{"id":362788,"date":"2026-09-14T07:42:48","date_gmt":"2026-09-14T07:42:48","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/korisec\/"},"modified":"2026-10-06T19:05:02","modified_gmt":"2026-10-06T19:05:02","slug":"korisec","status":"publish","type":"plugin","link":"https:\/\/mya.wordpress.org\/plugins\/korisec\/","author":23559206,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"1.1.1","stable_tag":"1.1.1","tested":"7.1.3","requires":"6.0","requires_php":"7.4","requires_plugins":null,"header_name":"Korisec Security \u2013 Vulnerability Scanner, Login Protection and Backup","header_author":"Korisec","header_description":"Connect this site to Korisec cloud security checks. Scans run on Korisec; this plugin reports installed plugins and shows your grade.","assets_banners_color":"ff3435","last_updated":"2026-10-06 19:05:02","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"https:\/\/korisec.com\/wordpress\/","header_author_uri":"https:\/\/korisec.com","rating":0,"author_block_rating":0,"active_installs":0,"downloads":447,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"1.0.10":{"tag":"1.0.10","author":"korisec","date":"2026-09-14 18:20:58","revision":3695745},"1.0.11":{"tag":"1.0.11","author":"korisec","date":"2026-09-15 08:10:03","revision":3696461},"1.0.12":{"tag":"1.0.12","author":"korisec","date":"2026-09-15 08:15:56","revision":3696471},"1.0.8":{"tag":"1.0.8","author":"korisec","date":"2026-09-14 07:42:27","revision":3694714},"1.0.9":{"tag":"1.0.9","author":"korisec","date":"2026-09-14 18:02:49","revision":3695713},"1.1.0":{"tag":"1.1.0","author":"korisec","date":"2026-10-05 18:34:17","revision":3729483},"1.1.1":{"tag":"1.1.1","author":"korisec","date":"2026-10-06 19:05:02","revision":3731435}},"upgrade_notice":{"1.1.1":"<p>Fixes a restore failure on busy sites, warns when WP-Cron is not running, applies retention immediately, and cleans up corrupted backups.<\/p>","1.1.0":"<p>Adds free encrypted Google Drive backups with one-click restore and undo.<\/p>","1.0.12":"<p>Fixes broken Update buttons on the Actions tab.<\/p>","1.0.11":"<p>Actions tab with update links and one-click exposure remedies.<\/p>","1.0.10":"<p>Clearer plugin title and directory tags for security search.<\/p>","1.0.9":"<p>Actionable findings plus local login attempt limiting.<\/p>","1.0.8":"<p>WordPress.org Plugin Check clean-up.<\/p>","1.0.7":"<p>Connects more reliably without editing wp-config.php.<\/p>","1.0.6":"<p>Privacy and uninstall cleanup.<\/p>"},"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3694724,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3694724,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256},"icon.svg":{"filename":"icon.svg","revision":3694724,"resolution":false,"location":"assets","locale":false}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3694724,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3694724,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["1.0.10","1.0.11","1.0.12","1.0.8","1.0.9","1.1.0","1.1.1"],"block_files":[],"assets_screenshots":[],"screenshots":[]},"plugin_section":[],"plugin_tags":[151,2439,1229,600,139069],"plugin_category":[54],"plugin_contributors":[280611],"plugin_business_model":[],"class_list":["post-362788","plugin","type-plugin","status-publish","hentry","plugin_tags-backup","plugin_tags-brute-force","plugin_tags-login-security","plugin_tags-security","plugin_tags-vulnerability-scanner","plugin_category-security-and-spam-protection","plugin_contributors-korisec","plugin_committers-korisec"],"banners":{"banner":"https:\/\/ps.w.org\/korisec\/assets\/banner-772x250.png?rev=3694724","banner_2x":"https:\/\/ps.w.org\/korisec\/assets\/banner-1544x500.png?rev=3694724","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":"https:\/\/ps.w.org\/korisec\/assets\/icon.svg?rev=3694724","icon":"https:\/\/ps.w.org\/korisec\/assets\/icon.svg?rev=3694724","icon_2x":false,"generated":false},"screenshots":[],"raw_content":"<!--section=description-->\n<p>Korisec is a <strong>hosted<\/strong> website security service. This plugin is the official WordPress client: it does not run port scans, Nuclei, or other scanners inside WordPress.