On this page
- Choose checks for your server, not a promise
- Compare the options at a glance
- 1. GrimAC
- What it does well
- Who it suits
- What to watch out for
- 2. VoidAC
- What it does well
- Who it suits
- What to watch out for
- 3. BS-AntiCheat
- What it does well
- Who it suits
- What to watch out for
- 4. Matrix
- What it does well
- Who it suits
- What to watch out for
- 5. NoCheatPlus
- What it does well
- Who it suits
- What to watch out for
- 6. AntiCheatAddition
- What it does well
- Who it suits
- What to watch out for
- 7. Spartan
- What it does well
- Who it suits
- What to watch out for
- Test flags before enabling punishments
- Install on a test copy first
- Choose by requirements and test workflow
Key takeaways
5- GrimAC, VoidAC, BS-AntiCheat and NoCheatPlus are listed as free or open-source; NoCheatPlus is GPLv3.
- Matrix is paid; AntiCheatAddition is GPLv3, but its current price was not confirmed.
- Spartan’s free version is limited to servers with 5 players or fewer and requires /spartan charge to add detection time.
- Compare each plugin’s stated checks and requirements against your server version and network setup.
- Test ordinary play on a staging copy and have staff review flags before enabling punishments.
This comparison is for Paper server owners choosing an anti-cheat for survival, minigames or PvP. You will leave with seven options to investigate, a way to check whether one fits your server, and a safer path to automatic punishments.
Choose checks for your server, not a promise
Anti-cheats monitor selected player behavior and can flag activity for staff to review. A flag needs context before you act on it. Check the plugin’s stated scope and requirements, then try it with your server’s own worlds, plugins and player routes.
Paper has a separate built-in Anti-Xray system that hides ores by swapping in fake blocks. Its documentation describes limits, including ores touching air remaining visible. Treat X-ray protection as its own layer and read Paper’s Anti-Xray guide for its modes and settings.
Before choosing, write down your Minecraft version, server software, and whether players connect through Geyser, a proxy or version translation. If Bedrock players join, our Geyser and Floodgate guide explains that setup. If you are changing Minecraft versions, our Paper update checklist covers testing plugins on a copy first.
Compare the options at a glance
| Option | Free or paid | What its listing describes | Check before choosing |
|---|---|---|---|
| GrimAC | Free, open source | Movement simulation and support for several server platforms | Version and network requirements |
| VoidAC | Free, open source | A Grim fork; automatic bans are off by default | Its auto-kick default and version notes |
| BS-AntiCheat | Free, MIT licensed | Several check types and report-only mode | PacketEvents is needed for some checks |
| Matrix | Paid | Combat, movement, packet and other checks, with configurable punishments | It requires a token after purchase; verify versions and setup details |
| NoCheatPlus | Free, open source (GPLv3) | Checks include flying, speed, fighting, fast block breaking, inventory and chat | Its repository cautions that compatibility depends on matching versions |
| AntiCheatAddition | Open source (GPLv3); price not confirmed | Modular detection and information protection; requires PacketEvents | Supported server versions and modules |
| Spartan | Limited free version, for servers with 5 players or fewer | Its Modrinth listing describes checks for combat, movement, world and miscellaneous behavior, and exploits | The free listing requires /spartan charge; check its time limits and requirements |
Vulcan is omitted from the numbered picks because we could not source an accessible allowed listing for the anti-cheat itself. The accessible BuiltByBit results were for Vulcan configuration files, not the plugin, so they do not establish its features or compatibility.
1. GrimAC
GrimAC on Modrinth is a free, open-source anti-cheat built around simulating what a player could legitimately do. Its listing names Paper, Purpur, Spigot and Folia, and Java 17 or later. The listing says a premium version with subscription-based checks is planned, while GrimAC itself is free.
What it does well
The project describes movement simulation and world replication as central parts of its approach. Check its current version list directly because page descriptions and version metadata can differ.
Who it suits
Owners looking for an open-source option whose listing emphasizes movement checks and several server platforms.
What to watch out for
The listing says Geyser players are exempt when Floodgate is on the backend, and recommends ViaVersion on the backend because movement checks depend on client version. Compare that guidance with your network layout before interpreting flags.
2. VoidAC
VoidAC on Modrinth describes itself as a free, open-source Grim fork. Its listing names Paper, Spigot, Purpur and Folia, and Java 17 or newer.
What it does well
The listing says automatic bans are off by default. It describes prediction-based movement checks, alerts, a threshold optimizer and bundled PacketEvents.
Who it suits
Owners interested in a Grim-based option with additional checks such as AutoTotem and ban waves described on its listing.
What to watch out for
The listing says an anti-spoof auto-kick for players announcing known cheat clients is on by default. Review this setting before opening the server. Its version notes say some versions are recognized but not verified, so compare the current page with your Paper build.
3. BS-AntiCheat
BS-AntiCheat on Modrinth is a free, MIT-licensed plugin. Its listing describes movement, combat, world, inventory and packet-level checks, and names Paper and Folia.
What it does well
The listing says it ships in report-only mode and has configurable punishment tiers. It also describes live threshold tuning and Geyser/Floodgate exemptions.
Who it suits
Owners who want to inspect reports and tune thresholds before deciding whether to enable punishments.
What to watch out for
The listing says PacketEvents is required for packet-level checks and the lag-transaction system, while other checks work without it. Its stated server requirement is Paper or Folia 1.21.x, so check compatibility with your setup.
