
Korisec is a hosted website security service. This plugin is the official WordPress client: it does not run port scans, Nuclei, or other scanners inside WordPress.
After you paste a plugin key from your Korisec account, the plugin:
Without a key, login protection and optional exposure remedies (XML-RPC, public usernames, install.php) still run locally. Those features do not send data to Korisec.
Paid plans, daily scan limits, and white-label PDFs are features of the Korisec service, not locked code inside this plugin. The plugin’s PHP is fully available under GPLv2 or later.
This plugin requires a Korisec account and talks only to https://api.korisec.com (unless you set KORISEC_API_BASE in wp-config.php).
Nothing is sent until a site administrator pastes a kr_live_… key and clicks Connect.
Typical payloads include this site’s URL and host, WordPress and PHP versions, names and versions of installed plugins/themes (and whether they are active), heartbeat, scan start/status requests, and billing/team/alert settings for the Korisec account that issued the key.