We ran 40+ accounts through basically the same setup to figure out what was getting them banned.
The biggest difference we found wasn't session length, breaks, or whether an account botted for 6 hours or 12.
It was the mouse.
If you've spent any time around OSRS botting communities, you've probably heard the same advice a hundred times:
Don't bot overnight. Take breaks. Randomize your sessions. Mix in some manual play. Don't do exactly the same thing every day.
None of that is necessarily bad advice. But after spending the last few months testing our own plugins, I think people put way too much emphasis on it.
We kept seeing accounts with fairly conservative schedules get banned while other accounts doing objectively stupid hours survived.
Eventually we started testing the input system itself.
The results were pretty hard to ignore.
What we tested
The setup was deliberately boring.
We split 40+ fresh F2P accounts into two groups and ran them through the same basic progression:
mine some ore to get starting GP, then move over to smelting steel bars at Edgeville.
Same activities. Same plugins. Same general scheduling logic. Same world rotation.
The main difference was mouse movement.
Group A used a fairly standard bot mouse: Bézier curves with some sinusoidal noise added to make the paths less perfect.
If you've looked through open-source bot clients before, you've probably seen some variation of this. Pick a start point, pick a target, generate a curve between them, add a bit of randomness, click.
It looks fine when you watch it.
Group B used the mouse system we'd been working on, which was built by recording real mouse movements and trying to reproduce the properties we saw in those recordings.
Each account also had its own schedule. Some played around six hours per day, others pushed closer to twelve. Login times and session lengths varied between accounts and from day to day.
There were 20+ accounts in each group.
What happened
Group A got wiped.
Not simultaneously, but the bans started showing up around 15 to 20 hours of total playtime. Some accounts lasted a couple of days. Others barely got through their first long session.
None made it beyond three active days.
Group B was completely different.
At the time I'm writing this, every account in that group has been running for more than two weeks.
And these aren't accounts doing tiny two-hour sessions either. Some of them have regularly been doing 10+ hour days.
That's obviously not enough data to claim we've reverse-engineered Jagex's bot detection. We haven't.
But when you run the same content on 40+ accounts and changing one part of the input stack produces that large a difference, it's worth paying attention to.
And so far, changing the mouse has made a much bigger difference for us than changing session lengths ever did.
The problem with most bot mice
The funny thing is that a normal bot mouse doesn't necessarily look robotic.
Watch a Bézier mouse move across the screen and it seems pretty convincing. The cursor follows a curved path. The speed changes. There's some randomness.
Then we started recording the movements and plotting them.
That's where things got weird.
The paths are way too clean
Real mouse movement is messy.
You start moving in roughly the right direction, drift a little, correct, overshoot occasionally, then make a couple of tiny movements when you're already close to the thing you're trying to click.
If you overlay hundreds of human movements, you get a mess.
That's what you'd expect. Your hand doesn't have the target coordinates available before it starts moving.
Our old generated movements looked nothing like that.
They formed these extremely clean arcs toward the target. When you plotted enough of them together, they almost looked like spikes radiating outward.
We started calling it the sea urchin.
Once you've seen the plot, it's painfully obvious.

The speed is wrong too
The pattern is the loudest tell. It's the one you can spot in a single plot, without measuring anything.
But it isn't the only one.
Humans also don't move the mouse at a constant-ish speed.
Most movements have a quick initial acceleration followed by a longer slowdown as you get closer to the target.
The last part of the movement is usually where all the little corrections happen.
Our generated movements were almost backwards.
They'd accelerate, cruise along most of the path, then stop.
They looked smooth on screen, but the velocity graphs looked nothing like the human recordings.
Humans spend a surprising amount of time correcting
This was probably the biggest thing we underestimated.
The first movement toward a target is only part of the action.
In our recordings, the initial "throw" toward the target was often around 40 to 50% of the movement. The rest was slowing down and correcting.
