Security scanner
Defensive, non-intrusive checks for exposure and risky configuration.
What it does — and never does
The scanner resolves DNS, opens a plain TCP connection to the ports you declared (public, backend and RCON) and sends one standard Minecraft status request. That is all.
Backend exposure
Backend servers trust the proxy to authenticate players. If a backend port is reachable from the internet, anyone can bypass the proxy. Firewall backend ports so only the proxy's address can connect.
RCON
RCON gives full console access and is a common brute-force target. Disable it when unused; otherwise firewall the port and use a long random password.
Online mode
online-mode=false without a proxy lets anyone join under any name, including operators. Only run it on backends that are fully hidden behind a correctly configured proxy.
Proxy forwarding
- Velocity: use
modernforwarding with a forwarding secret. - BungeeCord/Waterfall: enable
ip_forward, add BungeeGuard and firewall the backends.
Query protocol
enable-query=true exposes plugin and player information over UDP. Disable it unless a monitoring tool needs it.
Whitelist
Private or staging servers should not be open to everyone. Enable the whitelist for them.
Firewall posture
Tickhound cannot read your firewall; it infers posture from what an outside connection can reach. Use default-deny: allow only the public Minecraft port and SSH from trusted IPs.
Results
- Secure — no warnings or worse.
- Warning — at least one warning or error.
- Critical — at least one critical exposure.
