Published run6–7 October 2026 · Velocity · 3 rounds
Measured, not claimed.
We run the popular free anti-VPN plugins on the same server, with the same players and the same simulated detection services, and publish every number and log. Connection Guard included, so check our work.
Conflict of interest: the benchmark is built by Connection Guard's author. The method, the adapters and every log are public, and any plugin author can contest a result. Every plugin runs as it ships, without API keys. A second pass with the same free ProxyCheck key for every plugin follows. Connection Guard 0.6.1 RC is a release candidate: downloads deliver 0.6.0 until it ships, and 0.6.0's results are shown where they differ.
Join wave
999 / 1,000
players looked up when 1,000 joined in 20 seconds. The other plugins looked up at most 783.
See the numbers →
Detection services down
4 / 4
failure cases with VPN and Tor still blocked, without a single lookup.
See the numbers →
Caught
282 / 282
VPN and Tor addresses blocked. 2 of 310 home and mobile players were refused too, the fewest of the plugins that block most VPNs.
See the numbers →
1,000 players join at once.
50 new players per second for 20 seconds. Each detection service is simulated with the same delay and its real free-tier limit, so a plugin can't look fast by asking a service that would refuse it in reality.
Measured with run 37643006094 for Connection Guard 0.6.1 RC and run 37624137638 for the others.
Time until the plugin decides
95th percentile, and how many of the 1,000 players it looked up. Lower time is better.
- Connection Guard504 ms999 looked up
- ProxyShield7.6 s303 looked up
- VPNGuard11 s53 looked up
- FoxGate30 stimed out · 169 looked up
- AdvancedAntiVPN30 stimed out · 508 looked up
- KauriVPNafter joinlets everyone in, kicks later
What players feel
Join time during the wave, 95th percentile, next to the same proxy with no anti-VPN plugin.
- Connection Guard898 ms
- No anti-VPN plugin438 ms
- KauriVPN435 ms
- ProxyShield13 s
- VPNGuard18 s
- FoxGate27 s
- AdvancedAntiVPN28 s
One player in the wave was refused: the wave's random addresses include one in a range Connection Guard Intel lists as VPN.
| Scenario | Connection Guard0.6.1 RC | AdvancedAntiVPN2.31.8 | FoxGate1.2.0-pre10 | KauriVPN1.10.1.1 | ProxyShield2.5.1 | VPNGuard1.2.0 |
|---|---|---|---|---|---|---|
| First join of a new player50 new players, one after another | 132 msp95 289 ms | 244 msp95 421 ms | 843 msp95 6.0 s | after join | 789 msp95 1.4 s | 130 msp95 288 ms |
| The same players againAnswers can come from the cache | 3 msp95 4 ms | 4 msp95 5 ms | 452 msp95 5.3 s | after join | 2 msp95 2 ms | 2 msp95 2 ms |
| 100 joins from one address at onceA bot wave from one IP | 88 msp95 117 ms | 8.5 sp95 13 s | 453 msp95 651 ms | after join | 928 msp95 1.3 s | 1.1 sp95 1.1 s |
| 1,000 new players in 20 seconds50 per second, each from a new address | 208 msp95 504 ms | 30 sp95 30 s, timed out | 30 sp95 30 s, timed out | after join | 1.2 sp95 7.6 s | 10 sp95 11 s |
KauriVPN lets every player join and checks afterwards, kicking a VPN user a moment later. Its times measure the login, not a decision, so they are not compared here.
When the detection services fail.
Free detection services time out, rate-limit and break. We make every one of them fail in five ways and send a VPN, a Tor exit and a home player during the outage.
Measured with run 37622124772 for Connection Guard 0.6.1 RC and runs 37593590733, 37624132539 for the others.
| Failure | Connection Guard0.6.1 RC | AdvancedAntiVPN2.31.8 | FoxGate1.2.0-pre10 | KauriVPN1.10.1.1 | ProxyShield2.5.1 | VPNGuard1.2.0 | Connection Guard0.6.0 |
|---|---|---|---|---|---|---|---|
| Everything working | VPNTor | VPNTor | VPNTor | VPNTor | VPNTor | VPNTor | VPNTor |
| Services time out | VPNTor | VPNTor | VPNTor | VPNTor | VPNTor | VPNTor | VPNTor |
| Services rate-limit (429) | VPNTor | VPNTor | VPNTor | VPNTor | VPNTor | VPNTor | VPNTor |
| Services send broken answers | VPNTor | VPNTor | VPNTor | VPNTor | VPNTor | VPNTor | VPNTor |
| Services cut answers off | VPNTor | VPNTor | VPNTor | VPNTor | VPNTor | VPNTor | VPNTor |
| Home player's login while services time outLower is better; everyone lets the player in | 5.0 s | 3.0 s | 11 s | 3 ms | 6.7 s | 5.0 s | 5.0 s |
A check means the VPN or Tor exit was still refused while every detection service failed that way. Connection Guard checks its own signed lists of VPN servers and Tor exits (Connection Guard Intel) on the server before asking any service, so a known VPN needs no lookup at all. When several services hang at once, a home player's first login can take up to about 5 seconds; services that time out are then skipped for a while.
