Voxel Shop beta is live. Expect occasional bugs. Learn more  
ProtectCore Anti Grief - Web UI icon

ProtectCore Anti Grief - Web UI 5.4

Modern, powerful and web powered alternative to coreprotect

Page 1 2
5.4 11 days ago
Editor Access Reliability

• Replaced single-use token/cookie redirects with reusable 256-bit editor links.
• Each /po editor link now has its own fixed expiration time.
• Added editor.tokenTtlMinutes, defaulting to 60 minutes.
• Multiple links generated at different times remain independently valid.
• Link usage does not extend its expiration.
• Requests without a valid token continue to return HTTP 403.
• Tokens are invalidated on plugin reload or server restart.
• Fixed the relative API URL bug that caused the editor to open without entries.
• Added visible “Editor link expired” messaging.
• Made static Bootstrap assets and material icons publicly loadable; logs and metadata remain token-protected.
• Added automatic migration from previous token/session lifetime settings.
• Updated README and configuration documentation.
• Added tests for token strength, reuse, independent expiration, migration, and browser URL generation.

Please consider leaving a good review for the plugin.
Discord Support

5.2 12 days ago
Security, Reliability & Administration Update
ProtectCore 5.0
Highlights
  • Major security, reliability, and administration update.
     
  • Hardened embedded web editor with safer session handling.
     
  • More resilient MariaDB logging and reconnect behavior.
     
  • Improved command privacy controls and maintenance tools.
     
Logging & Privacy
  • Existing chat and normal command logging behavior remains unchanged.
     
  • Added configurable logging.sensitiveCommands.
     
  • Sensitive commands can now redact only their arguments instead of hiding the entire command.
     
  • Blacklist rules continue to take precedence.
     
  • Existing stored logs are not modified.
     
Editor Security
  • Added single-use 256-bit editor access links.
     
  • Added secure HttpOnly / SameSite sessions.
     
  • Tokens are removed from the URL after authentication.
     
  • Editor APIs now enforce same-origin access.
     
  • Assets are bundled locally instead of relying on external sources.
     
  • Added additional HTTP security headers.
     
  • Added bounded worker handling to prevent excessive resource usage.
     
  • Editor continues to default to loopback-only access.
     
Database & Maintenance
  • ProtectCore can now start in degraded mode when MariaDB is temporarily unavailable.
     
  • Added bounded log buffering and automatic database reconnection.
     
  • Added /po status for runtime and database health.
     
  • Added /po purge plan <days> for safe purge previews.
     
  • Added optional automatic log retention.
     
  • Database optimization behavior is now configurable.
     
Configuration
  • Updated configuration schema to version 2.
     
  • Legacy editor settings migrate automatically.
     
  • Existing editor reachability settings are preserved.
     
  • Added configurable action toggles.
     
  • Missing message entries automatically use bundled defaults.
     
  • Improved reload validation and failure handling.

Please consider leaving a good review for the plugin.
Discord Support
5.0 26 days ago
Database improvements less disk space
ProtectCore – Database Improvements
This update focuses on database cleanup, reduced storage usage, and safer metadata handling.
 
Improved
  • New databases no longer create several obsolete indexes and unused search columns.

  • Reduced unnecessary database overhead while keeping all important search, rollback, restore, purge, and web editor functionality intact.

  • Empty metadata is now stored more efficiently as SQL NULL.

  • The web editor now safely handles events with empty metadata.
Compatibility
  • Existing databases are not modified.

  • No indexes, columns, or existing records are removed.

  • Existing "{}" metadata remains fully supported.

  • Snapshot and inventory formats are unchanged.

  • No new commands, configuration options, or dependencies were added.
Please consider leaving a good review for the plugin.
4.8 Sep 1, 2026
Reliability & Rollback Safety Update
Reliability & Rollback Safety Update
 
This update improves rollback safety, logging accuracy, database reliability, and configuration handling.
 
