Runs fully in your browser. Nothing you upload leaves this tab.
Check a plugin jar for hidden or obfuscated code
Upload one or more .jar files. Jarscope reads each compiled class's constant pool
and flags patterns associated with obfuscation and backdoors: encrypted strings, reflective
call indirection, permission/OP manipulation, network or process execution capability, and
scrambled identifiers.
This is static pattern-matching, not proof of intent. Nothing is executed.
A high score means the jar uses techniques common in malicious plugins and deserves a closer look
or a sandboxed test run — it isn't a verdict. A clean score means nothing suspicious was found
in the constant pool, not a guarantee of safety.
Drop .jar files here or click to browse
Multiple files supported · nothing is uploaded to a server · try .jar