Voxel Shop beta is live. Expect occasional bugs. Learn more  
JustBans icon

JustBans v1.3.8

A modern, high-performance, and network-ready punishment system.

Page 1
v1.3.8 7 days ago
v1.3.8

[1] Fixed reports and punishments for players who have not joined the current server. Names are resolved from the shared player database, including confirmations, broadcasts, webhooks, ban screens, network kicks, the punish menu and notes.

[2] Fixed unresolved statistics in history, notes and punishment-detail menus. Player heads now show alt accounts, total punishments, active bans and mutes, warnings, kicks and notes. All of these heads respect justbans.staff.viewip.

[3] Fixed legacy colour codes in punishment reasons written by other plugins. Text that cannot be parsed falls back to plain text.

[4] Expanded ender-chest snapshots are paginated in the preview. Restores report items that cannot fit in the current chest.

[5] Staff inventory restoration handles changes in inventory size and drops overflow at the staff member's feet. A failed slot no longer interrupts the rest of the restore.

Staff tools

[6] settings.block-drops also blocks drops from an open inventory while in staff mode.

[7] Gamemode buttons in the staff panel require justbans.staff.gamemode.

[8] Frozen players can receive a persistent boss bar, repeating titles and a clickable Discord reminder. Each is configurable and can be disabled.

[9] Added /freeze <player> [on|off] and clickable Punish, Inspect and Unfreeze buttons.

[10] Replay viewers are hidden from other players, including players who join during playback. Set replay.hide-viewer to false to disable this. Existing vanish state is preserved.

[11] Check, history, notes and punishment-detail menus open on the viewer's scheduler on Folia.

Network and dashboard
[12] The dashboard groups backend servers under their proxy and displays platform, player count, TPS and availability. Servers publish a heartbeat every ten seconds and are matched to proxy entries by address. The panel is hidden on a single server.

[13] Added /justbans configsync with a preview and confirmation token. Receiving servers back up replaced files and reload. Licence keys, database settings, server identity, sync secrets, the proxy switch and api.yml are excluded.

[14] Config pushes are signed with the network sync secret and limited to the supported configuration files. Set sync.accept-config-pushes to false to disable receiving.

[15] Internal server addresses in the dashboard require the manage permission.

[16] Fixed MARIADB database type handling for server registration, config sync and schema migrations.

[17] The Reports HTTP API supports claiming, unclaiming, replying, marking reports handled and reading action history. Claim identity and power come from the authenticated session. Handling and unclaiming respect claim ownership and staff power. Replies are stored with their history before delivery, sent as plain text, and kept queued if the reporter disconnects before receiving them. Added integration tests for permissions, request limits, concurrent actions, transaction rollback, migrations and delivery.

Other changes

[18] Warning escalation now runs the configured warnings.actions command when the active warning count matches its threshold. Expired warnings are excluded. The default command example uses a command available on backend servers.

[19] Tab completion suggests online players from the local server and network. settings.tab_complete_offline_names restores stored names, limited by tab_complete_offline_limit. Proxy commands also suggest connected players and temporary punishment durations.

[20] Added banned-login alerts for justbans.notify.attempts, limited to one per account per minute.

[21] Added PlaceholderAPI staff-state placeholders and online counts for vanish, staff mode, freeze and staff chat, plus staff-permission state. Status placeholders use the labels in staff.yml; the new vanish_enabled, staff_mode_enabled, freeze_enabled and staffchat_enabled forms return true/false. Server-wide counts also work without a player context. All state lookups avoid blocking database queries.

[22] Fixed YAML boolean parsing of the yes/no/on/off status-label keys. The staff.yml update restores the quoted keys and removes the old boolean keys.

Minecraft 26.3
[23] Updated PacketEvents to 2.14.0 for Minecraft 26.3 packet support. Install PacketEvents 2.14.0 or newer for packet replays and vanish glow. Replay arm swings now use the new swing-animation packet on 26.3 and retain the previous packet on older servers.

[24] Added a local API compatibility matrix from 1.21.4 through Paper 26.3 build 42 (alpha), using separate Paper and Folia classpaths. Release builds still compile against the 1.21.4 API. Java 25 is required for 26.x servers. Paper 26.3 is experimental; Folia has no published 26.3 build yet.

[25] Fixed replay skin-layer metadata on 1.21.4 through 1.21.8. The renderer now uses index 17 on those versions and index 16 from 1.21.9 onward, with regression tests covering the supported range.
Updating

[26] The database updates to schema v23 automatically, adding config-sync, server-register and report-history tables, widening the report target-name column and marking queued replies as plain text. Existing formatted feedback is preserved. Configuration files receive their new keys automatically. Grant justbans.command.freeze to ranks that need /freeze. Replace self-hosted dashboard files to receive the network panel and updated report API client.

v1.3.7 Aug 23, 2026
v1.3.7

A proxy can moderate on its own, staff mode and vanish can be set on other players, and their state is readable as placeholders. Nothing to migrate.


Proxy


[1] A proxy can now issue punishments, not only enforce them. Turn on proxy.moderation in the proxy's config.yml and it handles /ban, /tempban, /ipban, /unban, /mute, /tempmute, /unmute, /kick, /warn and /check itself, enforces mutes in proxy chat, and records names and addresses at login so IP bans have something to read. That is for networks running justBans only on BungeeCord or Velocity, which until now could turn banned players away and nothing else.


[2] It is off by default. On a network with a backend those commands belong there, where they have the GUIs, and the proxy sees a command before the backend does. A proxy pointed at a database no backend has ever set up now says in its console that the switch exists and how to set it.


[3] Punishments issued on a proxy are written exactly as a backend writes them and queued on the same table, so adding a backend later gives one shared history rather than two. The GUIs, replays, detection, reports and the dashboard still need a backend.


[4] Fixed two console errors on proxy-only databases. Every punishment logged "Table 'db.justbans_sync_events' doesn't exist" and every unban logged "Unknown column 'removed_by_name'", because both were found out by failing rather than by asking first.


Staff mode and vanish


[5] /vanish and /staff now take a player: `/vanish Notch`, `/staff Notch`. Before, both only ever toggled whoever ran them, so a staff member who logged off vanished, or handed back an account still in staff mode, could only be fixed by that account.


[6] Both also take an explicit state: `/vanish Notch off`, `/staff Notch on`, and `/vanish off` for yourself. A plain toggle is a guess when you cannot see the current state, which matters from console, a command block or a script. Asking for the state something is already in says so instead of doing nothing.


[7] Naming somebody else needs its own permission, justbans.command.vanish.others or justbans.command.staff.others. The ordinary justbans.staff grant does not include them, so a staff member cannot pull another one out of staff mode unless you say so. Both default to op.


[8] Four new lines in staff.yml under messages: vanish-other-on, vanish-other-off, staff-other-on, staff-other-off. They are added to your file on first start.


Placeholders


[9] Added status placeholders for staff mode, vanish, freeze, staff chat and CPS, plus counts of how many are online: %justbans_is_vanished%, %justbans_vanish_status%, %justbans_is_staffmode%, %justbans_staffmode_status%, %justbans_is_frozen%, %justbans_frozen_status%, %justbans_is_staff%, %justbans_in_staffchat%, %justbans_staffchat_status%, %justbans_cps%, %justbans_staff_online%, %justbans_staffmode_count%, %justbans_vanished_count%, %justbans_frozen_count%. The is_ ones answer Yes or No like is_banned; the _status ones use the words from staff.yml, so they follow your language.


