| 开发者 | korisec |
|---|---|
| 更新时间 | 2026年10月7日 03:05 |
| PHP版本: | 7.4 及以上 |
| WordPress版本: | 7.1 |
| 版权: | GPLv2 or later |
| 版权网址: | 版权信息 |
wp-content (plugins, themes, uploads) plus wp-config.phphttps://api.korisec.com (unless you set KORISEC_API_BASE in wp-config.php).
kr_live_… key and clicks Connect.
Data sent after Connect
Typical payloads include this site’s URL and host, WordPress and PHP versions, names and versions of installed plugins/themes (and whether they are active), heartbeat, scan start/status requests, and billing/team/alert settings for the Korisec account that issued the key.
Google Drive backups
Nothing is contacted until an administrator clicks Connect Google Drive on the Backups tab.
https://www.googleapis.com, https://oauth2.googleapis.com) stores the encrypted backup files in a “Korisec Backups” folder in your own Drive. The plugin asks only for the drive.file permission, so it can see only the files it created. Google’s terms: https://policies.google.com/terms and privacy policy: https://policies.google.com/privacyhttps://api.korisec.com, the same service that runs Korisec’s own Sign in with Google) completes the Google sign-in and renews short-lived Google access tokens, because Google requires a client secret that cannot ship inside a plugin. The relay receives this site’s admin URL, a one-time public key, and (on each renewal) the Google refresh token. It returns the tokens encrypted to this site and stores nothing. It never receives backup contents or your encryption key.wp-config.php, and can be downloaded as a recovery key.
No. Checks run on Korisec workers. The plugin only reports inventory and displays results.
The key authenticates this site to the Korisec API. It is not a license gate for local scanner code. Without a key the plugin does not contact Korisec.
The hosted service pauses cloud checks until the account is renewed. The plugin itself remains installed and GPLv2 licensed.
Disconnect on the Connection tab, or delete the plugin. Deleting removes the stored key from WordPress. Korisec account history is managed in the Korisec dashboard.
Yes. Backups to your own Google Drive are free on any site and do not need a Korisec account or key. Storage comes from your Google Drive quota.
No. The database and files are encrypted on your server before upload. Only someone with this site’s key (or your downloaded recovery key) can decrypt them.
Before every restore Korisec takes and verifies a safety backup of the current site. The restore swaps tables and folders in one step. You can then undo it with one click, or keep it once you have checked the site.
Install WordPress and Korisec on the new server, connect the same Google Drive, then import your recovery key on the Backups tab. Your backups appear and can be restored.
wp-config.php is included in every backup but is not overwritten on restore, so database credentials for a new host are kept. WordPress core files are not backed up; reinstall core from WordPress.org. Multisite networks are not supported yet.
Backups stay in your Google Drive. The encryption key is kept in the database so a reinstall can still read them. Download the recovery key before moving or wiping the site.
Yes. In wp-config.php set define( 'KORISEC_API_BASE', 'https://your-host.example' );