<\/p>\n\n<p>After you paste a plugin key from your Korisec account, the plugin:<\/p>\n\n<ol>\n<li>Verifies this site with Korisec and binds the key to this host<\/li>\n<li>Sends WordPress core, plugin, and theme versions so cloud checks can include software that is not visible from the public internet<\/li>\n<li>Lets you start a cloud check from wp-admin and show grade, findings, and history<\/li>\n<li>Lets the <strong>billing owner<\/strong> who issued the key manage plan, team seats, PDF reports, and alerts (Telegram, Slack, WhatsApp, webhook)<\/li>\n<\/ol>\n\n<p>Without a key, login protection and optional exposure remedies (XML-RPC, public usernames, install.php) still run locally. Those features do not send data to Korisec.<\/p>\n\n<h4>Free encrypted backups to Google Drive<\/h4>\n\n<p>Backups are free for every site and do not need a Korisec key.<\/p>\n\n<ul>\n<li>Backs up the full database and <code>wp-content<\/code> (plugins, themes, uploads) plus <code>wp-config.php<\/code><\/li>\n<li>Everything is encrypted on your server before upload (XChaCha20-Poly1305). Google and Korisec never see your data<\/li>\n<li>Daily or weekly schedule, or back up on demand. Choose how many restore points to keep<\/li>\n<li>Each backup is verified after upload (size and checksum). A backup is only listed as restorable once it is verified<\/li>\n<li>One-click restore. A safety backup of the current site is always taken first<\/li>\n<li>Restores swap tables and folders atomically. If anything looks wrong you can <strong>undo<\/strong> the restore instantly<\/li>\n<li>Download a recovery key so you can restore onto a fresh WordPress install after a total loss<\/li>\n<li>Large sites are processed in small resumable steps, so it works on shared hosting<\/li>\n<\/ul>\n\n<p>Paid plans, daily scan limits, and white-label PDFs are features of the <strong>Korisec service<\/strong>, not locked code inside this plugin. The plugin\u2019s PHP is fully available under GPLv2 or later.<\/p>\n\n<h4>External services<\/h4>\n\n<p>Hosted security checks require a Korisec account and talk to <code>https:\/\/api.korisec.com<\/code> (unless you set <code>KORISEC_API_BASE<\/code> in wp-config.php).<\/p>\n\n<ul>\n<li>Terms of Use: https:\/\/korisec.com\/terms.html<\/li>\n<li>Privacy Policy: https:\/\/korisec.com\/privacy.html<\/li>\n<li>Plugin page: https:\/\/korisec.com\/wordpress\/<\/li>\n<li>Dashboard: https:\/\/app.korisec.com<\/li>\n<\/ul>\n\n<p>Nothing is sent until a site administrator pastes a <code>kr_live_\u2026<\/code> key and clicks Connect.<\/p>\n\n<h4>Data sent after Connect<\/h4>\n\n<p>Typical payloads include this site\u2019s URL and host, WordPress and PHP versions, names and versions of installed plugins\/themes (and whether they are active), heartbeat, scan start\/status requests, and billing\/team\/alert settings for the Korisec account that issued the key.<\/p>\n\n<h4>Google Drive backups<\/h4>\n\n<p>Nothing is contacted until an administrator clicks <strong>Connect Google Drive<\/strong> on the Backups tab.<\/p>\n\n<ul>\n<li><strong>Google Drive API<\/strong> (<code>https:\/\/www.googleapis.com<\/code>, <code>https:\/\/oauth2.googleapis.com<\/code>) stores the encrypted backup files in a \u201cKorisec Backups\u201d folder in your own Drive. The plugin asks only for the <code>drive.file<\/code> permission, so it can see only the files it created. Google\u2019s terms: https:\/\/policies.google.com\/terms and privacy policy: https:\/\/policies.google.com\/privacy<\/li>\n<li><strong>Korisec sign-in relay<\/strong> (<code>https:\/\/api.korisec.com<\/code>, the same service that runs Korisec\u2019s own Sign in with Google) completes the Google sign-in and renews short-lived Google access tokens, because Google requires a client secret that cannot ship inside a plugin. The relay receives this site\u2019s admin URL, a one-time public key, and (on each renewal) the Google refresh token. It returns the tokens encrypted to this site and stores nothing. It never receives backup contents or your encryption key.<\/li>\n<\/ul>\n\n<p>Backups are encrypted before they leave your server. The encryption key is stored in this site\u2019s database, wrapped with the salts in <code>wp-config.php<\/code>, and can be downloaded as a recovery key.