Free and open-source under GPL-3.0.
What to know first
- Requires Java 17 or newer.
- Requires PacketEvents 2.13.0+ and ProtocolLib 5.4.0+.
- Compatibility is listed for Minecraft 1.17.x–1.21.x.
Verdict
ExploitShield offers a broad set of configurable server protections and response actions. Server administrators should check the listed Minecraft version and dependency requirements before using it.
Get started with ExploitShield
- Open the ExploitShield GitHub website.
- Use a Minecraft 1.17.x–1.21.x server running Paper, Spigot, or Folia.
- Meet the Java 17+ requirement.
- Install or provide PacketEvents 2.13.0+ and ProtocolLib 5.4.0+.
- Configure protection modules, limits, thresholds, alerts, and punishments.
What the free plan stops at
The free plan is for Minecraft 1.17.x–1.21.x on Paper, Spigot, or Folia and requires Java 17+, PacketEvents 2.13.0+, and ProtocolLib 5.4.0+. GPL-3.0 requires distributed modified versions or projects incorporating its source to use GPL-3.0 and publish complete source code.
Questions about ExploitShield
How much does ExploitShield cost?
The Free plan costs 0.00 USD per free.
Which servers does it support?
The listed compatibility is Minecraft 1.17.x–1.21.x on Paper, Spigot, and Folia.
What does it require?
It requires Java 17+, PacketEvents 2.13.0+, and ProtocolLib 5.4.0+.
Is ExploitShield open source?
Yes. It is licensed under GPL-3.0, which requires distributed modified versions and projects incorporating its source to use GPL-3.0 and make their complete source public.
Does it analyze replays?
No. Replay analysis is listed as unavailable.
What usage data does the project say bStats collects?
It collects Minecraft version, Java version, operating system, plugin version, and online player count. The project says it does not collect personal information, player data, server IPs, or configuration files.
ExploitShield plans and pricing
All plansCompared on Minecraft anti-cheat plugins
- Free plan
- Yes
- Server platforms
- Paper, Spigot, Folia
- Minecraft versions
- 1.17.x – 1.21.x
- Detection coverage
- packet exploits, crash attempts, invalid NBT data, malicious payloads, duplication methods
- Enforcement actions
- alert, cancel, kick, ban, IP ban, custom commands
- Replay analysis
- No
