Skip to content

Security scanner

Checks the things server owners most often get wrong: open backend ports, exposed RCON, proxy forwarding and DNS. Defensive only, and only for servers you own or may test.

Public backend ports

Backends must only be reachable through the proxy. We try a plain TCP connect to the backend ports you declare.

RCON exposure

RCON gives console access. We check whether its port answers from the internet and whether it is enabled with a weak password.

Proxy & origin architecture

Online mode, Velocity modern forwarding, BungeeCord ip_forward and backends addressed over public IPs.

DNS & origins

Missing records, several origin addresses, and whether DNS shows a known DDoS-protection provider (heuristic).

Firewall indicators

Closed internal ports suggest a default-deny firewall; open ones suggest missing rules.

Clear result

Every scan ends in SECURE, WARNING or CRITICAL — with the exact port, the expected state and the fix.

What the scanner does

  • Resolves DNS for your hostname
  • Opens a plain TCP connection to ports you declared
  • Sends one standard Minecraft status request
  • Reads your proxy and server configuration if you provide it

What it never does

  • DDoS, flooding or stress testing
  • Brute-forcing passwords or RCON
  • Exploiting vulnerabilities
  • Scanning port ranges or hosts you did not declare
  • UDP floods or amplified traffic

Before any network check you confirm that you own the server or are authorised to test it. Probes only target public addresses, are rate-limited and are recorded in the audit log.

Know what's exposed.

Run a defensive scan on your own server in minutes.