<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Create a Korisec account at https:\/\/app.korisec.com\/signup and add a plugin key under Account \u2192 API keys<\/li>\n<li>Install this plugin and activate it<\/li>\n<li>Open <strong>Korisec<\/strong> in wp-admin, paste the key, and Connect (you agree to Korisec\u2019s terms and privacy policy)<\/li>\n<li>Run a check, or wait for Korisec\u2019s scheduled scans<\/li>\n<\/ol>\n\n<p>The plugin connects to Korisec automatically. You do not need to edit wp-config.php.<\/p>\n\n<!--section=faq-->\n<dl>\n<dt id=\"does%20this%20plugin%20scan%20my%20server%3F\"><h3>Does this plugin scan my server?<\/h3><\/dt>\n<dd><p>No. Checks run on Korisec workers. The plugin only reports inventory and displays results.<\/p><\/dd>\n<dt id=\"why%20do%20i%20need%20a%20key%3F\"><h3>Why do I need a key?<\/h3><\/dt>\n<dd><p>The key authenticates this site to the Korisec API. It is not a license gate for local scanner code. Without a key the plugin does not contact Korisec.<\/p><\/dd>\n<dt id=\"what%20if%20my%20korisec%20plan%20ends%3F\"><h3>What if my Korisec plan ends?<\/h3><\/dt>\n<dd><p>The hosted service pauses cloud checks until the account is renewed. The plugin itself remains installed and GPLv2 licensed.<\/p><\/dd>\n<dt id=\"how%20do%20i%20stop%20sending%20data%3F\"><h3>How do I stop sending data?<\/h3><\/dt>\n<dd><p>Disconnect on the Connection tab, or delete the plugin. Deleting removes the stored key from WordPress. Korisec account history is managed in the Korisec dashboard.<\/p><\/dd>\n<dt id=\"are%20backups%20really%20free%3F\"><h3>Are backups really free?<\/h3><\/dt>\n<dd><p>Yes. Backups to your own Google Drive are free on any site and do not need a Korisec account or key. Storage comes from your Google Drive quota.<\/p><\/dd>\n<dt id=\"can%20korisec%20or%20google%20read%20my%20backups%3F\"><h3>Can Korisec or Google read my backups?<\/h3><\/dt>\n<dd><p>No. The database and files are encrypted on your server before upload. Only someone with this site\u2019s key (or your downloaded recovery key) can decrypt them.<\/p><\/dd>\n<dt id=\"what%20happens%20if%20a%20restore%20goes%20wrong%3F\"><h3>What happens if a restore goes wrong?<\/h3><\/dt>\n<dd><p>Before every restore Korisec takes and verifies a safety backup of the current site. The restore swaps tables and folders in one step. You can then undo it with one click, or keep it once you have checked the site.<\/p><\/dd>\n<dt id=\"what%20if%20i%20lose%20the%20whole%20site%3F\"><h3>What if I lose the whole site?<\/h3><\/dt>\n<dd><p>Install WordPress and Korisec on the new server, connect the same Google Drive, then import your recovery key on the Backups tab. Your backups appear and can be restored.<\/p><\/dd>\n<dt id=\"what%20is%20not%20restored%20automatically%3F\"><h3>What is not restored automatically?<\/h3><\/dt>\n<dd><p>wp-config.php is included in every backup but is not overwritten on restore, so database credentials for a new host are kept. WordPress core files are not backed up; reinstall core from WordPress.org. Multisite networks are not supported yet.<\/p><\/dd>\n<dt id=\"what%20happens%20to%20backups%20if%20i%20delete%20the%20plugin%3F\"><h3>What happens to backups if I delete the plugin?<\/h3><\/dt>\n<dd><p>Backups stay in your Google Drive. The encryption key is kept in the database so a reinstall can still read them. Download the recovery key before moving or wiping the site.<\/p><\/dd>\n<dt id=\"can%20i%20point%20the%20plugin%20at%20my%20own%20api%3F\"><h3>Can I point the plugin at my own API?<\/h3><\/dt>\n<dd><p>Yes. In wp-config.php set <code>define( 'KORISEC_API_BASE', 'https:\/\/your-host.example' );<\/code><\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>1.1.1<\/h4>\n\n<ul>\n<li>Redesigned Backups screen: stat cards, side-by-side recovery key and settings, and Bootstrap-styled fields and buttons<\/li>\n<li>WP-Cron health check: tested when the plugin is activated and monitored hourly. Korisec warns in wp-admin if scheduled tasks stop running, since automatic backups depend on them<\/li>\n<li>Fix: restores could fail with a duplicate key error when a background step and the Backups screen ran at the same time<\/li>\n<li>Lowering the number of backups to keep now removes the extra backups right away instead of after the next backup<\/li>\n<li>Corrupted backups are