this plugin is not just for protecting our server from players cheating,... its also protecting our server from exploits and server crashes. I mean, this is the best anti-exploit plugin out there! It has everything a plugin must have. Every SMP server owner should have this!
All possible modules are enabled, but most of them were patched in 1.21.11 and 26.1.2, so we need a better version checker to not guess what to disable myself.
btw, unban MISHA on Discord :)
That doesn't seem safe to me! I will not add per world options. Maybe if you tell me the specific check, I can add bypass. But those like packet limiter etc are extremely unsafe to add a bypass for, even for administrators.
I have used this plugin and overall my experience has been positive. It is a very useful tool and offers better features compared to LPX.
However, there is one important issue that caused me to give it one less star.
There is a well-established standard across almost all plugins: the main command should be hidden from regular (non-admin) players and require a specific permission to be executed. Unfortunately, this standard has not been followed in this plugin. Regular players can type the /exploitfixer command immediately after joining the server, and once executed, a long help message is sent to their chat. From a usability and security perspective, this behavior is not considered standard or acceptable.
What makes this more disappointing is that despite this issue being reported, the developer refused to address or fix it. This small change could have made the plugin feel complete and truly professional.
That said, we sincerely appreciate the effort and work that went into developing this plugin. It is a great tool overall, but more attention to this issue was expected in order to keep the plugin flawless and at a high standard.
Sorry, I am not the kind of person that believes on that pattern design. Thank you so much for your review and I appreciate it! This is not a security vulnerability not unnaceptable. Security through obscurity is completely wrong and regarded as unsafe practice.
It should be fixed on ExploitFixer. I am not sure what it exactly does, but we have a lot of limitations of how you can interact with enderchests or what packets you can send. If you have issues please contact me and we can review together on Discord. Thanks!!!
Hey, I just wanted to ask about the ExploitFixer license. When it expires, does the plugin stop working on the server, or does it just mean I won’t get updates and support anymore?
We've been using ExploitFixer for a while now, it's an essential plugin for maintaining secure and stable servers. The developer is also highly active and responsive, consistently addressing bugs and improving the plugin.
Thank you so much for your review. Some servers are just incompatible because they for different reasons dont sync the correct item meta between server-client, usually when using plugins like ViaVersion, so a better option for me was to disable it by default. Servers not using viaversion and such plugins can benefit from this feature.
This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
By continuing to use this site, you are consenting to our use of cookies.