Database Reliability
 
  • Fixed logs occasionally being lost during batch processing.
  • Added database outage protection with automatic retry delays to prevent rapid retry loops and excessive memory usage.
  • Added a configurable pending-log queue limit to protect the server during extended database outages.
  • ProtectCore now provides rate-limited warnings if the queue reaches its emergency limit.
 
Safer Rollbacks
 
  • Fixed a global rollback permission bypass caused by negative radius values.
  • Global rollbacks must now explicitly use radius:global.
  • Fixed failed chunk loads potentially locking all future rollbacks.
Rollback failures are now safely released and reported instead of blocking the rollback system.
Prevented rollback completion from being triggered multiple times.
Added safer default rollback workload limits to reduce server impact.
Invalid rollback settings are automatically corrected instead of causing operations to stall.
 
 
More Accurate Activity Logging
 
 
  • Boats and armor stands are now correctly logged as entity placements.
  • Added the new ENTITY_PLACE action type.
  • Cancelled actions are no longer recorded as successful actions.
  • Denied block placement, breaking, interactions, explosions, hopper transfers, and similar events now produce more accurate logs.
  • Fixed empty-hand item-frame rotations being incorrectly logged as item removals.
  • Fixed hopper pull logging. Both hopper push and pull transfers are now recorded.
 
Improved Armor Stand Rollbacks
 
 
  • Armor stands now retain their equipment during rollback.
  • Item names, lore, enchantments, custom data, and other properties are preserved.
  • Armor stand poses, visibility, arms, size, marker state, base plate, gravity, custom name, disabled equipment slots, and other important properties are now restored correctly.
 
Administration Improvements
 
 
  • Added ENTITY_PLACE support to configuration controls.
  • Added entity-placement formatting to lookup results.
  • Added ENTITY_PLACE support to the web editor and command suggestions.
  • Database queue and retry limits can now be configured.
 
Improved Configuration Updates
 
ProtectCore can now automatically add new configuration options during startup and [ICODE]/po reload[/ICODE] without replacing your existing configuration.
 
 
  • Missing options and documentation comments are automatically added.
  • Existing administrator values and comments are preserved.
  • Custom and obsolete configuration keys are left untouched.
  • Structural conflicts are safely reported instead of overwritten.
  • A [ICODE]config.yml.bak[/ICODE] backup is created before automatic changes.
  • No changes are made when the configuration is already up to date.
 
This update makes ProtectCore significantly safer during rollbacks, more accurate when recording player activity, and more resilient during database or configuration problems.
4.6 Aug 24, 2026
Fixes & Improvements
  • Fixed a shutdown warning/error that could occur on servers where WorldEdit or FAWE was:
    • Not installed

    • Disabled

    • Unloaded before ProtectCore

    • Using an incompatible API version
  • Improved WorldEdit/FAWE integration so ProtectCore only interacts with WorldEdit components when they are actually available.

  • WorldEdit logging queues are now only drained when ProtectCore has actually created them.

  • Improved shutdown handling to prevent missing WorldEdit classes from causing NoClassDefFoundError errors.

  • Added additional safeguards around WorldEdit queue cleanup and unregistering.

  • Improved rollback handling so it safely uses the available WorldEdit integration without directly depending on WorldEdit classes.

This update makes ProtectCore shutdowns cleaner and more reliable, especially on servers where WorldEdit/FAWE is optional or unavailable.

Please consider leaving a good review for the plugin.
Discord Support

4.6 Aug 24, 2026
Fixes & Improvements
  • Fixed a shutdown warning/error that could occur on servers where WorldEdit or FAWE was:
    • Not installed

    • Disabled

    • Unloaded before ProtectCore

    • Using an incompatible API version
  • Improved WorldEdit/FAWE integration so ProtectCore only interacts with WorldEdit components when they are actually available.

  • WorldEdit logging queues are now only drained when ProtectCore has actually created them.

