jarscope
static plugin inspector
Runs fully in your browser.
Nothing you upload leaves this tab.

Check a plugin jar for hidden or obfuscated code

Upload one or more .jar files. Jarscope reads each compiled class's constant pool and flags patterns associated with obfuscation and backdoors: encrypted strings, reflective call indirection, permission/OP manipulation, network or process execution capability, and scrambled identifiers.

This is static pattern-matching, not proof of intent. Nothing is executed. A high score means the jar uses techniques common in malicious plugins and deserves a closer look or a sandboxed test run — it isn't a verdict. A clean score means nothing suspicious was found in the constant pool, not a guarantee of safety.
Drop .jar files here or click to browse
Multiple files supported · nothing is uploaded to a server · try .jar
Scanning…0 / 0

Scan results