[10] None of them touch the database. Staff state is already in memory, and the four counts are recounted at most once a second, so they are safe in a scoreboard or tab list that refreshes every tick.


Updating


[11] Nothing to do from 1.3.6. config.yml gains the proxy section, off by default, and staff.yml gains four message keys and two words. Both are added to your files on start.

v1.3.6 Aug 17, 2026
v1.3.6
A fix release on top of 1.3.5, plus a setup wizard for the dashboard. Nothing to configure, nothing to migrate.
 
Security
 
[1] The proxy no longer passes network sync traffic on to players. Both BungeeCord and Velocity forward anything a plugin does not claim, and every message on the justbans:update channel starts with the shared sync secret. That secret is what stops a modified client sending fake punishment messages, so handing it to every connected client defeated the point of having one. Anyone running a network should treat their old secret as known: clear sync.secret in config.yml and let a new one be made, or set a new one on every server.
 
Fixes
 
[2] Fixed banning an offline player wiping the address that account was last seen from. That address is all that alt scans, IP bans and ban evasion have to go on, so the account dropped out of all three and the next account from the same connection walked in unchecked. Banning someone after they log off is the normal case, so this hit chat, the dashboard and reports alike. Bans made while the player was online were never affected.
 
[3] Fixed the proxy never disconnecting a player who was on another server. It asked the proxy by account id, but the proxy expects a name, so it dropped every one of these silently. In practice sync usually caught it first, which is why it went unnoticed. With sync off, or when the sync message did not reach the right server, the player simply stayed online.
 
[4] Fixed punishments issued from a server with nobody on it not reaching anyone. Sync travelled only inside a player connection, so an empty server could not send at all. Ban someone from a quiet lobby while they were playing on another server and nothing happened to them until somebody joined the lobby. The punishment was stored correctly the whole time, which is what made it easy to miss. Servers on a shared MySQL database now hand these to each other through the database as well, so it no longer matters who is standing where. Checked every 3 seconds, tunable with sync.queue-poll-seconds.
 
[5] Fixed staff not being told about ban evasion when one of the accounts was new to the server. The ban still landed, so the only sign was a stack trace in console.
 
[6] Fixed an update skipping columns when the MySQL server holds more than one justBans database. The checks for "does this column already exist" looked at every database on the server and matched on the table name alone, so a test copy beside the live one, or another customer's, made the column look present and it was never added. Anything reading it then failed. If you run more than one justBans database on one MySQL server, start each server once after updating and the missing columns are added.
 
Proxy
 
[7] The proxy now says what is wrong when the database has no justBans tables and it cannot make them either, which usually means its database user has no rights to create tables. Before, it reported a good connection and then threw a raw SQL error for every player who logged in, naming neither the cause nor the fix.
 
[8] A proxy started before any backend now sorts itself out. It looks again every 30 seconds and switches on once the tables exist, so start order no longer matters and there is nothing to restart.
 
[9] The BungeeCord and Velocity plugin entries said version 1.3.3 whatever was installed. They now show the real one.
 
[10] Velocity now checks the ban off its event thread. It used to run both queries inline, holding one of Velocity's event threads for the whole round trip. That is fine against a local database and not fine against a busy or remote one, especially with a lot of players reconnecting at once. BungeeCord already worked this way.
 
[11] A proxy pointed at an empty database now creates the two tables it reads, so it can enforce bans on its own instead of failing every login. Worth being clear about what that does and does not give you: the proxy only turns banned players away. It has no commands. /ban, /mute, the GUIs and the web dashboard all live on the backend plugin, so you still need justBans on at least one Paper or Spigot server to issue anything. Starting one later fills in the rest of the schema by itself.
 
Dashboard
 
[12] Added a setup wizard in game. /dashboard setup lists the three ways to run the dashboard - the plugin serving it, the central dashboard on deltura.net, or your own hosting - and each one writes its own keys, restarts the API and then makes a real request to the port to see what answered. The plugin-served option finds the web files wherever the zip was extracted and checks the script bundle loads, not just index.html. The central one checks a license key is set first, since the heartbeat is keyed on it, and opens the bind address because nothing outside the machine can reach a loopback one. The self-hosted one clears the file path and checks cross-origin calls are allowed, then gives you the API address to paste in. /dashboard status says what is running now, /dashboard howto <option> explains one of them. Admin only.
 
[13] The console now says whether the dashboard is actually being served. A dashboard-path with no index.html in it was the quietest way for this to go wrong: the server started, the log said the API was running, and every browser got the API's JSON status page with nothing anywhere explaining why. It now names the path it tried and where the files look to be instead.
 
[14] Fixed dashboard-path being read only against the working directory. Started from somewhere other than the server folder - a systemd unit, some panels - and the relative path from the setup guide resolved to nothing, so the dashboard silently did not load. Both are tried now.
 
Other
 
[15] The ban-evasion check on join is now one database query instead of one per account on the address. It used to fetch every account seen from that address and then ask about each one separately, waiting for each answer before starting the next. On an address several accounts share, a household, a school, a VPN exit, or a proxy that is not forwarding real addresses, that was dozens of round trips before anyone could get in.
 
[16] Added bStats. It reports how many servers run justBans, which storage they use, and whether sync, replay, detection and the dashboard are on. No server, player or punishment data is sent. Opting out is the usual global setting in plugins/bStats/config.yml.
 
Updating
 
[17] Nothing to do from 1.3.5. config.yml gains one key on first load and the database gains one small table for cross-server delivery, both applied automatically. Accounts banned while offline before this release pick their address back up the next time they log in. If you run a network, change your sync secret as described above.
v1.3.5 Aug 4, 2026
v1.3.5

Mostly about catching cheats and making replays show what actually happened. Your configs, messages and database keep their values. config.yml adds the new keys on first load, and the two recording toggles now default on.


X-ray detection


[1] Added an X-ray detector, alongside the CPS, reach and duping ones. It does not count how many diamonds someone finds, it asks how they reached each one. A short trail of the blocks a player just broke is kept, and when they break a watched ore its six sides are checked. If the only opening was a block from their own tunnel, the ore was found blind, because nothing natural ever exposed it. That verdict carries along a whole vein, so a vein found in a cave never counts as blind.


[2] A blind find alone is not enough, since a diamond in a strip mine wall also looks blind. So four methods run together and any one can alert, while two agreeing raises the severity. One needs finds to be blind and barely dug to, which leaves honest strip mining alone. One catches a run of blind veins, for rare ores where the sample stays tiny. One catches digging straight at each hidden ore, measured per dig so it still fires when someone hops from ore to ore. One catches reaching several different rare ores blind at once. All tunable, creative and spectator are never checked.


Fake stash honeypot


[3] Added /fakestash, which hides a trap container one block behind you. A normal player never finds it, so anyone who opens it gave themselves away. The open is cancelled so no bait is taken, staff get an alert with a replay link, and any commands you set are run. Types and loot are configurable, placed stashes survive a restart, and it cannot double trigger.


Replay


[4] Replays now show blocks changing instead of only the end result. Breaking, placing and right click state changes like charging an anchor all play back and rewind in step. Explosions replay with their particles and sound, and the blocks they destroyed are rebuilt, so an arena blows apart at the right moment instead of loading already cratered.


