Security Guide
January 15, 20248 min read

RuneLite Plugins Safety & Security: How to Tell Which Plugins to Trust

How to know which RuneLite plugins are safe, why the official Plugin Hub is trustworthy, and how malicious 'external repo' plugins like Storm Client's Allure steal accounts.

RuneLite's official plugins are safe. The danger comes from external, closed-source plugins loaded through third-party clients — the category Storm Client's malicious Allure plugins fall into. Here is how to tell the difference.

Why the official Plugin Hub is safe

  • Every plugin is open source and code-reviewed before listing.
  • You can read exactly what each plugin does.
  • Plugins run in RuneLite's controlled environment.

Why "external repos" are risky

Some clients let you add external plugin repositories that are not reviewed by RuneLite. Storm Client uses exactly this mechanism to distribute its Allure plugins — and those plugins were found to steal credentials, session tokens, and Discord data. Once you load an unreviewed external plugin, it runs with full access.

A simple safety checklist

  1. Only install plugins from the official RuneLite Plugin Hub.
  2. Do not add external plugin repositories you cannot audit.
  3. Never pay for closed-source "premium" plugins.
  4. If a client asks you to disable antivirus warnings, stop.

The takeaway

Trust code you (or the community) can read. Distrust closed plugins sold by anonymous developers. Storm Client is the cautionary tale.

Protect Your Account

If you've used Storm Client or Allure plugins, your account may be compromised. Take action now.