Enter your website
Type your shop or business URL. We run automated checks in a few minutes. No plugin is required for a free public check. WordPress shops can install the Korisec plugin to include plugins that are not visible from the internet.
Free quick check · No signup required
Built for WordPress and WooCommerce shops. Korisec finds what's risky on your site, explains it in plain English, and alerts you on email and Telegram when something critical shows up.
Quick check covers HTTPS, browser protections & blacklists. Full trial unlocks all 13 checks — no card required.
Trusted by small businesses running WordPress shops, WooCommerce stores, and agency client sites.
How it works
Type your shop or business URL. We run automated checks in a few minutes. No plugin is required for a free public check. WordPress shops can install the Korisec plugin to include plugins that are not visible from the internet.
See a simple A–F grade and security score. Every issue comes with a plain-English explanation.
Each finding has the problem, the risk, and step-by-step fixes. Trial includes email and Telegram alerts after you verify the site; paid plans add weekly automatic scans and more channels.
Built for your shop
The checks shops and agencies actually need — delivered where owners already look.
Plugins, themes, login hardening, XML-RPC, user leaks, and shop API exposure — translated into plain-English fixes. The WordPress plugin also makes free encrypted Google Drive backups, with one-click restore.
Critical findings go to email and Telegram. Paid plans also support WhatsApp alerts.
White-label PDF reports, credential breach checks, and brand lookalike monitoring for the sites you manage.
What we check
Enterprise scanners run these same tests. We translate the results so anyone can act on them.
Finds live subdomains and scans them for the same security checks.
Is your padlock working and is the certificate still valid?
Extra safety settings browsers expect from modern sites.
Stops others from sending fake email that looks like yours.
Checks whether your site or IP is flagged as unsafe.
Finds WordPress/CMS clues and dangerous public files.
Plugins, themes, login/XML-RPC hardening, user leaks, and shop API exposure.
Looks for database and admin ports left open to the internet.
DNS settings that stop certificate abuse and takeovers.
Makes sure login cookies cannot be stolen easily.
Flags when emails on your domain show up in public data breaches (Agency).
Finds typosquat domains that could phish your customers (Agency).
Looks for common misconfigurations and publicly exposed files.
Sample finding
Your WordPress site still accepts XML-RPC requests, a common target for password-guessing and amplification attacks.
Attackers can hammer login attempts or abuse the endpoint without touching your normal admin screen — locking out staff or slowing the shop.
Disable XML-RPC in your security plugin or server config unless a specific integration needs it. Most shops can turn it off in under 15 minutes.
Pricing
One website, weekly peace of mind
KES 3,800 /mo
≈ $29 USD
KES 36,480 /yr
≈ $278 USD
KES 3,040/mo billed yearly
Best for growing shops
KES 10,300 /mo
≈ $79 USD
KES 98,880 /yr
≈ $758 USD
KES 8,240/mo billed yearly
For freelancers & agencies
KES 25,900 /mo
≈ $199 USD
KES 248,640 /yr
≈ $1,910 USD
KES 20,720/mo billed yearly
From the blog
Learn about CVE-2026-85102, an improper certificate validation vulnerability affecting Check Point Security Gateway…
Learn about CVE-2026-87886, a high-severity incorrect default permissions vulnerability in Acronis Backup for cPanel…
Learn about CVE-2025-39682 in the Linux Kernel TLS receive path. Understand the risks for end-of-life systems and how…