[5] Recorded players show their real username and the watched one is outlined, so you can pick them out in a busy scene. Their main hand follows the recording frame by frame, so a weapon swap plays back when it happened instead of showing one item frozen at capture time.


[6] The Replaying line says whether a capture was manual or automatic, and names what detected it. The timeline marks damage, containers and detections, so a fight is easy to read at a glance.


[7] record-entities and record-containers default on, so a capture carries the surroundings and container log without turning them on first.


[8] Replays fired by Legion(Tester only Plugin) are labelled as Legion rather than as a plain automatic capture, with their own icon in the replay list, so staff can tell at a glance what asked for a recording. The label and icon are both configurable in gui.yml. (Possible with the updated API in this version)


API


[9] The API ping now proves which server answered, for servers on the central dashboard. It returns a keyed fingerprint of the licence and a stable id for that install, so the dashboard can confirm the justBans it reached is really yours before forwarding a staff login. This matters on shared hosting, where the address is shared and ports move. Nothing is published for servers that have not enabled the central dashboard, and the fingerprint never contains the licence key.


[10] JustBansAPI gained replay methods, so another plugin can work with replays without reaching into internal classes. Ask whether recording is on, mark a moment, capture a replay and get its id, and get the command and permission for watching one. Safe to call from any thread, and nothing throws when recording is off. A capture through the API is stored under the calling plugin's name.


[11] Added POST /api/v1/replay/capture so a plugin can start a recording over HTTP. The plural /api/v1/replays path now also accepts the single replay routes.


Fixes


[12] Fixed the container view opening nothing for any chest smaller than a double chest.


[13] Fixed blocks lagging a tick behind the action. They now land on the same tick as the movement.


[14] Fixed a one shot kill printing a 39 digit damage number. It shows a lethal marker instead.


[15] Fixed the Container Log toggle in the modules dashboard sitting on the border instead of the grid.


[16] Fixed the container log missing interactions. Every container a player opened is now recorded, not only ones whose contents changed, so looking into a chest shows up. The empty message no longer tells you to enable a setting that is already on.


[17] Fixed a rebuilt scene turning into a curtain of waterfalls. The captured cube is a slice cut out of the world, so any water it cut through poured out into the void. The cut faces are sealed now, and the replay world no longer grows, decays or burns anything.


[18] Fixed a replay dropping into the live world without saying why. It now tells you in chat instead of only the console. Scene cells abandoned mid build are also released again, so replays stop being pasted on top of a scene that is already standing.


[19] Fixed dropped items being invisible. Their stack is re-sent over the first frames in case a packet was lost, an item that fails to convert falls back to a plain one instead of showing nothing, and items recorded before Minecraft renamed the type spawn again. They also hold their recorded path instead of sinking.


[20] Fixed the lag spike when a replay is captured. Copying the surrounding chunks now stops at a tick budget as well as a chunk count. A detector firing repeatedly no longer captures once per alert, since those all cover the same window. Captures staff run by hand are never held back.


[21] Cut the recorder's standing cost. Scanning for nearby entities ran for every player on every sample whether or not a replay was ever captured. It now runs every second sample and the frames between reuse the last result, so replays look the same and the cost roughly halves.


Updating


[22] Nothing to do to update from 1.3.4. config.yml adds the new keys on first load and turns the two recording toggles on where you had not changed them. Your own values are kept, and nothing in the messages or database changes.
v1.3.4 Jul 24, 2026
v1.3.4

justBans 1.3.4


This update is about running justBans across a network and about how it reaches Discord. Inventory rollbacks now know which server each snapshot came from and can be filtered to one server or a server group, snapshots are taken when a player joins so a server switch is captured on the server they land on, and punishments from the menu can preview the next step in a preset's ladder before you apply them. Discord webhooks gained the option of the new Components V2 layout. Everything new is off or unchanged by default unless noted, and configs, messages and the database auto-update from 1.3.3 on the first load, keeping your own values.


Punishment escalation preview


[1] Reasons in the punish menu can now be tied to a preset. Give a reason a preset in gui.yml and picking it applies that preset's escalating duration automatically and skips the duration picker, so the menu escalates the same way /ban <preset> already does. A reason without a preset behaves exactly as before.


[2] The confirm screen then previews the whole ladder: every step, with the one being applied now and the one a re-offense would trigger both marked, so you see at a glance what this punishment is and what the next one will be. Menu punishments issued this way are recorded against the preset, so the count stays right over time.


Inventory rollback across servers


[3] On a network that shares one database, every inventory snapshot is now tagged with the server that took it and that server's group, so you can always tell where a snapshot came from. The rollback list shows the origin on each snapshot.


[4] The list gained a filter that cycles between all servers, only this server, and only this server's group. Set a server-group in config.yml and a cluster like survival-1 and survival-2 shows as one, which is what you want when they share inventories. /rollback <player> <server> opens straight into one server's view.


[5] Snapshot retention is now per server, so a busy lobby no longer prunes away a survival snapshot and the other way around. Snapshots from before this update still show and restore, listed with an unknown origin.


Snapshots on join and server switch


[6] Inventories are now snapshotted when a player joins, not only on death and disconnect. On a network a server switch is a disconnect on the old server plus a join on the new one, so a hop from Lobby to Lobby2 is captured on Lobby2 and tagged with that server automatically. The capture waits a few seconds so cross-server inventory sync has loaded the items first, and is skipped if the player leaves again before then. Turn it off with on-join in config.yml.


Discord Components V2


[7] Webhook messages can now use Discord's Components V2 layout instead of the classic embed: a coloured container with the player's head as a thumbnail, the fields as text and separators between them. Pick it with style: components in webhooks.yml, globally or per destination. The same templates drive both, so switching only changes the look, never what is sent.


[8] Reasons and names can never mention anyone in either style, so a reason containing @everyone will not ping the server. The default is still the embed, so nothing changes unless you ask for it.


Freeze


[9] When a frozen player logs out, they are now flagged. Opening /check on them shows a "Logged out while frozen" warning in the bottom-left of the menu, so a staff member who missed the chat alert still knows the player left mid-freeze. The flag clears itself the moment the player is unfrozen or punished.


Menus


[10] The /check menu now uses the same darker glass as the newer menus, so the moderation menus read as one set.


Fixes


[11] Fixed the container view in a replay opening nothing. Viewing a chest a player had opened threw an error for any container smaller than a full double chest, so the [view] button and /replay chest did nothing at all. The controls now size to the container, and the view opens.


[12] Fixed the modules in the /justbans modules dashboard sitting against the right edge instead of lining up in the grid.


[13] Fixed the Components V2 webhook layout being rejected by Discord. A failed webhook now also logs the reason Discord gave, with the webhook's secret hidden from the log.


[14] Fixed the "logged out while frozen" alert showing a stray formatting tag in chat.


Updating


[15] No changes are needed to update from 1.3.3. Every config and message file adds only its new keys on the first load and keeps your existing values, and the database adds its new columns on startup.

v1.3.3 Jul 23, 2026
v1.3.3

This update builds on the replay and detection systems from 1.3.2. The headline is the isolated replay environment, which rebuilds the scene a replay was recorded in so watching one no longer drops staff into a live area. Everything new is off by default unless noted, so a plain drop-in keeps your server exactly as it was. Configs and messages auto-update from 1.3.2 on the first load, keeping your own values.


