KellyMaster v2.5.0
The most comprehensive operator protection system for Minecraft servers.
KellyMaster prevents unauthorized players from gaining or abusing operator (OP) permissions on your server. When a
player receives OP, they are immediately frozen and must verify their identity through a one-time code sent to
their Email, Discord DM, or Telegram — until verified, they cannot move, chat, interact, or execute any
command.
If someone who is not in your operator whitelist gains OP through exploits, backdoor plugins, or any other method
— KellyMaster instantly removes their OP and bans/kicks them automatically.
What's in v2.5.0
Multi-Layer Operator Protection
- Instant detection — OP changes are caught within milliseconds through multiple independent detection layers
- Pre-freeze system — Players are frozen the exact moment they receive OP, before they can execute any command
- UUID + name dual authentication — Prevents identity spoofing on offline-mode and proxy servers
- Namespace-aware command blocking — Catches bypass attempts like
/bukkit:op,/spigot:op,/essentials:op
Multi-Channel Verification
- Email (SMTP) — Works with Gmail, Outlook, Yahoo, or any SMTP provider
- Discord DM — Sends verification codes directly to the operator's Discord account
- Telegram — Sends codes via Telegram bot with automatic Chat ID detection
Real-Time Security Alerts
- Discord Webhooks — Instant alerts when unauthorized OP is detected or blocked commands are attempted
- Geolocation enrichment — Alerts include the intruder's country, city, and ISP
- Multi-channel operator notifications — All authorized operators are alerted through their configured channel
Complete Freeze System
During verification, operators are fully isolated:
- Cannot move (head rotation allowed)
- Cannot chat or execute commands (except
/kellymaster <code>) - Cannot interact with blocks, entities, or inventory
- Cannot take or deal damage
- Cannot see other players in the TAB list
- Countdown timer with actionbar and title warnings
LuckPerms Integration
Monitors permission changes in real-time. If an unauthorized player receives dangerous permissions (*,
luckperms.*, minecraft.command.op, etc.), KellyMaster automatically removes the permissions, bans the player, and
alerts all operators.
Plugin Self-Defense
- Blocks attempts to unload or disable KellyMaster through plugin management tools
- Runtime integrity monitoring detects tampering with the plugin's internal state
- Environment checks detect hostile JVM configurations at startup
Server Compatibility
| Platform | Versions |
|---|---|
| Paper | 1.17.1 — 1.21.x+ |
| Folia | All versions |
| Spigot | 1.17.1+ |
| Java | 17+ |
Performance
- Zero impact on TPS — All network operations (email, Discord, Telegram, webhooks) run on background threads
- Less than 0.05% of a tick used by the monitoring system
- ~15MB RAM without Discord bot, ~60MB with Discord active
- Fully compatible with servers running on 2GB+ RAM
Configuration
KellyMaster generates three configuration files on first startup:
| File | Purpose |
|---|---|
config.yml |
Main settings — verification timeout, blocked commands, webhook URL, SMTP credentials |
whitelist.yml |
Operator whitelist — who can have OP, their verification method, Discord/Telegram bot tokens |
messages.yml |
All in-game messages — fully customizable with color codes and placeholders |
See the README for detailed configuration guides.
Installation
- Download
KellyMaster.jarbelow - Place it in your server's
plugins/folder - Restart the server
Configuration
KellyMaster generates three configuration files on first startup:
| File | Purpose |
|---|---|
config.yml |
Main settings — verification timeout, blocked commands, webhook URL, SMTP credentials |
whitelist.yml |
Operator whitelist — who can have OP, their verification method, Discord/Telegram bot tokens |
messages.yml |
All in-game messages — fully customizable with color codes and placeholders |
See the README for detailed configuration guides.
Installation
- Download
KellyMaster.jarbelow - Place it in your server's
plugins/folder - Restart the server
- Edit the configuration files in
plugins/KellyMaster/ - Restart the server to apply changes
Links
- Documentation: See README for full setup guide
- Issues: Report bugs or request features
- Support: ko-fi.com/srcodexstudio
Made by SrCodexStudio — Protecting Minecraft servers, one operator at a time.