HomeJavaModsmProtect
mProtect

mProtect

Exploit, lag-machine, and event-spam protection for Paper, Purpur, and Folia.

Paper Purpur Folia

GitHub Modrinth Discord

bStats Release Java 25 Minecraft 26.2

What mProtect checks

Every detection can be written to H2 and JSONL, shown to online staff, and optionally sent to a Discord webhook. English and Russian messages are included.

Available for Folia

Requirements

mProtect protects the server event layer. Malformed packets must be rejected before Bukkit events exist, so use Paper's native packet limiter as described in Paper hardening. mProtect does not claim packet interception it cannot perform.

Installation

  1. Stop the server.
  2. Put mProtect-1.2.0.jar into the server's plugins directory.
  3. Start the server once to create plugins/mProtect/config.yml and the language files.
  4. Review the limits before opening the server to players.
  5. Run /mprotect status and /mprotect test items from the console or as an administrator.

Use /mprotect reload after changing checks, limits, alerts, or messages. Changing storage settings requires a restart.

Configuration guide

The generated config.yml is the source of truth. Missing options are restored automatically and invalid numeric values are replaced with safe defaults.

Items and containers

items.blocked-materials contains materials players must not possess. Validation also covers overstacking, enchantments, attributes, durability, names, lore, custom potion effects, fireworks, serialized size, and nested containers. Conservative defaults avoid rejecting intentional unbreakable rewards unless items.reject-unbreakable is enabled.

items.action accepts:

Most checks run when an inventory is actually touched. items.fallback-scan-minutes controls the low-frequency safety scan; it is not a per-tick scan.

Books, signs, and anvils

The books, signs, and anvils sections set character, component, and repair-cost limits. Set books.strip-formatting or anvils.strip-formatting only if formatting should be removed. Sign click events can be stripped independently with signs.strip-click-events.

Commands

Explicit blocked names are checked after removing a namespace, so /minecraft:op cannot bypass the op rule. Config version 2 no longer blocks every vanilla namespaced command by default. blocked-namespaces remains available when an entire plugin namespace must be prohibited.

Entities and chunks

entities.max-per-chunk limits the total tracked entities in a chunk, while entities.max-per-type-per-chunk limits a single type. Existing chunks are counted as they load and counters are updated on spawn and removal.

chunk-loads limits how quickly a player may cross into new chunks. Increase the limit for servers where fast elytra travel is expected.

Lag-machine protection

Every hot-path rule is a bounded O(1) window keyed by chunk, block, or player. No rule scans nearby entities or the whole world:

The defaults are intentionally generous for ordinary survival servers. Technical servers should tune one section at a time using /mprotect status and /mprotect violations. Administrative bypasses exist only for attributable player limits; machine limits have no bypass because most world events have no trustworthy owner.

Alerts and storage

Commands

Command Description Permission
/mprotect status Show enabled checks and today's counts mprotect.command.status
/mprotect violations [player] Show the ten newest stored violations mprotect.command.violations
/mprotect test <check> Validate a configured check mprotect.command.test
/mprotect inspect Check the held item without modifying it mprotect.command.inspect
/mprotect scan Audit your inventory without modifying it mprotect.command.scan
/mprotect reload Reload safe settings and language files mprotect.command.reload

The alias /mpr is also available.

Permissions

mprotect.admin grants all administrative commands, alerts, and player-attributable bypasses. Individual bypass permissions are available for items, commands, books, signs, anvils, creative, chunks, portals, and activity, using the form mprotect.bypass.<check>.

Entity spawn limits intentionally have no bypass permission because many spawn events do not have a reliable player initiator.

Telemetry and updates

mProtect uses bStats to collect anonymous usage statistics when metrics.enabled is true. Server owners can opt out in the global bStats configuration. The collected data and privacy details are documented in the bStats server owner guide.

The update checker only requests public release metadata from Modrinth when updates.enabled is true and a project ID is configured. It never downloads or installs updates.

Building

./gradlew clean build

The deployable artifact is build/libs/mProtect-1.2.0.jar. Automated tests cover bounded keyed rate windows, configured actions, semantic versions, and storage path containment.

Support

Report reproducible problems through GitHub Issues or ask for help in Discord. Include the server software, Java version, mProtect version, relevant configuration, and the complete error from the log.

Licensed under the MIT License.

Quick facts

Install steps are the general flow for this file type — How to install Minecraft Java mods & modpacks walks through it step by step.

Verified by MCModsHub

These come from our own check of the pack file, not from the source page.

Explore more