 


Isolated replay environment


 


[1] Added an isolated replay environment (replay.isolated-environment). When a replay is made, the plugin captures the blocks around the player. When staff watch it, that exact scene is rebuilt in a private world and the replay plays there, instead of teleporting staff into the live world at the recorded spot. On a minigame server that recorded spot is an arena reused for other matches, so before this staff would land in whatever match was running there.


 


[2] The capture is light. It takes chunk snapshots on the tick, which is quick, and does the per-block read and compression off the main thread, so recording does not lag the server. The stored scene is compressed and an area that is mostly air takes very little space.


 


[3] The rebuild streams in over several ticks with a "Replay is building..." action bar that counts up to 100 percent, then playback starts the moment the last block lands. Streaming the paste keeps the rebuild from freezing the server even for a large area. The scene is cleared again when the replay ends.


 


[4] The captured area is configurable: a radius each way around the player (up to 64) and a height above and below, plus the name of the private world it rebuilds in.


 


[5] Two staff can watch isolated replays at the same time without treading on each other. Each one gets its own cell in the private world, so two recordings made at the same arena coordinates never paste over each other. The capture also only reads chunks that are already loaded, so it never stalls the server pulling in far terrain.


 


[6] The isolated environment runs on Folia as well as Paper. Every slice of the rebuild is grouped by chunk and handed to the region that owns it, which is what Folia requires for block writes. The one thing Folia will not do is create a world while running, so on Folia the replay world has to be made once up front and the server restarted; until it exists, playback uses the live world and the log says why. On Paper the world is created for you.


 


Dedicated replay server


 


[7] Replays can be moved off your main servers entirely. Set dedicated-server to the proxy name of a server that hosts replays, and clicking Watch sends the staff member there through the proxy; that server starts the playback when they arrive. The handoff goes through the shared database, so both servers need the same MySQL database. Leave the field empty to keep playing on the same server, which needs no proxy and no MySQL.


 


Reach and CPS detection


 


[8] Added a CPS detector. Every arm swing is a click, and the last second of swings is the live CPS. It alerts when a player holds a CPS a human hand cannot sustain, which is what an auto-clicker does. The threshold is configurable and defaults to 16, since a fast human tops out around 12 to 14.


 


[9] Added a reach detector. It measures the distance from the attacker's eye to the target's hitbox on each melee hit. A single over-reach can be lag, so an alert needs several within a window. The distance and the number of hits are both configurable, with the distance defaulting to 3.3 blocks, a little above the survival melee range.


 


[10] Both detectors feed the same pipeline as the existing ones, so they show up as staff alerts, attach a replay, appear back inside a replay with the REPLAY tag, and can fire a Discord alert, all with the same LOW, MEDIUM, HIGH and CRITICAL severities.


 


[11] The staff Inspect menu now shows a player's peak CPS and their current and peak reach, next to the live CPS it already showed.


 


[12] While a replay is playing, the recorded player's CPS and reach for the frame you are watching are shown above your hotbar. The values are recorded per frame alongside the movement, so you can see exactly what their click rate and reach were at the moment something happened. This is recorded while detection is on, and older replays simply do not carry it.


 


[13] Added a check tool at /justbans checktool. It is a menu that edits the CPS and reach thresholds live: the master toggle, each detector on or off, the CPS threshold, the reach distance and the number of reach hits before an alert. Left-click raises a value or enables a toggle, right-click lowers or disables it, and shift makes a bigger step. Changes are written to the config and applied straight away.


 


Rollback webhook


 


[14] Added a rollback webhook. When staff restore a player's inventory or ender chest from a snapshot, a Discord alert is posted with the player, the staff member, the snapshot and what was restored. Set the URL in configs/webhooks.yml under rollback to switch it on. Empty means off.


 


Menus and messages


 


[15] The rollback menus and all five replay menus (the player picker, the replay list, the playback options, the container log and the before and after viewer) are now driven by gui.yml, the same way the punish menu already was. Titles, filler, and every button's slot, material, name and lore are yours to change, with placeholders for the values that vary. Anything you leave out keeps its current look.


 


[16] Every message the replay and rollback features send is now a key in messages.yml, including the "Replay is building..." and "Replay ready" action bars and the in-replay CPS and reach line, so each one can be reworded or translated. The check tool's layout, and the two new detectors, sit in the same config files as the rest.


 


Fixes and hardening


 


[17] Went back over all of the above and fixed what the review turned up. Stopping a replay while its scene was still building could leave you stuck in a session you could not end; the handoff now checks the replay is still yours before it starts. Capturing near unexplored terrain could stall the server while it generated chunks, so capture now only reads chunks that are already loaded. Two staff watching replays from the same arena could overwrite each other's scene, which the per-viewer cells above now prevent. The replay server also checks a staff member still has replay permission before starting a replay it was sent, rather than taking the sending server's word for it.


 


[18] Fixed the LiteBans import failing with "Data type TIMESTAMP cannot be decoded as Long" and importing nothing. LiteBans does not store all of its time columns the same way: some hold plain millisecond numbers while others are TIMESTAMP columns, and which is which changes between its MySQL, MariaDB, PostgreSQL, H2 and SQLite backends. All of them are now read in a way that copes with either. The import runs in a single transaction, so the failure rolled everything back and nothing was half-imported; just run it again.


 


[19] Fixed the staff Inspect ender-chest view cutting off anything past the 27th slot. If another plugin gives your players a bigger ender chest, staff were quietly seeing less than half of it. The view now sizes itself to what is actually stored: every row that holds an item, plus a row for the Back button. Four rows of items give a five-row menu. When items fill all six rows there is no space left for a button row, so the Back button sits in a free slot of your own inventory while you look and is removed when you close. It only ever uses an empty slot, so none of your own items are touched.


 


Watching a replay


 


[20] Replays now narrate the fight in chat as it happens. Each hit is read back at the moment it landed, either "Zombie hit f_h for 3.5" or "f_h took 6.2 from FALL" when nothing attacked them. An arrow is credited to whoever fired it rather than to the arrow. Every line can be clicked to jump the replay straight back to that hit, and hovering shows the time and frame. Both sides of a fight are recorded, so the same exchange reads correctly whichever player's replay you open.


 


[21] Added a sidebar while watching that carries the replay's id, so you can note it and open the same recording again with /replay play <id>. It is sent when playback starts and redrawn only when someone joins or leaves, and the running clock stays on the boss bar, so it costs almost nothing. Title and lines are configurable and it can be switched off.


 


[22] Added /replay seek <frame>, which is what the clickable combat lines use to jump back to a hit.


 


Replay fixes


 


[23] Recorded players never moved their arm. The recording carried a swing flag and playback already knew how to show it, but nothing ever set the flag, so every replay was silent-armed. Swings are recorded now.


 


[24] Nearby entities flickered, and copies of them could be left hanging in mid-air. Two separate causes: the recorder took an arbitrary slice of the entities in range rather than the nearest ones, so a different set could be picked each frame and entities kept dropping out and coming back; and a replay could leave its copies behind for the next one to inherit. Both are fixed, so entities stay put and starting another replay clears anything left over.


 


[25] The rebuilt scene only covered where a recording started, so a player who ran any distance walked out of it into empty space. It now follows the whole path, bounded by a max-blocks budget so a long run does not turn into a huge file or a slow rebuild.


 


[26] Fixed the combat lines dropping hits that landed close together. Several hits regularly share one recorded moment, and only the first was being shown; a four-hit exchange came out as two lines.