re-checked in Google Drive: intact ones become restorable again, damaged ones are removed after 7 days to free space<\/li>\n<\/ul>\n\n<h4>1.1.0<\/h4>\n\n<ul>\n<li>New: free encrypted backups to Google Drive (database + wp-content + wp-config.php), no Korisec key needed<\/li>\n<li>Daily or weekly schedule, retention, remote verification, and audit log<\/li>\n<li>One-click restore with automatic safety backup and instant undo<\/li>\n<li>Recovery key for restoring onto a fresh WordPress install<\/li>\n<\/ul>\n\n<h4>1.0.12<\/h4>\n\n<ul>\n<li>Fix Actions-tab Update links showing \u201cThe link you followed has expired\u201d (nonce URLs were HTML-escaped twice)<\/li>\n<\/ul>\n\n<h4>1.0.11<\/h4>\n\n<ul>\n<li>Actions tab: update outdated plugins\/themes with deep links, plus one-click remedies for XML-RPC, public usernames, and wp-admin\/install.php<\/li>\n<li>Richer inventory (plugin file paths and WordPress-known updates) posted before each check<\/li>\n<\/ul>\n\n<h4>1.0.10<\/h4>\n\n<ul>\n<li>Directory display name: Korisec Security \u2013 Vulnerability Scanner and Login Protection<\/li>\n<li>SEO-focused short description and tags (vulnerability scanner, login security, brute force)<\/li>\n<\/ul>\n\n<h4>1.0.9<\/h4>\n\n<ul>\n<li>Findings show CVE links, known-exploited badges, and one-click links to Plugins \/ Themes \/ Updates when a fix version is known<\/li>\n<li>Login protection: limit failed wp-login attempts by IP (local; on by default; configurable under Protection)<\/li>\n<\/ul>\n\n<h4>1.0.8<\/h4>\n\n<ul>\n<li>WordPress Plugin Check (plugin-repo) fixes: nonce in AJAX handlers, JSON payload sanitization, no false Cloudflare offload string<\/li>\n<\/ul>\n\n<h4>1.0.7<\/h4>\n\n<ul>\n<li>Reliable connection is on automatically so site owners do not edit wp-config.php<\/li>\n<\/ul>\n\n<h4>1.0.6<\/h4>\n\n<ul>\n<li>WordPress.org packaging: privacy policy suggestion, uninstall cleanup, i18n, service documentation<\/li>\n<li>Origin IP pin is off unless KORISEC_PIN_ORIGIN is defined<\/li>\n<li>Plugin key is sanitized before storage<\/li>\n<\/ul>\n\n<h4>1.0.5<\/h4>\n\n<ul>\n<li>Horizontal tabs for billing, team seats, PDF \/ white-label reports, and alerts<\/li>\n<li>Plugin key can only manage the Korisec billing account that issued it<\/li>\n<\/ul>\n\n<h4>1.0.4<\/h4>\n\n<ul>\n<li>In-admin dashboard: grade, score, grouped findings, recent checks, live progress<\/li>\n<\/ul>\n\n<h4>1.0.3<\/h4>\n\n<ul>\n<li>Optional origin pin for hosts that cannot reach api.korisec.com through Cloudflare<\/li>\n<\/ul>\n\n<h4>1.0.2<\/h4>\n\n<ul>\n<li>Only treat Cloudflare challenge pages as Bot Fight blocks<\/li>\n<\/ul>\n\n<h4>1.0.1<\/h4>\n\n<ul>\n<li>Clearer connect errors when the API is unreachable<\/li>\n<li>WordPress AJAX no longer returns HTTP 403 for Korisec API errors<\/li>\n<\/ul>\n\n<h4>1.0.0<\/h4>\n\n<ul>\n<li>First release: connect, inventory, run check, grade<\/li>\n<\/ul>","raw_excerpt":"Cloud vulnerability checks, login protection, and free encrypted backups to your own Google Drive with one-click rollback.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/mya.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/362788","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/mya.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/mya.wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/mya.wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=362788"}],"author":[{"embeddable":true,"href":"https:\/\/mya.wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/korisec"}],"wp:attachment":[{"href":"https:\/\/mya.wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=362788"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/mya.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=362788"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/mya.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=362788"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/mya.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=362788"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/mya.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=362788"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/mya.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=362788"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}