HomeJavaModsOPShield
OPShield
ModsJava

OPShield

by Duong2012G · on Modrinth

Protects your server from OP/admin abuse with console-only OP (via password) and optional admin command restriction.

⬇ Download on Modrinth

🛡️ OPShield

Advanced security & command protection plugin for Paper 1.21+

Version Paper Java License

Protect your server from abuse — secure OP access, track every action, stop attackers instantly.


📖 Table of Contents


✨ Features

🔒 OP Protection


🚫 Sensitive Command Protection


🧠 Brute-force Detection & Lockout


🕵️ Shadow Ban System


⚠️ Auto Punishment System


🌍 Multi-Language Support


📊 Audit & Logging


📦 Requirements

Component Version
Java 21+
Paper 1.21+
Folia ❌ Not supported

🚀 Installation

  1. Download the plugin .jar
  2. Drop it into your server's plugins/ folder
  3. Start the server — OPShield will generate a random password and print it once in the console
  4. Save the password somewhere safe (it is only shown once)
  5. Grant permissions — add opshield.admin to your admin group in your permission plugin (e.g. LuckPerms). OPShield no longer grants permissions based on OP status alone (changed in v1.8.0)
  6. Open plugins/OPShield/config.yml to customise behaviour
  7. Run /opshield reload in-game or restart to apply changes ✅

Upgrading from 1.7.0? data.yml is automatically migrated on first boot. You only need to update your permission plugin setup — see the CRITICAL note in the changelog.

Tip: If you already have an op_password plaintext value from an older version, OPShield will automatically migrate it to op_password_hash and remove the plaintext entry.


⌨️ Commands

Command Description
/op <player> [password] Grant OP with password verification
/deop <player> [password] Remove OP with password verification
/opshield reload Reload configuration
/opshield unlock <player|ip> Clear all tracking state for a player or IP
/opshield status Show runtime statistics (active sessions, auth queue, flagged IPs, etc.)

🔐 Permissions

⚠️ Changed in v1.8.0: All permissions now default to false. You must grant them explicitly via a permission plugin.

Permission Default Description
opshield.* false Wildcard — grants all permissions
opshield.admin false Grants all child permissions
opshield.reload false Reload OPShield configuration
opshield.unlock false Unlock a tracked player or IP
opshield.status false View runtime statistics
opshield.op false Use password-protected /op
opshield.deop false Use password-protected /deop
opshield.bypass false Bypass non-OP restricted command blocking

Example LuckPerms setup

/lp group admin permission set opshield.admin true

🔧 Configuration

Files generated under plugins/OPShield/:


⚙️ Key Config Options

# Enable verbose console logging for troubleshooting (disable in production)
debug: false

# Password security
security:
  lockout:
    enabled: true
    max-attempts: 3
    duration-minutes: 3
    track_ip: true
    count_decay_hours: 168
  # Session timeout after successful auth (0 = disable, always require password)
  session_timeout_minutes: 30
  password:
    pbkdf2_iterations: 120000       # range: 10000 – 1000000
    auto_upgrade_legacy_hash: true  # silently upgrade SHA-256 → PBKDF2 on login

# Auto-punishment
auto_punishment:
  enabled: true
  threshold: 5
  window_seconds: 300
  command: "kick"                   # kick | ban | ban-ip | firewall | custom
  firewall_timeout_seconds: 10

# Shadow ban
shadow_ban:
  enabled: true
  auto_punish_level: 5

# Audit log
audit:
  console_output: true
  max_file_size_mb: 5
  log_retention: 3
  max_queue_size: 10000             # 0 = unlimited (not recommended)
  format: "plain"                   # plain | json

📐 Recommended settings by server size

Small server (≤ 20 players)

security.lockout.max-attempts: 3
security.lockout.duration-minutes: 5
ip_limit.max_accounts: 2
auto_punishment.enabled: false
shadow_ban.auto_punish_level: 10