 


[27] Fixed a few things around capturing and leaving a replay. Capturing along a long path could ask the server for far too many chunk copies at once, which is now capped. An oversized captured scene could fail to save and take the whole recording with it; the scene is dropped instead and the replay is kept. Leaving a replay did not always put you back where you started, which is now done with a teleport that is checked afterwards and retried. And if the server stops or crashes while you are watching, you are returned to spawn on your next login instead of being left in the private replay world.


 


[28] Staff can now watch a replay together. Opening a replay someone is already watching joins them instead of starting a second one, so everyone shares one timeline and, with the isolated environment on, one rebuilt scene rather than a copy each. The sidebar lists who is watching. If the person who started it leaves, the replay keeps running for the others and is only cleared away by the last one to leave.


 


[29] Fixed being disconnected with a network protocol error while watching. The sidebar is redrawn when someone joins or leaves a shared replay, and the redraw announced the scoreboard as new each time. Telling a client to create a scoreboard it already has is a protocol violation, so the connection was dropped. The redraw now removes the old one first. Two viewers whose names render identically no longer collide on the list either.


 


[30] Watching a replay no longer drops you inside a wall. The viewpoint was placed a fixed few blocks sideways of where the player started, which in a rebuilt scene could be solid rock, a black screen. It now steps back along the way the player was looking to the nearest open spot, and never inside a block.


 


[31] Your own items can no longer be lost by watching a replay. The control belt replaces your inventory while you watch and your real one comes back when you stop or quit, but a server crash mid-replay left no chance to restore it and the belt was what got saved. Your inventory is now also copied to disk the moment the belt goes on and put back on your next login, so a crash cannot eat it.


 


More in the replay viewer


 


[32] Added a Players button to the replay options menu (F). It lists the recorded player and anyone who was near them, and clicking one teleports you to that player at the exact moment you are watching, so you can follow a specific person through a fight.


 


[33] You now watch blocks get broken and placed instead of finding them already gone. The rebuilt scene used to show only the final state, so anything the player mined had vanished the moment it loaded. Every break and place is recorded with its timing now, and the scene plays them back in step with the movement, rewind included. It needs the isolated environment and only works on replays recorded from now on; older ones still show the final state.


 


Moderation


 


[34] Added /clearhistory <player>. It wipes a player's whole punishment history, active records and all, so someone can be given a clean slate. Because that cannot be undone, the first run only warns you and shows what to type; you confirm with /clearhistory <player> confirm. It needs justbans.command.clearhistory, which ops have by default.


 


[35] No changes are needed to update from 1.3.2. Every config and message file adds only its new keys on the first load and keeps your existing values and layout, and the database adds its one new table on startup.

v1.3.2 Jul 15, 2026
v1.3.2

This is a large update. The headline additions are the replay system, smart activity detection, inventory rollback, the web dashboard and full plugin protection. Everything below is off by default unless noted, so a plain drop-in keeps your server exactly as it was.


Replay system


[1] Added a movement replay system. With replay.enabled on, the plugin keeps a short rolling buffer of each player's movement so staff can capture and rewind the last seconds after a report or a flagged moment. Open replays with /replay, the staff panel, or straight from a detection alert.


[2] Replays are watched as a real, invisible flying viewer, not in spectator. You keep a hotbar of controls (rewind, play or pause, speed, restart, timeline, container log, stop) and press F for the full options menu. Your real inventory, gamemode and flight are saved when a replay starts and put back exactly when it ends, including if you log out mid-replay.


[3] Added a timeline you can scrub. Click any point to jump there, and every chest the player opened is marked on the bar so you can jump straight to it.


[4] The recorded player renders 1:1 with PacketEvents: their real skin (all layers), worn armour and held items, pose (sneak, sprint, swim, elytra) and arm swings.


[5] Nearby entities can be recorded and replayed (replay.record-entities). Mobs, dropped items and other players around the target are re-enacted, including when they entered and left. Dropped items show their real stack, and nearby players render with their own skin and armour.


[6] Container interactions can be recorded (replay.record-containers). Opening a chest, barrel, shulker, hopper or furnace is logged with a before and after snapshot, so playback shows exactly what was taken out or put in. A notice appears at the moment they open it, and you can open a read-only view to look inside.


[7] Detections that fired during a replay are shown back during playback, each at its exact moment with a REPLAY tag, plus an overview at the start listing which detection triggered the replay.


Activity detection


[8] Added smart activity detection. It flags duping and looting patterns (rapid container opens, sustained fast inventory moves, item drop floods, pickup floods) and alerts staff, with LOW, MEDIUM, HIGH and CRITICAL severities. It works on its own and does not need replay recording. On by default.


[9] The detector learns each player's own baseline and escalates on real deviations. Thresholds are deliberately conservative so normal play (sorting a chest, farming pickups, clearing an inventory) does not trip it, and staff are only pinged from MEDIUM up. Everything is configurable, and there is a Detection dashboard GUI with severity filters.


Inventory rollback


[10] Added inventory rollback. Snapshots are taken on death, quit and on a timer so staff can preview and restore what a player had. Restores bring back the full state: items, armour, off-hand, held slot, XP levels, food and item durability. Ender chests can be rolled back too.


Web dashboard and API


[11] Added the embedded web API and dashboard. Manage punishments, view player history, run punishments and browse the audit log from the browser, with login, optional two-factor and a license page. A central-dashboard reporter is included.


Reports


[12] Reworked reports. Clicking a report no longer double-triggers, chat report alerts open the report instantly, and staff can claim a report. A higher-power staff member can still act on a claimed report. Report presets have their own icons.


Punishments and staff tools


[13] Added voice mute through Simple Voice Chat, available in the punish GUI and as /voicemute and /unvoicemute.


[14] Punishment presets are filtered by action, so a mute only shows mute reasons and a ban only shows ban reasons, with more fitting templates added.


[15] The modules dashboard (/justbans modules) lists every feature with its real enabled or disabled state, including Detection, Replay Recording, Replay nearby entities, Replay container log and Inventory Rollback, and toggles them with one click.


[16] Missing dependencies (PacketEvents, Simple Voice Chat) are now reported clearly at startup, in the console banner, in-game and in the modules GUI when a feature that needs them is on.


[17] Added a LiteBans import (/justbans migrate-litebans) to bring an existing LiteBans database into justBans.


Cross-server


[18] Network sync is authenticated with a shared secret. On a shared MySQL database the secret is generated and shared automatically, so cross-server punishments and detection alerts just work with no manual key setup.


Fixes and stability


[19] Fixed muted players being unable to use unrelated commands such as /rtp; the mute command blacklist now matches the exact command, not any command that starts with the same letters.


[20] Fixed a shutdown error where cleanup tried to schedule a task after the plugin was disabled.


[21] Fixed several Folia crashes where repeating tasks were scheduled the wrong way.


[22] Config, GUI and message files auto-update safely from any older version: missing keys are added, your customisations are kept, and the file layout and header are preserved.


[23] Fixed the update notice showing twice on join and never flags an older version as an update. Reworded messages across the plugin for a plainer tone.


[24] Every GUI now fills its empty slots and has consistent back and close buttons, and Detection and Replays opened from the staff panel return to the panel.


