Skip to content
Connection Guard
Download

Published run6–7 October 2026 · Velocity · 3 rounds

Measured, not claimed.

We run the popular free anti-VPN plugins on the same server, with the same players and the same simulated detection services, and publish every number and log. Connection Guard included, so check our work.

Conflict of interest: the benchmark is built by Connection Guard's author. The method, the adapters and every log are public, and any plugin author can contest a result. Every plugin runs as it ships, without API keys. A second pass with the same free ProxyCheck key for every plugin follows. Connection Guard 0.6.1 RC is a release candidate: downloads deliver 0.6.0 until it ships, and 0.6.0's results are shown where they differ.

1,000 players join at once.

50 new players per second for 20 seconds. Each detection service is simulated with the same delay and its real free-tier limit, so a plugin can't look fast by asking a service that would refuse it in reality.

Measured with run 37643006094 for Connection Guard 0.6.1 RC and run 37624137638 for the others.

Time until the plugin decides

95th percentile, and how many of the 1,000 players it looked up. Lower time is better.

  • Connection Guard504 ms999 looked up
  • ProxyShield7.6 s303 looked up
  • VPNGuard11 s53 looked up
  • FoxGate30 stimed out · 169 looked up
  • AdvancedAntiVPN30 stimed out · 508 looked up
  • KauriVPNafter joinlets everyone in, kicks later

What players feel

Join time during the wave, 95th percentile, next to the same proxy with no anti-VPN plugin.

  • Connection Guard898 ms
  • No anti-VPN plugin438 ms
  • KauriVPN435 ms
  • ProxyShield13 s
  • VPNGuard18 s
  • FoxGate27 s
  • AdvancedAntiVPN28 s

One player in the wave was refused: the wave's random addresses include one in a range Connection Guard Intel lists as VPN.

Decision time per scenario, median and 95th percentile
ScenarioConnection Guard0.6.1 RCAdvancedAntiVPN2.31.8FoxGate1.2.0-pre10KauriVPN1.10.1.1ProxyShield2.5.1VPNGuard1.2.0
First join of a new player50 new players, one after another132 msp95 289 ms244 msp95 421 ms843 msp95 6.0 safter join789 msp95 1.4 s130 msp95 288 ms
The same players againAnswers can come from the cache3 msp95 4 ms4 msp95 5 ms452 msp95 5.3 safter join2 msp95 2 ms2 msp95 2 ms
100 joins from one address at onceA bot wave from one IP88 msp95 117 ms8.5 sp95 13 s453 msp95 651 msafter join928 msp95 1.3 s1.1 sp95 1.1 s
1,000 new players in 20 seconds50 per second, each from a new address208 msp95 504 ms30 sp95 30 s, timed out30 sp95 30 s, timed outafter join1.2 sp95 7.6 s10 sp95 11 s

KauriVPN lets every player join and checks afterwards, kicking a VPN user a moment later. Its times measure the login, not a decision, so they are not compared here.

When the detection services fail.

Free detection services time out, rate-limit and break. We make every one of them fail in five ways and send a VPN, a Tor exit and a home player during the outage.

Measured with run 37622124772 for Connection Guard 0.6.1 RC and runs 37593590733, 37624132539 for the others.

VPN and Tor blocked during service failures, per plugin
FailureConnection Guard0.6.1 RCAdvancedAntiVPN2.31.8FoxGate1.2.0-pre10KauriVPN1.10.1.1ProxyShield2.5.1VPNGuard1.2.0Connection Guard0.6.0
Everything workingVPNTorVPNTorVPNTorVPNTorVPNTorVPNTorVPNTor
Services time outVPNTorVPNTorVPNTorVPNTorVPNTorVPNTorVPNTor
Services rate-limit (429)VPNTorVPNTorVPNTorVPNTorVPNTorVPNTorVPNTor
Services send broken answersVPNTorVPNTorVPNTorVPNTorVPNTorVPNTorVPNTor
Services cut answers offVPNTorVPNTorVPNTorVPNTorVPNTorVPNTorVPNTor
Home player's login while services time outLower is better; everyone lets the player in5.0 s3.0 s11 s3 ms6.7 s5.0 s5.0 s

A check means the VPN or Tor exit was still refused while every detection service failed that way. Connection Guard checks its own signed lists of VPN servers and Tor exits (Connection Guard Intel) on the server before asking any service, so a known VPN needs no lookup at all. When several services hang at once, a home player's first login can take up to about 5 seconds; services that time out are then skipped for a while.

