Cava's AntiCheat is composed by a client-side Forge mod and a server-side Spigot plugin that form a powerful client-server anticheat for Minecraft. It detects unauthorized loaded mods, textures and tampering using hashes.
Installation
Client side
To install the anticheat on the client just place the CavaAntiCheatClient.jar in the mods folder. Once the anticheat is installed on the server only the players with the anticheat installed on the client will be able to join the server; in other words the client side installation is not optional.
Server side
Place the CavaAntiCheatServer.jar in the plugins folder, then after the first startup you have to configure the whitelist.
You have to calculate the SHA-256 hashes for your Minecraft version jar, your forge version jar and for CavaAntiCheatClient jar (you can find the first two jars in %appdata%/.minecraft/versions).
In case you want to whitelist more mods just add a new line and compute the relative hashes.
I raccomend to use this online tool for calculating the hashes fast.
Example:
Commonly asked questions
Q: What if the user doesn't install the client mod? Can he still join with cheats?
A: Absolutely not. After a delay that you can set in the config (defaults to 5 seconds), the user will be kicked because the client mod hasn't been detected from the server.
Q: What if the user deletes the mods file after the client startup? Can he avoid the protection mechanism?
A: Nope, if the client detects a loaded mod that isn't not present in the mods folder it inform the server and will be kicked.
Q: Are only jar files checked?
A: No, every file in the mods folder will be checked.
Q: What if a user changes the modID of a cheat to the modID of a whitelisted mod?
A: That's not a problem. The hashes of the mod will not match, thus preventing the user from joining.
Q: Will a Fabric version be released?
A: Yes it will but no actual work as been scheduled yet. I am currently too busy to work on it. The code is open-source, pull-requests are accepted.
Q: Will you keep the plugin updated?
A: I will try too, probably in late 2023 I will have more time to update and implement new features that have been requested.
Disclaimer: as every client-server anticheat not running at kernel level, a skilled user can still find a way to bypass the protection. Other layers of protections "server-side only" are raccomended.
Installation
Client side
To install the anticheat on the client just place the CavaAntiCheatClient.jar in the mods folder. Once the anticheat is installed on the server only the players with the anticheat installed on the client will be able to join the server; in other words the client side installation is not optional.
Server side
Place the CavaAntiCheatServer.jar in the plugins folder, then after the first startup you have to configure the whitelist.
You have to calculate the SHA-256 hashes for your Minecraft version jar, your forge version jar and for CavaAntiCheatClient jar (you can find the first two jars in %appdata%/.minecraft/versions).
In case you want to whitelist more mods just add a new line and compute the relative hashes.
I raccomend to use this online tool for calculating the hashes fast.
Example:
Code (YAML):
whitelisted-mods:
minecraft : ffd4fb3037d4110085b4d3d2dc47b760695528eb14292c3e5f7c758983c6d764
forge : ffd4fb3037d4110085b4d3d2dc47b760695528eb14292c3e5f7c758983c6d764
cavaanticheat : 5d7fdb3fa948864930064f7f1d46d535b58fee1306793d7c63da5d37f877c965
#List of the enabled resource packs on the server with their checksums.
whitelisted-textures :
# exampleTexture: exampleChecksum
minecraft : ffd4fb3037d4110085b4d3d2dc47b760695528eb14292c3e5f7c758983c6d764
forge : ffd4fb3037d4110085b4d3d2dc47b760695528eb14292c3e5f7c758983c6d764
cavaanticheat : 5d7fdb3fa948864930064f7f1d46d535b58fee1306793d7c63da5d37f877c965
#List of the enabled resource packs on the server with their checksums.
whitelisted-textures :
# exampleTexture: exampleChecksum
Commonly asked questions
Q: What if the user doesn't install the client mod? Can he still join with cheats?
A: Absolutely not. After a delay that you can set in the config (defaults to 5 seconds), the user will be kicked because the client mod hasn't been detected from the server.
Q: What if the user deletes the mods file after the client startup? Can he avoid the protection mechanism?
A: Nope, if the client detects a loaded mod that isn't not present in the mods folder it inform the server and will be kicked.
Q: Are only jar files checked?
A: No, every file in the mods folder will be checked.
Q: What if a user changes the modID of a cheat to the modID of a whitelisted mod?
A: That's not a problem. The hashes of the mod will not match, thus preventing the user from joining.
Q: Will a Fabric version be released?
A: Yes it will but no actual work as been scheduled yet. I am currently too busy to work on it. The code is open-source, pull-requests are accepted.
Q: Will you keep the plugin updated?
A: I will try too, probably in late 2023 I will have more time to update and implement new features that have been requested.
Disclaimer: as every client-server anticheat not running at kernel level, a skilled user can still find a way to bypass the protection. Other layers of protections "server-side only" are raccomended.
Quick facts
- Edition: Minecraft Java
- File type: .jar
- Minecraft version listed: 1.19
- How to install: Install the matching mod loader (Forge, Fabric or NeoForge) for your Minecraft version. → Download the .jar. → Put it in the .minecraft/mods folder and launch that loader profile.
- Where to get it: Opens on Spigot — not every file is mirrored on our own servers.
Install steps are the general flow for this file type — How to install Minecraft Java mods & modpacks walks through it step by step.
Cava's Anti Cheat is a free Minecraft Java mod. Compatible with Minecraft 1.19. Downloaded 1,622 times (via Spigot). Download it and open it directly in the game.