WordPress plugin · GPLv2 · v1.0.10

Korisec Security for WordPress

Hosted vulnerability checks and local login protection. Scans run in Korisec’s cloud — not on your server — with plain-English findings, CVE links, and one-click paths to update plugins and themes.

Free GPLv2 plugin — install from WordPress.org. Cloud checks use your Korisec account (14-day trial, then a paid plan). Source mirror on GitHub. Current release: v1.0.10.

Three steps, no scanner on your host

1

Create a Korisec account

Sign up at app.korisec.com and add a plugin key under Account → API keys. The key starts with kr_live_.

2

Install the plugin

Install Korisec Security from WordPress.org, activate it, then open Korisec in wp-admin.

3

Paste the key and Connect

Nothing is sent until a site administrator connects. Connecting binds the key to this host and agrees to Korisec’s Terms and Privacy Policy.

Cloud checks + light local protection

Vulnerability scanner (hosted)

Reports WordPress core, plugin, and theme versions so cloud checks can find known CVEs — including software that is not visible from the public internet.

Actionable findings

See grade, severity, CVE links, and shortcuts to Plugins / Themes / Updates in wp-admin. Full history and PDFs stay in your Korisec account.

Login protection (local)

Limits failed wp-login attempts by IP. Runs on your site only — no Korisec API call — and works even before you connect a key.

Version history

Same notes as readme.txt on WordPress.org. Current release: 1.0.10.

1.0.10

  • Directory display name: Korisec Security – Vulnerability Scanner and Login Protection
  • SEO-focused short description and tags (vulnerability scanner, login security, brute force)

1.0.9

  • Findings show CVE links, known-exploited badges, and one-click links to Plugins / Themes / Updates when a fix version is known
  • Login protection: limit failed wp-login attempts by IP (local; on by default; configurable under Protection)

1.0.8

  • WordPress Plugin Check (plugin-repo) fixes: nonce in AJAX handlers, JSON payload sanitization, no false Cloudflare offload string

1.0.7

  • Reliable connection is on automatically so site owners do not edit wp-config.php

1.0.6

  • WordPress.org packaging: privacy policy suggestion, uninstall cleanup, i18n, service documentation
  • Origin IP pin is off unless KORISEC_PIN_ORIGIN is defined
  • Plugin key is sanitized before storage

1.0.5

  • Horizontal tabs for billing, team seats, PDF / white-label reports, and alerts
  • Plugin key can only manage the Korisec billing account that issued it

1.0.4

  • In-admin dashboard: grade, score, grouped findings, recent checks, live progress

1.0.3

  • Optional origin pin for hosts that cannot reach api.korisec.com through Cloudflare

1.0.2

  • Only treat Cloudflare challenge pages as Bot Fight blocks

1.0.1

  • Clearer connect errors when the API is unreachable
  • WordPress AJAX no longer returns HTTP 403 for Korisec API errors

1.0.0

  • First release: connect, inventory, run check, grade

Need an account first? Start a 14-day trial, create a plugin key, then Connect in wp-admin. Get started →