  • Improved shutdown handling to prevent missing WorldEdit classes from causing NoClassDefFoundError errors.

  • Added additional safeguards around WorldEdit queue cleanup and unregistering.

  • Improved rollback handling so it safely uses the available WorldEdit integration without directly depending on WorldEdit classes.

This update makes ProtectCore shutdowns cleaner and more reliable, especially on servers where WorldEdit/FAWE is optional or unavailable.

Please consider leaving a good review for the plugin.
Discord Support

4.5 Aug 21, 2026
hotfix
- Marked Adventure / Kyori dependencies as provided.
 
- Removed Adventure / Kyori from the shaded artifact includes.
 
- Removed the net.kyori -> com.lucidaps.shaded.adventure relocation.
 
- Left OkHttp, Okio, and Hikari relocation intact.

Please consider leaving a good review for the plugin.
Discord Support
4.5 Aug 19, 2026
Maintenance update

- Added missing protectcore.admin.purge permission declaration.
- Updated plugin metadata and command usage.
- Added permission descriptions and protectcore.* wildcard.
- Cleaned internal logging for icon extraction and reload errors.
- Rebuilt the release JAR with aligned plugin and Maven versions.

Please consider leaving a good review for the plugin.
Discord Support

4.4 Apr 15, 2026
general improvements
Update Changelog
  • Added expiration support for one-time /pc_tp teleport tokens.
  • Added automatic cleanup for expired /pc_tp tokens during the scheduled token GC task.
  • Improved update checking so the HTTP request runs async, while the version result is handled safely back on the main server thread.
  • Added connection and read timeouts to the update checker for more reliable network handling.
  • Cleaned up the Spigot update-check URL handling.
  • Switched subcommand storage from HashMap to LinkedHashMap for stable command/help ordering.
  • Preserved original username casing in log output instead of forcing lowercase.
  • Improved time-ago formatting to safely handle negative clock differences.
  • Updated time formatting to use Locale.ROOT for consistent decimal output across locales.
  • Improved /pc_tp token validation so tokens are consumed immediately and expired tokens are rejected.
  • Updated /pc_tp tab completion to return no suggestions directly.
  • Changed date locale access to use the cached plugin value instead of rereading config each time.
  • Updated Editor API server initialization to use the cached dateLocale value.
  • Fixed a possible NullPointerException in system log detection by using a safe UUID comparison.
  • Removed redundant token removal logic in PcTpCommand.
  • Removed unused indent calculation code from log component building.
  • Removed unused imports and minor internal cleanup.
Please consider leaving a good review for the plugin.
Discord Support
4.3 Mar 23, 2026
shutdown improvements
Shutdown / WorldEdit drain fixes
 
 
  • Fixed plugin shutdown error caused by WorldEdit queue draining trying to register Bukkit tasks after the plugin was already disabling.
  • Removed scheduled/asynchronous WorldEdit drain usage from onDisable().
  • Changed shutdown flow to use a direct, synchronous WorldEdit queue drain instead.
  • Kept shutdown order safe: unregister WorldEdit bridge first, drain WorldEdit queues second, flush database queue last.
 
ProtectCore shutdown flow
  • Updated ProtectCore.onDisable() to stop new WorldEdit hooks before draining pending edit logs.
  • Replaced WELoggingExtent.flushAllQueues(...) + async drain waiting with WELoggingExtent.flushAllQueuesDirect().
  • Ensured database shutdown happens only after WorldEdit entries have been pushed into the DB queue.
  • Preserved final scheduler cancellation at the end of shutdown instead of relying on scheduled drain tasks.
 
WELoggingExtent changes
  • Added a direct shutdown-safe queue flush path that does not use runTask, runTaskTimer, BukkitRunnable, or Paper schedulers.
  • Direct drain now polls queued WorldEdit entries and logs them straight into the database queue.
  • Direct drain builds log metadata the same way as the normal scheduled drain, including origin, material, block data, and pretty material name.
  • Direct drain safely handles unknown/missing worlds by dropping queued entries with a warning instead of crashing shutdown.
  • Reset drain state cleanly after direct flushing finishes.
 