4. Matrix
Matrix AntiCheat on BuiltByBit is a paid plugin. Its listing describes checks for combat, movement, packets, block actions, vehicles and other behavior. It also says the plugin requires a token after purchase.
What it does well
The listing describes configurable punishment commands, separate configuration files and GUI controls. Its listed check groups give administrators several areas to investigate when evaluating it.
Who it suits
Owners considering a paid option who want the listed check coverage and configuration controls. The listing also links to a free trial for testing.
What to watch out for
Read the token and setup instructions before planning an installation. The listing says it may not have the newest version available directly there, so follow its current download instructions and verify compatibility with your server version.
5. NoCheatPlus
NoCheatPlus on GitHub describes checks for flying and speed, fighting, fast block breaking, inventory and chat behavior. Its repository says to match the NoCheatPlus and Spigot or CraftBukkit versions, and identifies the project as GPLv3.
What it does well
The repository organizes its checks into different sections and provides links to configuration and documentation.
Who it suits
Owners evaluating a project whose documented checks span movement, combat, block breaking, inventory and chat.
What to watch out for
The repository notes that using a compatible ProtocolLib version is important for full efficiency of fight checks and that some checks may otherwise be disabled. Confirm current compatibility before using it on a modern Paper server.
6. AntiCheatAddition
AntiCheatAddition on GitHub describes a Spigot anti-cheat extension with modular detection checks, selected exploit protections and controls for information shown to clients. The repository says it requires PacketEvents, integrates with ViaVersion, Floodgate and WorldGuard, and is licensed under GPLv3. It points administrators to its official Spigot resource for supported releases and support.
What it does well
Its documented scope includes configurable detection modules, violation management and information-protection controls. The repository also gives a canonical config file for module settings.
Who it suits
Administrators assessing a modular extension that covers selected checks and player-information controls.
What to watch out for
The repository says the plugin refuses to load on unsupported server versions. Check its linked Spigot resource for current supported releases and operational guidance.
7. Spartan
Spartan AntiCheat on Modrinth lists Bukkit, Folia, Paper, Purpur and Spigot, and Minecraft 1.7.x through 1.21.x. Its free version is limited to servers with 5 players or fewer. The listing says you need to run /spartan charge and click an item to add detection time.
What it does well
The listing describes checks for combat, movement, world behavior and miscellaneous actions, and includes commands for managing checks, punishments and notifications.
Who it suits
Owners of small servers who want to evaluate its listed checks and commands within the free version’s player limit.
What to watch out for
The free version’s detection time needs to be charged through the in-game menu. Read the current listing before installing, including its time limits and any requirements for your server.
Test flags before enabling punishments
Run the first evaluation on a staging copy with the same Paper build, plugins, worlds and important settings as production. Keep automatic punishments off while staff learn which checks trigger during ordinary play.
- Test ordinary activities for your server, such as sprinting, jumping, swimming, knockback, vehicles, building, mining and PvP.
- Repeat with client versions and network routes your players use, including proxy, Geyser or ViaVersion setups where applicable.
- Record the check name, ping, server performance, client version and what the player was doing when a flag appeared.
- Have staff review a sample of flags. Change one setting at a time, then repeat the same tests.
- Consider automatic action only after tests and staff review support the settings you plan to use. Keep a way to reverse mistakes.
Install on a test copy first
Follow the plugin’s own installation notes and include required dependencies. These steps cover placing the plugin file and restarting the test server.
- Stop the test server.
- Upload the plugin jar to the
pluginsfolder. - Start the server and review the console for startup errors.
- Stop the test server from the Console.
- Use the File Manager or SFTP to place the jar in
plugins. - Start the server from the Console and check startup output. If Java selection is limited by the host’s Docker images, ask the host about the available choice.
- Stop the test server from the Console.
- Use the Files / FTP page to put the jar in
plugins. - Start the server and review the console for errors.
For a first-time Paper setup, see our Paper installation guide.
Choose by requirements and test workflow
GrimAC, VoidAC, BS-AntiCheat and NoCheatPlus have project pages describing free or open-source status; Matrix is paid. AntiCheatAddition’s repository identifies its GPLv3 license, though this does not establish its current price. Spartan’s Modrinth listing describes a limited free version for servers with 5 players or fewer. We could not source an allowed listing for the Vulcan anti-cheat itself. Check each project’s current version information, dependencies and defaults, then test your shortlist on a copy before enabling automatic punishments.
Frequently asked questions
Which options in this comparison are free?
The checked project pages identify GrimAC, VoidAC and BS-AntiCheat as free or open source. Matrix is paid. NoCheatPlus is listed as free, open-source software under GPLv3. AntiCheatAddition's repository states GPLv3, but that alone does not establish its current price.
Does VoidAC ban players by default?
Its listing says automatic bans are off by default. It also says an anti-spoof auto-kick is enabled for players announcing known cheat clients, so review that setting before opening the server.
Does BS-AntiCheat need PacketEvents?
Its Modrinth listing says PacketEvents is required for packet-level checks and the lag-transaction system. It says other checks work without it.
What should I check before installing Matrix?
Matrix’s BuiltByBit listing says a token is required after purchase. It describes a free trial and says the newest version may not be available directly on the listing, so check its current setup and download instructions.
How should I test anti-cheat flags?
Use a staging copy with the same server build and important plugins as production. Test ordinary player actions, record the context for flags, and have staff review them before enabling automatic punishments.