Voxel Shop beta is live. Expect occasional bugs. Learn more  
NoAltsExploits️ icon

NoAltsExploits️ 7.0

Prevent abuse and exploits of alt accounts & bungee support! Accurate Geolocation data of any player

Page 1
7.0 12 days ago
safer login protection, improved account tracking, stronger privacy controls, better staff tools, an
Velocity 7.0
 
Added
  • HikariCP pooling for SQLite/MySQL with bundled JDBC drivers.
     
  • Versioned database migrations and performance indexes.
     
  • Validated YAML configuration with safe atomic reloads.
     
  • Configurable database failure policy (DENY / ALLOW).
     
  • Atomic command cooldowns and login reservations to prevent concurrency bypasses.
     
  • /naev status, /naev cleanup, and paginated IP history.
     
  • Automatic 24-hour retention cleanup.
     
  • Maven Wrapper, GitHub Actions, MySQL 8.4 integration testing, and expanded automated tests.
     
Changed
  • Updated to Java 21 and Velocity 3.5.
     
  • Database and login operations now run asynchronously.
     
  • Replaced persistent JDBC connections with pooled short-lived connections.
     
  • Cleanup now respects configured retention and actual player inactivity.
     
  • Storage changes correctly require a restart.
     
  • Added configurable MySQL security and pool settings.
     
  • Release JAR now shades/relocates internal dependencies.
     
Fixed
  • Removed the hardcoded 30-day history limit.
     
  • Fixed simultaneous logins bypassing account/IP limits.
     
  • Fixed concurrent commands bypassing cooldowns.
     
  • Login reservations are immediately released after denied logins.
     
  • Fixed cleanup scheduling, initialization order, and misleading storage status.
 


 
Paper Backend 7.0
Protection
  • Same-IP checks now happen before players join.
     
  • Added login reservations to prevent simultaneous-login bypasses.
     
  • Denied logins no longer create account or IP-history records.
     
  • Added optional recent-account limits per IP with configurable lookback.
     
  • Preserved household and bypass exemptions.
     
Storage & Retention
  • Reworked account storage to track UUID, name, latest IP, and last-seen time.
     
  • Automatic migration and backup of legacy JSON data.
     
  • Added configurable latest-IP retention.
     
  • New asynchronous, atomic JSON persistence with retry and corruption backups.
     
  • Added IP-history retention, duplicate compaction, and cooldown cleanup.
     
Command Protection
  • Cooldowns are committed only after commands successfully execute.
     
  • Added precise target-argument configuration.
     
  • Added proper multi-word command matching.
     
  • Improved case-insensitive player lookup.
     
  • Prevented unrelated arguments from being treated as player targets.
     
Staff Tools
Added or expanded:
 
  • /nae status
     
  • /nae forget <player> confirm
     
  • /nae purge now
     
  • /nae sameip
     
  • /nae iphistory
     
  • /nae household
     
  • Permission-aware tab completion and pagination.
     
Permissions & Privacy
  • Added granular staff permissions.
     
  • Moderators can inspect linked accounts without viewing IP/geolocation data.
     
  • Sensitive information requires dedicated admin permission.
     
  • Added rotating, sanitized administrative audit logs.
     
  • IP addresses are excluded from audit logs by default.
     
Configuration & Networking
  • Added dedicated messages.yml.
     
  • Added configuration for retention, account caps, target arguments, and auditing.
     
  • Update and geolocation requests are now fully asynchronous.
     
  • Added HTTP timeouts and geolocation caching.
     
  • Geolocation only accepts valid public IP addresses and is requested on demand.
Please consider leaving a good review for the plugin.
Discord Support
6.8 26 days ago
compatability update

This update provides included database driver support for servers that don't already have and prevents the plugins from starting mainly for Velocity that download allow library downloads on startup.

Please consider leaving a good review for the plugin.
Discord Support

6.7 Aug 29, 2026
Reliability, Security & Staff Tools Update
This update strengthens the plugin’s core protection systems while introducing easier household management, safer geolocation, and improved staff controls.
 
New Household Management Commands
 
Household accounts can now be managed directly in-game without manually editing the configuration:
 
/nae household list [group]
/nae household add <group> <real|alt> <player>
/nae household remove <player>
/nae household delete <group>
 
Commands include permission-aware tab completion and automatically save changes to the configuration.
 
Improved Command Protection
  • Cooldown commands now use accurate, token-aware matching.
  • The longest configured command is always selected.
  • Commands such as “test two” no longer incorrectly use the shorter “test” cooldown.
  • Short command names no longer match unrelated commands or command arguments.
  • Matching is now case-insensitive and handles additional arguments correctly.
 
Storage & Reliability Improvements
 
  • Saved IP and cooldown data is fully loaded before protection becomes active.
  • Closed a startup window where players could join before existing data finished loading.
  • IP history operations are now thread-safe.
  • Repeated identical IP-history entries are compacted to reduce file size.
  • Corrupted JSON files are automatically backed up instead of preventing startup.
  • Added safer atomic file saving with filesystem fallback support.
  • Improved handling of missing player addresses and invalid stored data.
 
Secure Geolocation
  • Geolocation requests now use HTTPS.
  • Added configurable connection and request timeouts.
  • Successful lookups are cached to reduce external requests.
  • Private and local IP addresses are never sent to the provider.
  • Geolocation can be completely disabled in config.yml.
  • The provider URL and cache duration are configurable.
Permissions & Staff Tools
 
Added and documented the following permissions:
 
noaltsexploits.admin
noaltsexploits.moderator
noaltsexploits.admin.notify
noaltsexploits.bypass
 
Moderators can use the info command without seeing sensitive IP or geolocation data. Unauthorized users are now rejected before account information is accessed.
 
