Create a Korisec account
Sign up at app.korisec.com and add a plugin key under Account → API keys. The key starts with kr_live_.
WordPress plugin · GPLv2 · v1.0.10
Hosted vulnerability checks and local login protection. Scans run in Korisec’s cloud — not on your server — with plain-English findings, CVE links, and one-click paths to update plugins and themes.
Free GPLv2 plugin — install from WordPress.org. Cloud checks use your Korisec account (14-day trial, then a paid plan). Source mirror on GitHub. Current release: v1.0.10.
How it works
Sign up at app.korisec.com and add a plugin key under Account → API keys. The key starts with kr_live_.
Install Korisec Security from WordPress.org, activate it, then open Korisec in wp-admin.
Nothing is sent until a site administrator connects. Connecting binds the key to this host and agrees to Korisec’s Terms and Privacy Policy.
What the plugin does
Reports WordPress core, plugin, and theme versions so cloud checks can find known CVEs — including software that is not visible from the public internet.
See grade, severity, CVE links, and shortcuts to Plugins / Themes / Updates in wp-admin. Full history and PDFs stay in your Korisec account.
Limits failed wp-login attempts by IP. Runs on your site only — no Korisec API call — and works even before you connect a key.
Changelog
Same notes as readme.txt on WordPress.org. Current release: 1.0.10.