Free · MIT · FiveM
molfar_audit
Find broken manifests, missing items, risky server settings and exploitable events — in one command.
Console summary, full report in the browser
Type audit in the server console. You get the top findings right there and a link to a filterable report with an explanation and a fix for every finding. Both screenshots are from a fresh Qbox recipe server.


What it checks
Manifests & resources
ox_inventory items
Server config
CfxLua syntax is supported (backtick hashes, +=, ?., <const>, /* */). Escrowed files are skipped.
Install
- Download
molfar_audit.zipfrom the latest release and extract it into yourresourcesfolder. - Add
ensure molfar_audittoserver.cfg, after your other resources. - Restart the server and type
auditin the console or txAdmin Live Console.
Optional, to let in-game admins run it: add_ace group.admin command.audit allow
Usage
audit full audit
audit items lua only some groups (manifest, items, config, lua)
audit last show the link to the last report again
The report link is valid for 60 minutes. Every report is also saved to molfar_audit/reports/ as JSON. No console access on your host? Add set molfar_audit:autorun 60 to server.cfg to run the audit 60 seconds after start.
False positives
Findings marked possible are heuristics — read the code before changing it. To hide a finding, add a comment on the same or the previous line:
player.Functions.AddMoney('cash', amount) -- molfar-audit-ignore LUA001
or ignore by rule, resource or path in config.json:
"ignore": [{ "rule": "LUA002" }, { "resource": "qbx_*", "rule": "LUA003" }, { "path": "[standalone]/**" }]
Security
- Server-side only. Nothing is sent to players and report data never leaves your server.
- The report link carries a random 256-bit token, expires after 60 minutes and is rate-limited against guessing.
- Reports never contain convar values: no license key, database or RCON passwords, Steam key.
- Prefer the console only? Set
"web": { "enabled": false }inconfig.json.
Requirements
- FXServer build 35245 or newer.
- ox_inventory for the item checks (other inventories: disable the
itemsgroup). - Tested on Qbox. QBCore and ESX servers that use ox_inventory should work the same way.
Found a bug or a false positive?
Open an issue on GitHub with the snippet — rules get better with every report.