Stability / safety improvements
  • Avoided illegal task registration during plugin disable, preventing IllegalPluginAccessException.
  • Reduced shutdown race risk between queued WorldEdit drain work and database shutdown.
  • Kept database queue acceptance window open long enough for shutdown-drained WorldEdit entries to be persisted.
  • Improved reliability of graceful shutdown for pending WorldEdit block change logs.
 
Please consider leaving a good review for the plugin.
Discord Support
4.2 Mar 16, 2026
faster searches
Search & Performance Update
 
- Improved search performance for PLAYER_MESSAGE and PLAYER_COMMAND logs.
- Added a dedicated fast path for chat and command searches.
- Message and command searches now use details-only text matching instead of scanning full metadata.
- Kept metadata loading disabled for message/command rows in the UI path.
 
Search Improvements
 
- Added unified text-search handling for more consistent search behavior.
- Improved multi-word FULLTEXT query handling.
- Added smarter index selection so FULLTEXT searches no longer get forced onto weaker normal indexes.
- Improved action-specific search performance.
- Improved per-user action search performance.
- Improved message/command-specific FULLTEXT searching.
 
Database / Indexing
 
- Added support for dedicated message/command search text handling.
- Added support for a dedicated FULLTEXT index for chat/command searching.
- Added support for an action + time index to improve action-specific browsing.
- Added support for a player + action + time index to improve per-user action browsing.
 
Code Cleanup
 
- Reworked filter-building logic to reduce duplicated query code.
- Updated user search paths to use the new shared search logic.
- Updated area search paths to use the new shared search logic.
- Reduced duplicate SQL-building across paged, keyset, and windowed searches.
- Made search behavior more consistent across paged, keyset, windowed, user, and area queries.

Please consider leaving a good review for the plugin.
Discord Support
4.0 Mar 4, 2026
Massive changes!

Synopsis
This update mainly focuses on making the plugin faster, safer, and more scalable by improving database startup, schema/index design, query performance, retry behavior, and item/container logging so searches and rollbacks are more reliable. It also tightens the editor and API side with safer rendering, cleaner pagination, better async/tab handling, stronger filtering/date handling, and reduced desync or stale-state issues.

For best results I recommend that you do /po purge 0 and start your database storage from the begining.

- Added maintenance mode protection to stop DB queues from growing too large.
- Improved shutdown handling so queued work flushes more safely.
- Switched Hikari to use MariaDbDataSource directly.
- Split DB setup into fast startup + heavy async migrations.
- Added async schema updates for name/lore search columns and FULLTEXT indexes.
- Added generated chunk columns cx and cz.
- Added new chunk-based indexes for faster rollback and area searches.
- Updated queries to use cx/cz and sort_ts for better performance.
- Improved filtering for materials, entities, ignored usernames, name, and lore.
- Added safer retry logic for transient DB update failures.
- Added dedicated database fields for searchable item data, including name, lore, and enchants.
- Switched item name, lore, and enchant search data from JSON storage to dedicated database columns for better reliability and performance.
- Cleaned up item frame logs so even basic items now store usable item data instead of sometimes being empty.
- Expanded item search logging to cover more important cases, including pickup/drop, item frames, armor stands, and container add/take.
- Improved container tracking to reduce duplicate logs and store cleaner snapshots.
- Added better handling for shulker box snapshots when placed with items already inside.
- Updated database startup so the essential setup runs first, while larger migration tasks run after startup to reduce load during boot.
- Hardened the editor UI against injection by replacing fragile string-built HTML/JS with safer escaping and DOM-based rendering.
- Fixed async race conditions in log loading so stale requests no longer append into the wrong tab or corrupt loading state.
- Restored consistent tab behavior: switching tabs now cleanly resets and reloads with correct per-tab pagination state.
- Improved metadata rendering and item-detail display, including safer parsing of colored text/lore and lazy-loaded metadata panels.
- Cleaned up client pagination by using keyset cursors (lastTimestamp / lastId) instead of brittle page-based behavior.
- Tightened server-side request flow with better token handling, refresh support, gzip responses, and more up-to-date stats rendering.
- Fixed backend filtering edge cases, including safer config handling, better request parsing, and consistent timezone-aware date filtering.
- Simplified API usage toward safer, more reliable same-origin behavior and reduced frontend/backend desync issues.
- Removed dead code / stale state from earlier refactors, making the editor easier to maintain without changing intended features.