Protection


[25] The plugin is now properly obfuscated: class, method and field names are renamed and string constants are encrypted with a fresh key per build. Only the handful of entry points loaded by name from outside stay readable. This is transparent at runtime and needs no configuration.


[26] No changes needed to update. Drop in the new jar and restart. Your config and data stay as they are. Replay recording, nearby-entity and container logging are off by default; turn them on if you want that extra detail.

v1.3.1 Jul 11, 2026
v1.3.1

[1] Fixed heavy server lag caused by placeholders. justBans placeholders (scoreboards, tab list, chat) used to hit the database on the main thread every time they were shown, which could freeze the server. They are now served from memory, so the lag is gone. Note: Only for those who are on 1.3.0

[2] Ban and mute status is now cached. Checks for bans, mutes and shadow-mutes are faster and stay in sync, with the database only touched in the background. Mute and shadow-mute work exactly as before.

[3] Hardened the web API. The API secret key is now checked in a way that can't be guessed through timing, closing a small security gap.

[4] No changes needed to update. Drop in the new jar and restart; your config and data stay as they are.

v1.3.0 Jul 8, 2026
v1.3.0

[1] The dashboard now uses real accounts instead of one-time login codes. Run /dashboard in-game and you get your own account with a random starting password, shown once as a line you can click to copy. From then on you log in on the dashboard with your username and that password, so there is no code to redeem every time. Forgot it? Run /dashboard newpassword in-game for a fresh one (being in-game is proof it is you).


[2] You can use the dashboard on Deltura, without hosting it yourself. Turn on central-dashboard in api.yml and your server shows up on the central dashboard at deltura.net: sign in with Discord, open your license, choose Manage then Open Web Management, and manage your server live. The plugin only tells Deltura your server is online (license, API port and version, nothing else); your data is read straight from your own server, never stored on Deltura's side. Hosting the dashboard yourself still works exactly as before.


[3] You can change your password and turn on two-factor authentication right from the dashboard. There is a new Account page: set a new password whenever you like, and add 2FA by scanning a QR code with Google Authenticator, Authy or any similar app. After that, logging in also asks for the 6-digit code.


[4] Admins can require 2FA for a group. Add require-2fa: true to a group in api.yml and its members must set up two-factor before they can use the dashboard. They can still sign in with their password, but until 2FA is on they only see the setup screen.


[5] The dashboard no longer logs you out on a refresh. A page refresh, a brief network hiccup or the server still starting up used to be able to drop your session. Now a slow moment just shows a short "reconnecting" state and the login comes back on its own; you are only ever signed out by a real logout or a genuinely expired login. Logins still survive server restarts.


[6] Passwords are stored securely. They are never kept in plain text: each one is salted and hashed with PBKDF2, and 2FA secrets follow the standard TOTP format, so nothing sensitive is readable in the database.


[7] Fixed the plugin not starting on servers without PacketEvents. If PacketEvents was not installed, the vanish glow could stop the whole plugin from enabling. Now glow simply turns itself off (with a note in the console) and everything else loads normally. PacketEvents is still only needed if you want the vanish glow.


[8] Your config files update themselves cleanly. When an update adds new options they are merged into your existing files with their comments intact, your own settings are always kept, and an option is added back even if you removed it by hand.


[9] Updating from 1.2.9 changes nothing else. The new account table is added automatically, your api.yml keeps all your settings (the new keys are merged in), and anyone already signed in stays signed in. The only change is the login method: the first time each staff member runs /dashboard they get their account and password.


[10] Works on Paper 1.21.11, 26.2.x, Folia, Spigot and BungeeCord/Velocity, same as always. All of the new account work runs off the main thread and is region-safe on Folia.
v1.2.9 Jun 29, 2026
v1.2.9
[1] Staff mode never loses your items again. If you disconnect, crash, or the server restarts while you are in staff mode, your real inventory is backed up the instant you go into staff mode and handed straight back the next time you log in, so a disconnect in staff mode can no longer leave you holding the tool belt with your real items gone. The staff tools are also kept out of that backup, so toggling staff on and off can never save them as your real items.
 
[2] That backup works across a whole network, not just one server. It is stored in the database, and each one is tied to the server you went into staff mode on, so your items are only ever restored there and can never overwrite a different server's inventory. Give each server a unique server-name in staff.yml so it can tell them apart.
 
[3] PremiumVanish and SuperVanish now hook in cleanly across their versions. Before, one missing API method could quietly switch the hook off and fall back to the built-in vanish, so the vanish tool in slot 0 ran justBans' own vanish and desynced from PremiumVanish. Now only the core hide and show methods are required, so the slot-0 vanish tool and vanish-on-enter go straight to PremiumVanish. The console logs "Hooked into PremiumVanish for vanish" on startup so you can confirm it connected.
 
[4] Some bugs & issues were fixed.
 
[4] Works on Paper 1.21.11, 26.2.x, Folia, Spigot and BungeeCord/Velocity, same as always. The staff teleports, inventory handling and player work all use Paper's region-aware scheduling so it stays safe on Folia.
v1.2.8 Jun 25, 2026
v1.2.8
[1] Tools and panel buttons now run actions. Drop an "actions" list on any tool or button and it runs what you list instead of the built-in behaviour, and you can add brand new tools and buttons too. You get [command] and [console] to run commands (with <player> for whoever you clicked), the built-ins like [vanish], [inspect], [freeze], [punish], [heal], plus menu openers and [close] / [refresh]. So a custom command tool, or a whole custom menu, is just a few lines of config. The choice between justBans vanish and another plugin is now just [vanish] versus [command] v.

 


[2] You can pick who handles vanish. Leave it on the built-in one, or set vanish.provider to use PremiumVanish or SuperVanish if you run one of those (hooked through their own API, no hard dependency), or point it at a command for any other vanish plugin. justBans steps out of the way when you hand vanish to another plugin.

 


[3] Vanished players can glow, and only staff see it. The glow goes out through PacketEvents so the outline only ever reaches staff who can see the player, and if you do not run PacketEvents the glow simply turns itself off with a note in the console. There is also a switch to stop justBans touching the join and quit messages, so if you run a custom join-message plugin the two never fight over it.

 


[4] Staff chat is easier to reach. Use /staffchat, /sc or /schat, or just put a symbol in front of a normal message (# by default) and that one line goes to staff without any command. The symbol is configurable, and only staff with the permission trigger it.

 


[5] Every short word the menus reuse, like Yes, No, On, Off, Current and Click to set, now lives in a text section in the config, so the whole staff interface can be translated.

 


[6] The report Teleport button now uses justBans' own vanish by default, so the right-click-to-arrive-hidden feature needs no other plugin. Set a vanish-command if you would rather it run a different one.

 


[7] The staff-mode action bar now shows up the instant you go into staff mode or vanish, instead of waiting a moment for the next refresh.

 


[8] Fresh, modern sounds. Going into staff mode, leaving it, vanishing, and freezing or unfreezing each have their own sound now, and every one is configurable or can be turned off.

 


[9] Muting is tighter. A muted message is now stopped at the earliest point.

 


[10] Works on Paper 1.21.11, 26.2.x, Folia, Spigot and BungeeCord/Velocity, same as always. All of the staff teleports and player handling use Paper's region-aware scheduling so it stays safe on Folia.
v1.2.7 Jun 23, 2026
v1.2.7

[1] There's a staff mode now. Type /staff and your normal items get tucked away safely while your hotbar fills with a set of moderation tools. Run /staff again and everything you had comes straight back, exactly where it was. While you're in staff mode you fly, you get night vision so dark spots are easy to read, and you take no damage and deal none, so you can move through anything to watch what's going on.