A new command has also been added:
 
/nae placeholders
 
This displays a quick overview of the available PlaceholderAPI placeholders.
 
Additional Improvements
 
  • Update notifications now appear only when the remote version is actually newer.
  • Improved IP-history pagination and validation.
  • Added dynamic %max_same_ip% support to the kick message.
  • Updated PlaceholderAPI compile support.
  • Synchronized the plugin version and generated JAR filename.
  • Bundled and relocated Gson to prevent dependency conflicts.
  • Removed unused dependencies and legacy code.
  • Added automated tests for cooldown matching, version comparison, and household roles.
  • The plugin now targets Java 17 for wider server compatibility.
 
Upgrade Notes
 
Existing configurations and stored data remain supported.
 
Unnamed household entries are automatically recognized as group-1, group-2, and so on. The old advanced-detection setting remains accepted for compatibility, but command matching is now safely handled automatically.
 
Geolocation remains enabled by default. Server owners who do not want external IP lookups can set:
 
geolocation:
  enabled: false
 
Please consider leaving a good review for the plugin.
6.6 Aug 19, 2026
Maintenance update

NoAltsExploitsVelocity 6.6 Changelog
Fixed

  • Fixed IP-based command cooldowns not reading nested commands-per-ip config values correctly.
  • Fixed cooldown storage to work with both SQLite and MySQL.
  • Fixed command blocking so cancellations happen immediately during command execution.
  • Fixed whitelist matching for multi-word commands like cmi msg and cmi server.
  • Fixed admin command page validation for /naev iphistory.
  • Fixed unreachable tab-complete logic for /naev removeaccount.
  • Fixed broken/encoded section-symbol color messages.

Changed

  • Reworked command parsing to use case-insensitive command prefixes.
  • Cooldown attempts that are denied no longer refresh the cooldown timer.
  • JDBC drivers are now bundled into the plugin jar instead of downloaded at runtime.
  • Updated build metadata and dependency versions.
  • Centralized plugin version/name metadata so the plugin annotation and startup banner match.

Improved

  • Added better tab completion for /naev subcommands.
  • Added IP suggestions for /naev removeaccount <player> <ip>.
  • Improved database error logging.
  • Updated default config comments to explain whitelist and cooldown prefix matching.


Please consider leaving a good review for the plugin.
Discord Support

6.4 Mar 28, 2026
velocity improvements
  • Fixed false alt-account history entries on failed joins.
    IP history is now only recorded after a player successfully connects to their initial backend server, instead of during the earlier login phase.
  • Improved max-accounts detection accuracy.
    Recent successful connections are now used for account checks, helping reduce false positives from older or stale IP history.
  • Fixed same-house alt group handling.
    Configured same-house alt accounts are now checked only against their own group instead of mixing with alt accounts from other configured households.
  • Fixed max IP online edge cases.
    The plugin now handles unset or disabled max IP online values more safely.
  • General stability and login-flow improvements.
    Adjusted connection tracking logic to better match real network joins and reduce incorrect alt-account blocks.
Please consider leaving a good review for the plugin.
Discord Support
6.2 Feb 21, 2026
fixes and perforamnce

- Stopped doing file saves while players join/leave, so it won’t slow down the main server loop.
- Made saving happen in the background and “batch up” lots of changes into one save.
- Made saves safer so files don’t get half-written or corrupted if the server stops suddenly.
- Made sure what gets saved is a stable snapshot, not changing mid-save.
- Removed the old extra save system so there’s only one clean way of saving.
- Made sure the plugin still saves one last time properly when the server shuts down.

Please consider leaving a good review for the plugin.
Discord Support

6.0 Feb 5, 2026
velocity 3.5.0 fixes and improvements

For the new velocity version.
Fixed the plugin not starting (startup error).
Fixed the plugin “logger” issue that caused a crash on boot.
Made the plugin create its data folder safely.
Improved config file creation/loading so it won’t crash if the config is missing.
Fixed a setup problem so Velocity can load the plugin correctly.
Added safer handling for missing settings to prevent random errors.

Please consider leaving a good review for the plugin.
Discord Support

5.8 Jan 5, 2026
safefty compatibility
- Made history entries more resistant to potential corruction for various edge cases or crashes.
- Incase the plugin finds a corrupt entry, it will provide a report and continue to work correctly regardless.
 
Please consider leaving a good review for the plugin.
5.7 Dec 29, 2025
Fixes and options :)
- Fixed: Alias cooldowns now properly save/load from alias_cooldowns.json (previously stored in the wrong file).
- Fixed: Per-IP cooldowns now mark data dirty on use, improving persistence after restarts/crashes.
- Added: Configurable update notification message (settings.update-available-message) + corrected typo.
- Internal: Reduced duplicate command handler instantiation.
 
Please consider leaving a good review for the plugin.
5.5 Nov 11, 2025
Error fix, maintaince

Fixed rare database error for batch writes.
Better performance.
Small organization improvements.


Please consider leaving a good review for the plugin.
Discord Support

5.4 Oct 26, 2025
Page 1
Sign in
$6.89 USD
Sign in to purchase, save this product to your cart, and keep downloads tied to your account.
Stripe