Who gets caught, who gets in.
692 labelled addresses, each with its source: VPN servers from the providers' own lists, Tor exits from the Tor Project, and home and mobile connections from volunteers' RIPE Atlas probes.
Measured with run 37666758972 for Connection Guard 0.6.1 RC and runs 37540326121, 37623918344, 37646483626 for the other plugins, keyless.
| Group | Connection Guard | AdvancedAntiVPN* | FoxGate | KauriVPN | ProxyShield | VPNGuard |
|---|---|---|---|---|---|---|
| Should be blocked: higher is better | ||||||
| Commercial VPNs | 125 / 125 | 18 / 125 | 125 / 125 | 124 / 125 | 125 / 125 | 124 / 125 |
| Newly added VPN servers | 37 / 37 | 6 / 37 | 37 / 37 | 37 / 37 | 37 / 37 | 37 / 37 |
| VPNs over IPv6 | 40 / 40 | 11 / 40 | 39 / 40 | 2 / 40 | 39 / 40 | 36 / 40 |
| Tor exits | 80 / 80 | 15 / 80 | 80 / 80 | 79 / 80 | 80 / 80 | 78 / 80 |
| Public proxies | 93 / 100 | 17 / 100 | 92 / 100 | 68 / 100 | 96 / 100 | 89 / 100 |
| Should get in: lower is better | ||||||
| Home connections | 0 / 150 | 0 / 150 | 3 / 150 | 5 / 150 | 4 / 150 | 3 / 150 |
| Home connections, IPv6 | 0 / 60 | 0 / 60 | 3 / 60 | 4 / 60 | 3 / 60 | 3 / 60 |
| Mobile networks | 2 / 100 | 0 / 100 | 1 / 100 | 2 / 100 | 2 / 100 | 2 / 100 |
Read the VPN rows with care: Connection Guard's own lists are built from the same provider lists that label these addresses, so for those groups they show coverage, not how well it finds unknown servers. Tor, proxies and the false positives are not affected.
*AdvancedAntiVPN ran in a separate run without the shared free ProxyCheck key the others' keyless lookups got, so its free quotas ran out after about 100 players and it let the rest in. A run with the same key for every plugin follows.
Connection Guard 0.6.1 RC refused 2 of 310 home and mobile players, both mobile connections; FoxGate, ProxyShield, VPNGuard and KauriVPN refuse one of the two as well. Version 0.6.0 refused 10 here, four of them on a single answer from one detection service, Blackbox. From 0.6.1 on, a Blackbox answer needs a second source before a player is refused.
How it's measured.
- Unmodified plugin JARs from their official pages, with checksums, on one pinned server build.
- A real Minecraft client logs in from each test address, so every plugin sees what it would see in production.
- Detection services are recorded once and replayed to every plugin, with the same delay (120 ms median, 350 ms at p95) and each service's free-tier limit.
- Each plugin runs with its documented settings, enforcement switched on. No plugin-specific tuning.
- No combined score: speed, reliability and detection are reported separately, with every denominator.
What it doesn't show.
- Velocity only on this page; Paper, Folia and BungeeCord results are in the repository.
- Simulated services measure how a plugin handles them, not how good each service is.
- The dataset is a snapshot. VPN servers and Tor exits change; we rebuild it and keep every old run.
- Results are the median of three rounds.
Plugin author and see something wrong? Contest a result. Corrections are re-measured, and the original stays in the history.
Run it yourself.
Docker on Linux or Docker Desktop with 6 GB, about 15 GB of disk. Or fork the repository and start the GitHub Actions workflow.
$ git clone https://github.com/gerolndnr/mc-antivpn-bench $ cd mc-antivpn-bench $ docker build -t mc-antivpn-bench:dev harness/docker $ docker run --rm -v "$PWD:/bench" -e PYTHONPATH=/bench/harness --entrypoint python3 mc-antivpn-bench:dev -m bench.dataset materialize $ docker run --rm --cap-add NET_ADMIN -v "$PWD:/bench" -v mcbench-work:/work -e PYTHONPATH=/bench/harness \ --entrypoint python3 mc-antivpn-bench:dev -m bench run performance --platforms velocity
This page: performance run, detection run, failure run. Runner: GitHub-hosted 4 vCPU, 15 GB, AMD EPYC 9V74 80-Core Processor. Versions: Connection Guard 0.6.1 RC, AdvancedAntiVPN 2.31.8, FoxGate 1.2.0-pre10, KauriVPN 1.10.1.1, ProxyShield 2.5.1, VPNGuard 1.2.0.