[2] The hotbar is a tool belt. Vanish toggles you in and out of sight. Inspect opens a read-only look at a player. Freeze holds a suspect still. Punish drops you straight into the punish menu for whoever you're looking at. Staff Panel opens the hub described below. Random Teleport jumps you to a random player to watch them unseen. Online Staff shows who else is on duty and lets you teleport to them. And Leave Staff Mode puts your own items back. Every tool, its slot, its item, its name and its lore is yours to change in the new configs/staff.yml, and you can switch any tool off entirely.

[3] Inspect is a clean read-only menu. Right-click a player and you see their full inventory, their armour and their off-hand, plus a head in the corner with their gamemode, health, food, ping, world, exact coordinates, IP and whether they're currently muted. Nothing in there is clickable, so you can never touch their stuff by accident. The title, the filler and every line of that info head are configurable.

[4] Freeze is built for catching people. Right-click a suspect and they're locked in place with a big FROZEN title, they can't walk off, they can't run commands except the ones you allow, and they're slowed and blinded so they can't keep playing. While frozen they also take no damage and can't drop a thing, so nobody can kill them to break the freeze or toss the evidence. If a frozen player logs out, every staff member gets told right away, which is the classic sign someone's trying to duck a ban.

[5] The Online Staff menu shows a head for everyone on duty with their current mode and world, and clicking a head teleports you to them. Handy when something kicks off and you want backup in the same spot fast.

[6] There's a built-in vanish you can use on its own with /vanish, no staff mode needed. Vanished, you vanish from everyone who isn't staff, you stop picking up items, mobs ignore you, and you take no fall damage, so you can stand anywhere and watch without leaving a trace. Who can see vanished players is permission-based and set in the config.

[7] Vanish is genuinely silent. When you vanish or come back, normal players see a fake leave or join line so nobody clocks that a staff member just went invisible. Both lines are yours to word however you like, or you can switch them off. And while vanished you can right-click a chest, barrel, shulker or any container to peek inside without the lid ever opening or making a sound for anyone nearby. The peek is read-only, so unvanish if you actually want to move something.

[8] There's an action bar that keeps you posted. While you're in staff mode it sits above your hotbar and tells you you're in staff mode and whether you're currently vanished, and while you're only vanished it shows that too. Both lines are configurable, and you can turn the whole thing off.

[9] Your items are safe no matter what. The moment you enter staff mode your real inventory is written to disk, so even if the server hard-crashes before you leave staff mode, your items are waiting for you and come straight back the next time you log in. Every clean exit, whether you leave staff mode, log out or the server reloads, hands your items back and tidies up after itself.

[10] There's a Staff Panel now, a proper hub you open with the compass tool. It's one clean menu with a button for everything below, so you don't have to remember which hotbar slot does what. Every button, its slot, its item and its text is set in the config, and the panel shows live numbers like how many players and staff are online and the current TPS.

[11] The Player List button opens a paged list of everyone online, each as their head with their world, gamemode, ping, health and whether they're muted or staff. Left-click a head to teleport to them, right-click to inspect them, and shift-click to drop straight into the punish menu. On a network the people you see are the ones on your own server, but a punish from here goes through the normal punish flow, so it lands across the whole network in SQL mode.

[12] The Recent Activity button opens the latest punishments from across the network, newest first, each showing the type, who got it, which staff member did it, the reason, whether it's still active and how long ago it happened. Click any one of them to jump straight to that player's full record.

[13] Staff Chat is a toggle. Flip it on from the panel and everything you type in chat goes only to other staff instead of the whole server, flip it off and you're back to normal. The channel, who receives it and how it looks are all set in the config.

[14] The Utilities button is your own quick-controls. Toggle flight, night vision and speed on or off, each one showing its current state, or heal and feed yourself in one click. Good for getting set up the way you like without typing a string of commands.

[15] The Gamemode button is a one-click switcher between survival, creative, adventure and spectator, with your current mode marked so you always know where you are.

[16] The Broadcast button lets you send a server-wide announcement. Click it, type your message in chat (or type cancel to back out), and it goes to everyone in a format you can style however you want.

[17] The IP in the Inspect menu is now locked behind its own permission. Staff without justbans.staff.viewip just see "Hidden" where the IP would be, so you can let your whole team inspect players without handing everyone their addresses. The word shown in place of the IP is configurable.

[18] All of it lives in configs/staff.yml. Flight, night vision, invincibility, vanish-on-enter, the sounds, every tool, the freeze rules, all the menus, the action bar, the panel, staff chat, broadcast and every message are in there, written out on first start and updated on later versions while keeping whatever you changed. The new commands are /staff (also /staffmode and /sm) and /vanish (also /v).

[19] Works on Paper 1.21.11, 26.2.x, Folia, Spigot and BungeeCord/Velocity, same as always. All of the staff teleports and player handling use Paper's region-aware scheduling so it stays safe on Folia.

v1.2.6 Jun 12, 2026
v1.2.6

[1] There's a report system now. Players type /report <player> and a menu pops up. They pick a Type, pick a Reason, drop in some Proof, and hit Submit. The head up top shows who they're reporting so they know they grabbed the right person. It's all clickable, nobody has to remember any syntax.


[2] Type and Reason both open their own little menu with preset options you set up. Don't see the one you want? There's a Custom button that closes the menu and lets you type your own answer in chat. Proof works the same way, you click it and type a link or a quick description. Type cancel any time to back out.


[3] Staff get /reports view to see everything that's come in. Every report shows the reported player's head, who reported them, the type, the reason and when it happened. Click one to open the full report. To delete one, Shift-Right-Click it twice (once to arm it, once to confirm) so nobody nukes a report by fat-fingering a click.


[4] /reports view <player> pulls up every report tied to that player, both the ones they made and the ones made about them, active or not. Handy when someone's a repeat problem or a serial false-reporter.


[5] /reports view non-active shows the reports that have been deleted or have aged out, and /reports view all shows the whole pile, active and not. So nothing is ever really gone, you can always go back and look.


[6] Reports remember who closed them. Open a non-active one and it tells you which staff member dealt with it.


[7] There's a cooldown so one angry player can't spam ten reports in a row. Set it to whatever you want in seconds, or 0 to turn it off. Staff with the bypass permission skip the wait.


[8] Reports can be set to expire on their own. Leave a time like 14d and anything older quietly moves into the non-active list. Set it to permanent if you'd rather keep them forever.


[9] You can hook reports up to Discord. Drop a webhook url in reports.yml and every new report gets posted to that channel with all the details. Put a role ping in there too if you want your staff team buzzed the moment something comes in. Off by default until you fill in the url.


[10] Your staff also get pinged in-game the second a report lands, as long as they have the notify permission. You can turn that off or change the wording.


[11] When you open a report there's a Punish button right there that drops you into the normal /punish menu for the reported player, so you can read a report and deal with it without typing their name out again. Only shows if you can punish, and it still respects all your usual punish permissions.


[12] There's also a Teleport button in the report. Left-click and you're standing next to them. Right-click and you go into vanish first so they don't see you coming, which is great for catching someone in the act. It just runs your vanish command, so set vanish-command in reports.yml to whatever your vanish plugin uses and it'll work. The right-click needs the vanish permission.


