Free · MIT · FiveM

molfar_audit

Find broken manifests, missing items, risky server settings and exploitable events — in one command.

~5 s~100 resources, ~600 Lua files
~50 mslongest continuous work
0.00 msidle in resmon
0secrets in reports

Console summary, full report in the browser

Type audit in the server console. You get the top findings right there and a link to a filterable report with an explanation and a fix for every finding. Both screenshots are from a fresh Qbox recipe server.

molfar_audit console output
molfar_audit web report

Install

  1. Download molfar_audit.zip from the latest release and extract it into your resources folder.
  2. Add ensure molfar_audit to server.cfg, after your other resources.
  3. Restart the server and type audit in the console or txAdmin Live Console.

Optional, to let in-game admins run it: add_ace group.admin command.audit allow

Usage

audit                 full audit
audit items lua       only some groups (manifest, items, config, lua)
audit last            show the link to the last report again

The report link is valid for 60 minutes. Every report is also saved to molfar_audit/reports/ as JSON. No console access on your host? Add set molfar_audit:autorun 60 to server.cfg to run the audit 60 seconds after start.

False positives

Findings marked possible are heuristics — read the code before changing it. To hide a finding, add a comment on the same or the previous line:

player.Functions.AddMoney('cash', amount) -- molfar-audit-ignore LUA001

or ignore by rule, resource or path in config.json:

"ignore": [{ "rule": "LUA002" }, { "resource": "qbx_*", "rule": "LUA003" }, { "path": "[standalone]/**" }]

Security

  • Server-side only. Nothing is sent to players and report data never leaves your server.
  • The report link carries a random 256-bit token, expires after 60 minutes and is rate-limited against guessing.
  • Reports never contain convar values: no license key, database or RCON passwords, Steam key.
  • Prefer the console only? Set "web": { "enabled": false } in config.json.

Requirements

  • FXServer build 35245 or newer.
  • ox_inventory for the item checks (other inventories: disable the items group).
  • Tested on Qbox. QBCore and ESX servers that use ox_inventory should work the same way.

Found a bug or a false positive?

Open an issue on GitHub with the snippet — rules get better with every report.