Please consider leaving a good review for the plugin.
Discord Support

3.1 Feb 2, 2026
hotfix

- Small hotfix for lookup when using an action and the include filters together some material entries didn't show up at the results but they existed without the include.
- Small updates here and there.

Please consider leaving a good review for the plugin.
Discord Support

3.0 Jan 26, 2026
Purging, maintness and more
  • Added /po purge to remove old data (actions + orphan snapshots) and optimize automatically if there’s enough free disk space.

  • Removed startup auto-maintenance/optimization (unsafe on low disk space machines).

  • Added a one-command full database delete + recreate option.

  • Various code cleanup + optimizations.

New purge command (with prompts + confirmations):
Examples

  • Keep last 30 days (delete everything older): /po purge 30

  • View progress / results anytime: /po purge status

  • Stop purge: /po purge stop

⚠ Warning

  • /po purge 0 = deletes everything and recreates the database (use when disk space is low).

  • Purging alone won’t shrink the DB file; optimization does. Optimization will run automatically if you have enough disk space. Optimization requires free disk space ≈ DB size (e.g., 100GB DB → ~100GB free). If you don’t have that, use /po purge 0.

Please consider leaving a good review for the plugin.
Discord Support

2.8 Jan 6, 2026
Web UI Improvements
- Message and command action categories will now have a text search function.
- Action categories will have specific and dedicated filters for them that will switch on the fly as you change action categories
- General cleanup and error catching for the Web UI.
image.png
 
Please consider leaving a good review for the plugin.
2.6 Jan 2, 2026
fix improvements
- Made it so that inspect mode is just for single blocks only.
- Added a few missing armorstand actions to be recorded by the plugin.
 
Please consider leaving a good review for the plugin.
2.5 Dec 29, 2025
small fixes

- Suggests user: / time: only if not already present
- Suggests time presets whenever the current arg starts with time: (works for arg #1 or #2)
- Suggests online player names after user:

Please consider leaving a good review for the plugin.
Discord Support

2.4 Dec 18, 2025
Compatibility

- Database changes to ensure compatibility with older MYSQL servers while mainting modern MariaDB standards.

Please consider leaving a good review for the plugin.
Discord Support

2.2 Dec 15, 2025
Wellness update
- Fix rare potential NPE in case plugin.yml is misconfigured.
- Fixed a command being registered twice by mistake.
- Better handling when tab complete is supposed to return nothing.
- Shutting down the plugin now waits for active DB workers to finish, then drains queued DB tasks directly so nothing gets skipped.
- Replaced a few database queues with more efficient ones for faster results.
- “System” actions are handled more consistently in logs.
 
Please consider leaving a good review for the plugin.
2.1 Dec 11, 2025
Aliases, include , exclude materials

- Made it so that admins can use both user: time: radius: and u: t: r:


- Improve lookup searches using the include and exclude material filters sometimes failing to filter results, webui was already good.


 


Please consider leaving a good review for the plugin.


Discord Support

Page 1 2
Sign in
$12.64 USD
Sign in to purchase, save this product to your cart, and keep downloads tied to your account.
Stripe