Skip to content
Discord server security and configuration audits

Know exactly how your Discord server is configured.

EvaluBot runs one command, inspects nine areas of your server, scores it out of 100, and returns a detailed report with concrete fixes. It never changes a thing.

  • Read-only
  • No Administrator
  • Privacy-first

Server Audit

HTML report

Sample
82out of 100

Good standing

Solid setup with a few fixes to lock things down further.

  • 2FA required for moderatorsPassed
  • 3 channels are thread-vulnerable-12
  • 3 webhooks found-6

9 sections inspected · nothing changed on the server

audit sections
9audit sections
point score
100point score
unsafe permissions tracked
19unsafe permissions tracked
changes made to your server
0changes made to your server
What it inspects

Nine sections, one command.

EvaluBot walks every corner of your server that affects safety and setup, then reports what it finds in plain language. Request the full sweep or just the areas you care about.

Server

Identity, size, verification level, 2FA-for-moderators, community and onboarding descriptions, features, boosts, emoji, sticker and soundboard counts, system, rules and safety channels, vanity URL, and widget.

NeedsView Channels

Roles

Total roles against the 250 limit, administrator roles, roles that can mention everyone, 19 tracked unsafe permissions per role, per-role human and bot counts, plus inactive and near-empty roles.

NeedsView Channels and the Server Members intent

Channels

Every category and channel, their types, last-message activity, custom versus inherited permission overwrites, and thread-vulnerability detection on read-only channels.

NeedsView Channels

Onboarding

Whether onboarding is enabled, the default channels, every prompt, and the roles and channels each option hands out.

NeedsView Channels

Webhooks

Each webhook by name, its target channel, its type, and the account that created it.

NeedsManage Webhooks

Bans

The ban list with reasons, paginated and capped for very large servers. EvaluBot only reads this list and never bans anyone.

NeedsBan Members

Welcome Screen

The community welcome description and the channels featured on the welcome screen.

NeedsNo extra permission

Invites

Active invites by code, channel, creator, uses, and expiry, with never-expiring and high-use invites flagged.

NeedsManage Server

Integrations

Connected apps and bots plus platform links such as Twitch and YouTube, and who added each one.

NeedsManage Server

How it works

From invite to insight in minutes.

No dashboards to configure and no data to hand over. Add the bot, run the command, and read the report.

  1. 01

    Add EvaluBot

    Invite the bot with five read-only permissions. None of them is Administrator, and every one is optional.

  2. 02

    Run one command

    An administrator runs /audit, chooses HTML or JSON, and picks the sections to inspect, or simply audits everything.

  3. 03

    Watch it work

    A live progress bar tracks the run. Under heavy load you get a queue position and an estimated time instead of a failure.

  4. 04

    Read the report

    You receive a scored report with findings grouped into critical, general, and optional fixes. Nothing on your server changes.

Scoring

A single number you can act on.

Every audit starts at 100 and loses points for the risks it finds, then lands between 0 and 100. Findings are grouped into critical, general, and optional fixes so you know what to tackle first.

How points come off

Starts at 100
  • 2FA is not required for moderators-20
  • A role holds an unsafe permission-12
  • A channel is thread-vulnerable-12
  • More than two administrator roles-10
  • Webhooks present-2 each, up to -14
  • More than 500 bans-6
  • Webhook or ban list unreadable-4 each
Signature check

Thread-vulnerable channels

A common misconfiguration lets members slip past a read-only channel. When @everyone is denied Send Messages but is still allowed to Create Public Threads, anyone can post inside a thread that the channel was meant to lock down.

EvaluBot flags every channel where this gap exists, so a channel you believe is locked cannot be quietly bypassed.

19 permissions treated as unsafe on a role

Any role holding one of these is called out.

  • Manage Channels
  • Manage Roles
  • Manage Expressions
  • View Audit Log
  • Manage Webhooks
  • View Server Insights
  • Manage Server
  • Manage Nicknames
  • Moderate Members
  • Ban Members
  • Mention Everyone
  • Manage Messages
  • Manage Threads
  • Mute Members
  • Deafen Members
  • Move Members
  • Priority Speaker
  • Manage Events
  • Pin Messages
Sample report

A report you can actually read.

Every audit ends in a clear, scored report. See what passed, what needs attention, and exactly what to change, all without a single edit to your server.

  • Choose a styled HTML report or raw JSON for your own tooling.
  • The HTML report is self-contained, printable, and easy to share.
  • Findings are grouped into critical, general, and optional fixes.
  • Delivered right inside Discord, with a direct-message fallback if a queued run finishes late.
  • Reports live only as files on the host and are removed after 30 days.
server-audit.html

Overall score

82/ 100

HTMLJSON

Critical

  • Require 2FA for moderators
  • Fix 3 thread-vulnerable channels

General

  • Reduce roles with unsafe permissions
  • Review 3 active webhooks

Optional

  • Prune channels inactive for 90+ days
  • Add onboarding descriptions
Commands

Everything runs from slash commands.

Each command needs the Administrator permission in your server and is disabled in direct messages, so only your team can run an audit.