A mathematical curve doesn't really need to do that.
It already knows exactly where the target is.
So a typical generated mouse spends most of the movement heading directly toward the endpoint and almost no time figuring out how to actually land there.
That's great if you're trying to write a precise cursor animation.
It's probably not great if you're trying to imitate a hand.
Bots are weirdly still
Another stupidly obvious one once we measured it: humans don't leave the mouse perfectly motionless.
Even while you're waiting for something in-game, your hand moves slightly. A few pixels here, a small adjustment there.
Meanwhile a bot happily leaves the cursor sitting on exactly (614, 382) for fifteen seconds until the next action starts.
Then it suddenly comes alive again.
Watching the game normally, you'd never care.
Looking at input data over hours, it sticks out.
So we rebuilt the mouse
Our first attempts at fixing this were basically what everyone else does: start with a nice mathematical path and add more randomness.
More noise. More control points. Random speeds. Random overshoots.
It helped a little, but we eventually realized we were approaching the problem backwards.
Instead of asking:
How do we make this generated curve look more human?
We started asking:
What does an actual human movement look like, statistically?
So we recorded manual OSRS sessions and built tooling around analyzing the resulting movements.
Path shape, velocity, acceleration, corrections, overshoots, idle movement, target distance, movement duration, and a bunch of other stuff.
Then we built the generator around reproducing those behaviors rather than producing a perfect path first and trying to ruin it afterward.
The result is intentionally kind of bad at moving the mouse.
It drifts.
It starts heading somewhere before fully settling on the final trajectory.
It overshoots sometimes.
It slows down and makes tiny corrections near the target.
Basically, it behaves more like someone dragging a physical mouse around and less like a function interpolating between two coordinates.

We also vary the parameters over longer sessions.
Someone who's been playing for six hours doesn't move exactly like they did five minutes after logging in. Movements get a little slower and a little less precise, and corrections become slightly more common.
We're still experimenting with this part, but it showed up consistently enough in our recordings that it made sense to model.
Each Pluginscape installation also gets its own movement profile.
That part matters because making one "perfect human mouse" and running the exact same statistical profile across hundreds of accounts would create another fingerprint of its own.
Does this mean Jagex only cares about mouse movement?
No.
And I wouldn't trust anyone claiming they know exactly what Jagex's detection system looks at.
There are obviously a lot of possible signals: account history, activities, session patterns, client behavior, interactions, inputs, and probably plenty of things we haven't thought of.
What our tests do suggest is that mouse movement deserves a lot more attention than it gets.
Session length is inherently messy as a detection signal.
Real OSRS players are insane.
People play fourteen-hour sessions. People click the same tree for days. Someone will decide they're going to get 99 Fishing using shrimp in Al Kharid purely because they think it's funny.
Human behavior has enormous variance.
Input data is different.
When you collect thousands of mouse movements, patterns start appearing that aren't particularly obvious while watching someone play.
And if your generator produces those same patterns over and over again, changing your login schedule from 7 hours to 6 hours and 43 minutes probably isn't going to fix the underlying problem.
That's the main thing we took away from these tests.
We used to spend a lot of time worrying about schedules.
Now the input layer is one of the first things we look at.
The takeaway
If your accounts keep getting banned after roughly the same amount of playtime, even after changing activities and messing with session schedules, I'd take a serious look at your mouse implementation.
And don't judge it by watching the cursor.
Record the movements.
Plot them.
Look at velocity and acceleration. Look at how much time is spent correcting near the target. Look at idle periods. Overlay a few thousand trajectories and compare them with actual manual play.
That's how we ended up rebuilding the Pluginscape mouse system.
Not because our old mouse looked obviously robotic.
It didn't.
It looked completely fine.
The data just looked wrong.
And so far, fixing that has produced the biggest improvement we've seen in account survival.
Pluginscape plugins use our input system automatically. There's nothing to configure. Browse plugins →