Who gets caught, who gets in.

692 labelled addresses, each with its source: VPN servers from the providers' own lists, Tor exits from the Tor Project, and home and mobile connections from volunteers' RIPE Atlas probes.

Measured with run 37666758972 for Connection Guard 0.6.1 RC and runs 37540326121, 37623918344, 37646483626 for the other plugins, keyless.

Blocked addresses per group and plugin
GroupConnection GuardAdvancedAntiVPN*FoxGateKauriVPNProxyShieldVPNGuard
Should be blocked: higher is better
Commercial VPNs125 / 12518 / 125125 / 125124 / 125125 / 125124 / 125
Newly added VPN servers37 / 376 / 3737 / 3737 / 3737 / 3737 / 37
VPNs over IPv640 / 4011 / 4039 / 402 / 4039 / 4036 / 40
Tor exits80 / 8015 / 8080 / 8079 / 8080 / 8078 / 80
Public proxies93 / 10017 / 10092 / 10068 / 10096 / 10089 / 100
Should get in: lower is better
Home connections0 / 1500 / 1503 / 1505 / 1504 / 1503 / 150
Home connections, IPv60 / 600 / 603 / 604 / 603 / 603 / 60
Mobile networks2 / 1000 / 1001 / 1002 / 1002 / 1002 / 100

Read the VPN rows with care: Connection Guard's own lists are built from the same provider lists that label these addresses, so for those groups they show coverage, not how well it finds unknown servers. Tor, proxies and the false positives are not affected.

*AdvancedAntiVPN ran in a separate run without the shared free ProxyCheck key the others' keyless lookups got, so its free quotas ran out after about 100 players and it let the rest in. A run with the same key for every plugin follows.

Connection Guard 0.6.1 RC refused 2 of 310 home and mobile players, both mobile connections; FoxGate, ProxyShield, VPNGuard and KauriVPN refuse one of the two as well. Version 0.6.0 refused 10 here, four of them on a single answer from one detection service, Blackbox. From 0.6.1 on, a Blackbox answer needs a second source before a player is refused.

How it's measured.

  • Unmodified plugin JARs from their official pages, with checksums, on one pinned server build.
  • A real Minecraft client logs in from each test address, so every plugin sees what it would see in production.
  • Detection services are recorded once and replayed to every plugin, with the same delay (120 ms median, 350 ms at p95) and each service's free-tier limit.
  • Each plugin runs with its documented settings, enforcement switched on. No plugin-specific tuning.
  • No combined score: speed, reliability and detection are reported separately, with every denominator.

What it doesn't show.

  • Velocity only on this page; Paper, Folia and BungeeCord results are in the repository.
  • Simulated services measure how a plugin handles them, not how good each service is.
  • The dataset is a snapshot. VPN servers and Tor exits change; we rebuild it and keep every old run.
  • Results are the median of three rounds.

Plugin author and see something wrong? Contest a result. Corrections are re-measured, and the original stays in the history.

Run it yourself.

Docker on Linux or Docker Desktop with 6 GB, about 15 GB of disk. Or fork the repository and start the GitHub Actions workflow.

$ git clone https://github.com/gerolndnr/mc-antivpn-bench
$ cd mc-antivpn-bench
$ docker build -t mc-antivpn-bench:dev harness/docker
$ docker run --rm -v "$PWD:/bench" -e PYTHONPATH=/bench/harness --entrypoint python3 mc-antivpn-bench:dev -m bench.dataset materialize
$ docker run --rm --cap-add NET_ADMIN -v "$PWD:/bench" -v mcbench-work:/work -e PYTHONPATH=/bench/harness \
    --entrypoint python3 mc-antivpn-bench:dev -m bench run performance --platforms velocity

This page: performance run, detection run, failure run. Runner: GitHub-hosted 4 vCPU, 15 GB, AMD EPYC 9V74 80-Core Processor. Versions: Connection Guard 0.6.1 RC, AdvancedAntiVPN 2.31.8, FoxGate 1.2.0-pre10, KauriVPN 1.10.1.1, ProxyShield 2.5.1, VPNGuard 1.2.0.