[13] The reporter now hears back. When you close a report, whoever filed it gets a message saying what happened, either the player got punished and what they got, or nothing was done this time. If they're offline when you close it they get the message the next time they log in, so reports don't just vanish into the void for the person who took the time to make one.


[14] Punishing a player auto-closes the open reports on them. So if five people reported the same cheater and you ban them, all five reports close on their own and all five reporters get told the player was dealt with. You can turn that off in reports.yml if you'd rather close them by hand.


[15] New /alts <player> command (also /alt or /ipscan). It scans everyone who's logged in from that player's IP and lists each account with a tag, [ONLINE] or [OFFLINE], plus [BANNED] if that account is banned and [IP-BANNED] if the whole IP is. Quick way to spot somebody's alts. Works on offline players too. The whole readout, badges and all, lives in messages.yml.


[16] On top of that, staff get a heads-up when someone joins from an IP another account has used, even if nobody on it is banned. The old alert only fired for ban evasion (a banned account on the IP). This one's broader so you catch alts early. Needs the alts notify permission, and you can shut it off in config.yml if your players share IPs a lot.


[17] All the report and alt stuff is yours to change. The new configs/reports.yml holds every menu, the preset Type and Reason lists, the cooldown, the expiry, the webhook, the teleport and vanish settings and all the messages. The alt scan text sits in messages.yml and the IP alert toggle in config.yml. Everything writes itself out on first start and updates itself on later versions while keeping whatever you changed.


[18] There's a web dashboard. It's a clean, self-hosted panel where your staff manage punishments from a browser. They log in with a one-time token from /dashboard in game, no account or password to set up. Host it yourself, or serve it straight from the plugin: point api.dashboard-path at the built dashboard folder in api.yml, open the API address in a browser, and it just works, with no cross-origin setup and no URL to type in.


[19] Player heads show up all over the dashboard and they always look right, including on offline-mode servers. A coloured tile with the player's initial shows instantly, then the real head fades in over it.


[20] The dashboard has a full Reports page. See active reports, deleted and expired ones, or everything at once, search by player, and open any report to read the proof and see who handled it. With the right permission you can close a report right from there. Search a player on the Players page and you get their whole record, the same as /check in game.


[21] Dashboard access runs on groups you set in api.yml. Two come ready: Moderator (view, punish, revoke, see reports) which everyone gets by default, and Admin which gets everything. Anyone with justbans.command.admin in game is always an Admin. Each staff member only sees and can do what their group allows.


[22] Admins get a Settings panel to build their own groups, tick exactly which permissions each one has, and assign staff to them, all from the dashboard without touching a config file. Moderators never see any of it.


[23] You can edit punishments from the dashboard, not just revoke them. Open Punishments, hit the edit pencil on any ban, mute or warn, and change its reason or its length right there. Editing a mute's length takes effect immediately for anyone who's online.


[24] Players hear about it when their punishment changes. Edit someone's ban or mute and they get a message saying it was updated and by whom, right away if they're online or the next time they join if they're offline. Word it however you like, or turn it off entirely, in messages.yml.


[25] Player heads on the dashboard are extra reliable now. They try a few head-render services in turn, so if one is blocked or down the next one fills in, and you still get the coloured initial tile if none of them answer.


[26] Works on Paper 1.21.11, 26.1.x, Folia, Spigot and BungeeCord/Velocity, same as always. The teleport uses Paper's async teleport so it's safe on Folia across worlds.

1.2.5 Jun 5, 2026
1.2.5

[1] Your backends connect to MySQL now. The plugin was trying to create its tables with a line MySQL doesn't support, so the whole setup crashed and the punishments table never got made. That's why every join said "table doesn't exist." Fixed.


[2] There's a full punishment menu now. Type /punish <player> and you click what you want (ban, temp-ban, IP-ban, mute, IP-mute, shadow-mute, warn or kick), then pick a reason and a length and confirm. The head up top tells you if they're already banned or muted, their warning count and how many alts they have. There's a silent toggle, an IP toggle, and a button to flip a ban into a mute without starting over. It does the same thing the commands do, just clickable.


[3] Run /punish on its own and it shows everyone who's online. Click a head to punish them instead of typing the name.


[4] New /justbans data screen. It's the full log of every punishment on the server: who did it, the exact time, the reason, the length, whether it's still active, and if it was lifted, which staff member lifted it. Search by a player's name or a staff name, click any entry for the details, and a Back button puts you right back on the page you were on. Admins only.


[5] /editban <player> opens a list of that player's active bans and mutes. Click one to change its reason or its length. /editban <id> <reason|duration> <value> still works if you'd rather type it, and it's the only way from console.


[6] You can jump straight from someone's /check history to punishing them. There's a Punish button in the bottom-right. It only shows if you have permission.


[7] "Custom reason" and "custom duration" ask you to type it in chat now instead of opening an anvil. The anvil never worked on 1.21.11 so that button used to look dead. Now it just closes the menu, you type it, done. Type cancel to back out.


[8] /unwarn works now. Warnings were getting saved as already-expired the instant you gave them, so /unwarn could never find one and told you "this player is not muted," which made no sense for a warning. Warnings now last as long as warnings.expire_after says (30 days by default) and /unwarn has its own message. One thing: warnings from before this update are already dead, so give a fresh one to test.


[9] IP bans stick across the network now. They were tied to the banned player's current IP, so the second that player logged in from somewhere else, the IP you banned quietly stopped being blocked and their alts could walk right back in. Now it sticks to the IP you actually banned, on the proxy and the backends both, so that address stays blocked for everyone on it.


[10] You can punish offline players from any server on the network now. Banning, muting or warning someone who's in the database but never joined the exact server you're standing on used to fail with a "not found" message, even though they showed up in tab-complete. It now looks them up in the database (and Mojang as a last resort), so it works no matter which backend you run it from.


[11] You can edit the network ban screen now. The "You are banned from this network!" message the proxy shows was locked in the code before. It's in messages.yml as network_ban_screen now, and on Velocity it uses MiniMessage like everything else (colors, gradients, hex). Edit it in your proxy's plugins/justbans/messages.yml. On BungeeCord it falls back to plain colors since Bungee has no MiniMessage.


[12] No more invisible item stuck to your cursor after jumping between menus, like going from History to Punish.


[13] Warns and kicks don't tack "(N/A)" onto the end of the confirmation anymore. There's no duration on them, so it just leaves it off.


[14] Player heads don't show that odd "Dynamic" line under the name anymore. (If you still see "minecraft:player_head" or "X component(s)" lines, those are your own client's advanced tooltips. Hit F3 + H to turn them off. Players never see them.)


[15] The menus look a lot nicer, with fresh icons and shorter, cleaner text. Everything in them (titles, slots, icons, wording) lives in the new configs/gui.yml, and you can switch off any punishment you don't want showing in the menu right there.


[16] /justbans help got a cleaner look and lists every command now.


[17] Your config updates itself on the first start and keeps anything you changed. To get the new look on a setup you already have, delete configs/gui.yml and configs/messages.yml and let them regenerate.


[18] Works on Paper 1.21.11, 26.1.x, Folia, Spigot and BungeeCord/Velocity.

1.2.4 May 1, 2026
Page 1
Sign in
$9.99 USD
Sign in to purchase, save this product to your cart, and keep downloads tied to your account.
Stripe