Medium server (20–100 players)

security.lockout.max-attempts: 3
security.lockout.duration-minutes: 3
ip_limit.max_accounts: 3
auto_punishment.enabled: true
auto_punishment.command: kick
auto_punishment.threshold: 5
shadow_ban.auto_punish_level: 5

Large server (100+ players)

security.lockout.max-attempts: 2
security.lockout.duration-minutes: 10
ip_limit.max_accounts: 2
auto_punishment.enabled: true
auto_punishment.command: ban-ip
auto_punishment.threshold: 3
shadow_ban.auto_punish_level: 3

🔥 Firewall mode setup

Firewall mode executes an OS script asynchronously. To enable it:

auto_punishment:
  command: "firewall"
  allow_unsafe_firewall_exec: true
  firewall_timeout_seconds: 10
  # Linux:
  firewall_script: "iptables -A INPUT -s {ip} -j DROP"
  # Windows:
  # firewall_script: "netsh advfirewall firewall add rule name=OPShield dir=in action=block remoteip={ip}"

If allow_unsafe_firewall_exec is false, firewall mode falls back to a safe kick.


🔍 Troubleshooting

Admin needs to enter password every single /op command

OPShield grants a session after each successful authentication. Check:

Cannot use /op — "Incorrect password"

The password is required. Run:

/op <yourname> <password>

If you forgot the password, clear op_password_hash in config.yml and restart — a new password will be generated and printed in the console.

Admin cannot use /opshield after upgrading from 1.7.0

In v1.8.0, permissions now default to false instead of op. You need to explicitly grant the permission:

/lp group admin permission set opshield.admin true
Player is locked out and cannot try again

An admin can manually clear the lockout:

/opshield unlock <playername>
/opshield unlock <ip-address>
Auto-punishment is not triggering

Check the following:

Audit log is empty or not updating Config changes are not taking effect

Run in-game or console:

/opshield reload

❓ FAQ

Does OPShield replace /op?

No — it intercepts and wraps it. The original /op behaviour is preserved but gated behind a password.


Is the password stored securely?

Yes — passwords are hashed using PBKDF2-HMAC-SHA256 with a random salt and 120,000 iterations (configurable). The plaintext is never written to disk.


Does it support Spigot or Folia?

Paper 1.21+ only. Spigot may work but is not tested. Folia is explicitly not supported (folia-supported: false).


Can I disable auto-punishment entirely?

Yes — set auto_punishment.enabled: false. Shadow-ban fake messages will still work independently.


What happens if the server restarts during a lockout?

Lockout state is persisted to data.yml and restored on startup. Players cannot bypass lockouts by crashing or restarting the server.


Can I have multiple language files?

Yes — all three bundled files (en, vn, ru) are always present. Switch via language: in config.yml. Missing keys automatically fall back to the bundled English defaults.


What changed in v2.0.0?

Thread-safety overhaul — five race conditions and visibility bugs fixed:

See the Changelog for details.

What changed in v1.9.1?

Six bugs fixed in a patch release: double timestamps in audit log, missing session-granted/active messages, shadow-ban decoy messages losing their colours, exponential backoff count being reset too early (making count_decay_hours ineffective), and the /opshield reload permission check order. See the Changelog for details.

What changed in v1.9.0?

The biggest changes are async PBKDF2 authentication (no more TPS impact under brute-force) and session tokens (no need to re-type the password every command within the session window). See the Changelog for the full list.

What changed in v1.8.0?

The most important change is permission defaults — see the Changelog for the full list. The short version: grant opshield.admin to your admin group in LuckPerms.


📄 Credits

Author: Duong2012G
License: Apache 2.0
Website: https://modrinth.com/user/Duong2012G

Built for secure, professional Minecraft servers.

Quick facts

Install steps are the general flow for this file type — How to install Minecraft Java mods & modpacks walks through it step by step.

Verified by MCModsHub

These come from our own check of the pack file, not from the source page.

Explore more