Compatibility
Minecraft: Java Edition
Platforms
Links
Tags
Creators
Details
VI: LƯU Ý: PLUGIN NÀY ĐƯỢC VIẾT Ở NGÔN NGỮ TIẾNG VIỆT. NÊN RẤT XIN LỖI NHỮNG NGƯỜI KHÔNG BIẾT TIẾNG VIỆT, CÓ THỂ TÔI SẼ THÊM PHIÊN BẢN TIẾNG ANH (HOẶC LÀ KHÔNG NẾU TÔI LƯỜI)
ENG: NOTE: THIS PLUGIN IS WRITTEN IN VIETNAMESE. SO I'M VERY SORRY FOR THOSE WHO DO NOT KNOW VIETNAMESE, MAYBE I WILL ADD AN ENGLISH VERSION (OR NOT IF I'M LAZY)
This plugin offers a solution to minimize the risk of your server falling victim to "Force OP" attacks by preventing players not on the allowlist from obtaining OP status or sensitive permissions (such as *, essentials.*, etc.).
KEY FEATURES:
-
Checks for OP status and sensitive permissions (e.g., , luckperms., ...) (Customizable in config.yml)
-
Automatically punishes players who are not on the whitelist but possess OP status or sensitive permissions—almost instantly—using commands customizable in config.yml (Delay is also customizable in config.yml)
-
The config reload command (/cglreloadconfig) is restricted to players listed in the whitelist
-
Allows disabling the server's /op command (Toggleable in config.yml)
-
Blocks players not on the whitelist from switching to Creative mode. If they somehow already possess Creative mode before joining the server, their mode will be switched to Survival immediately upon entry (Toggleable in config. NOTE: If you are upgrading from version 1.0 and this feature isn't working, please add the line "block_gamemode_creative: true" to your config and restart the server!)
-
Automatically executes pre-configured commands from the "logout_actions" section when an OP player leaves the server (prevents unauthorized administrative account compromise).
-
Prevents UUID spoofing by verifying the player's UUID immediately upon joining the server (applies only to servers with
online-mode=false; toggleable in the config). -
Protects against unauthorized disabling: If the plugin is disabled without authorization by another plugin (such as PlugMan or backdoors capable of disabling arbitrary plugins), it will immediately shut down the server (configurable in
config.yml).
USAGE:
- Download the plugin.
- Place the plugin in your
pluginsfolder. - Restart the server (Do not use plugin management tools like PlugMan or any method other than a full server restart to load the plugin, as this will cause errors. If
stop_serveris set totrueinconfig.yml, the server will stop immediately!). - Do not join the server yet; edit
CloudGuardLite/config.ymlto customize the player list, sensitive permissions, punishment commands, etc. - Restart the server DISCLAIMER: I will not be held responsible if you install this plugin but your server still falls victim to a "Force OP" attack via some other method. Backdoors and exploits vary widely, each operating through different mechanisms, making it extremely difficult to prevent them entirely with a single plugin. Ultimately, your own vigilance remains the best line of defense. Please stop indiscriminately installing plugins from unknown sources to minimize risk!
As this is my first plugin, please contact me via Discord (ftl2nd) if any issues arise!Thank you for using my plugin!