  • /auditAdmins

    Generate an audit report now, or schedule one for later.

    Options: format (html or json), sections, a saved preset name, and an optional local run time with an IANA timezone.

  • /auditstatusAdmins

    See this server's monthly usage and your own daily usage and remaining runs.

  • /auditscheduleAdmins

    List or cancel your pending scheduled audits.

    Options: cancel with an id.

  • /auditpresetsAdmins

    Save, delete, show, or list reusable section presets.

    Options: up to 20 presets per user.

  • /audithistoryAdmins

    Review your recent audit scores and formats.

    Options: optional guild id and a result limit.

  • /auditdataAdmins

    View or delete the data the bot stores about you.

    Options: delete requires an explicit confirmation.

  • /helpAdmins

    About, links, privacy, and contact information.

  • /auditlimitsBot owners

    Override daily and monthly limits for a user or server, with an automatic expiry.

    Options: reserved for bot owners.

Security and privacy

Read-only by design. No Administrator, ever.

EvaluBot reads your server so it can describe it. It has no code path that bans, kicks, edits, or changes anything. The permissions it asks for are used purely to read.

The read-only guarantee

Ban Members and Manage Server are used only to read the ban list, invites, and integrations. Nothing EvaluBot does can modify your server.

The five permissions it can ask for

View Channels

Read the guild, role, and channel structure.

If declined: Hidden channels are left out of the report.

View Audit Log

Identify who invited the bot for the welcome message.

If declined: The inviter is simply left unknown.

Manage Webhooks

List the webhooks in your server.

If declined: The webhooks section is limited.

Ban Members

Read the ban list. The bot never bans anyone.

If declined: The bans section is limited.

Manage Server

List invites and integrations.

If declined: The invites and integrations sections are limited.

What is stored

  • Audit usage rows: user and server IDs, section scope, format, score, issue count, and timestamp.
  • Limit overrides, server installs and who invited the bot, scheduled jobs, and saved presets.

What is never stored

  • Message content.
  • Report contents or files. Reports exist only as generated files on the host and are removed after 30 days.
  • Audit-log dumps.

Your data, your control

  • View exactly what is stored about you with a single command.
  • Delete your presets, overrides, and pending schedules on request.
  • Past audit rows are anonymized rather than deleted, so per-server monthly counts stay accurate.
  • Five read-only permissions, none of them Administrator
  • Every permission is optional and declining one only limits that section
  • Message content, presence, and other intents are never used
Pricing

Free while EvaluBot is in beta.

Every server gets a free audit each month. Need more while you test or run a specialty community? Ask, and we will sort it out.

Free during beta

Free

1audit / server / month

Resets on the first of every month. The cap is per server, not per person.

  • All nine audit sections
  • Styled HTML or raw JSON reports
  • Scheduled audits in any timezone
  • Up to 20 saved section presets
  • Audit history and score tracking
  • Full data view and deletion controls
Add to Discord

Need more runs

Request access

Running a testing server or a niche community that needs extra audits? Open a ticket on the support server and we will grant more runs with an automatic expiry.

Open a support ticket

Premium

Coming soon

Premium is on the way, and the plan is simple: raise the free monthly allowance once the bot is proven stable. More runs for everyone, not a paywall.

Planned

Daily guardrails keep bursts in check: up to 3 audits per user and 3 per server each day, with up to 10 scheduled audits pending at once.

FAQ

Questions, answered.

Everything you might want to know before you add EvaluBot. Still curious? The support server is one click away.

Is EvaluBot safe to add to my Discord server?

Yes. EvaluBot is read-only. It has no code path that bans, kicks, edits, or changes anything in your server, and it never asks for the Administrator permission.

Does EvaluBot need Administrator permission?

No. EvaluBot asks for up to five read-only permissions, and none of them is Administrator. Every permission is optional, and declining one only limits that section of the report.

What does EvaluBot check?

It inspects nine areas of your server: server settings, roles, channels, onboarding, webhooks, bans, the welcome screen, invites, and integrations. It then scores your server out of 100 and lists concrete fixes.

How much does EvaluBot cost?

EvaluBot is free during beta, with one audit per server each calendar month. If you need more runs, you can request additional audits through the support server.

What is a thread-vulnerable channel?

It is a channel where @everyone is denied Send Messages but is still allowed to Create Public Threads. Members can bypass the read-only channel by posting inside a thread. EvaluBot flags every channel where this gap exists.

What data does EvaluBot store about me?

EvaluBot keeps small usage records such as your audit score, section scope, and a timestamp. It never stores message content, and report files are removed from the host after 30 days. You can view or delete your data at any time.

How do I run an audit?

An administrator runs the /audit command, chooses an HTML or JSON report, and picks the sections to inspect or audits everything. A live progress bar tracks the run, and the finished report is delivered in Discord.

Can I schedule audits in advance?

Yes. You can schedule an audit for a future time in any timezone, and EvaluBot delivers the finished report to you when it runs.

See how your server really scores.

Add EvaluBot, run one command, and get a clear, scored report in minutes. Read-only from start to finish.