KoraScan documentation and user guide
Everything you need to install, configure, and manage KoraScan across your WordPress sites without slowing them down.
1. Quick start: get protected in 3 steps
You don’t need to spend hours tweaking settings to secure a site. KoraScan activates sensible security defaults the moment you turn it on.
Step 1: Install & Authorize
Upload the plugin and click Kora Scan in your sidebar to launch the Setup Wizard. Click Authenticate & Connect to log into your KoraScan Cloud account (or create a free one). This will authorize your site and activate your dashboard.
Step 2: Configure Protections
After logging in, you will be redirected back to the wizard. Simply click Continue through the remaining steps to instantly enable Site Hardening, 2FA, and your Active Defense engines.
Step 3: Activate Security
On the final step, click Activate Security Engine. Your dashboard is now live, and your first background malware scan will begin automatically.
2. Core security modules explained
3. Feature walkthrough & dashboard guide
KoraScan organizes all security tools into a clean, modern, tab-based interface.
4. SaaS cloud hub for agencies and multi-site owners
- 1. AI-Powered Vulnerability Remediation & Patch Pipeline (Gemini AI): Automatically analyzes newly discovered WordPress theme/plugin vulnerabilities and deploys instant virtual WAF patch rules across your connected sites.
- 2. Global Threat Intelligence & CVE Feed Synchronization: Continuously polls and synchronizes global CVE feeds and IP reputation blacklists across all connected client sites in real time.
- 3. Remote Fleet Command & Control: Execute remote scans, push firewall rules, enforce 2FA policies, or quarantine suspicious files across any managed WordPress site from one central dashboard tab.
- 4. Portfolio-Wide Exposure Map & Executive Reports: Interactive cross-site threat heatmaps, attack vector breakdowns, and downloadable white-label PDF security reports for agency clients.
- 5. Multi-Channel Alert Dispatcher: Custom real-time alert routing to Slack, Discord, Email, and Webhook endpoints with severity filtering and threshold rules.
- 6. Agency White-Labeling & Client Portals: Fully rebrandable dashboard and reports. Present KoraScan as your own proprietary security product with custom logos, colors, and client-facing portals.
SaaS entitlement tiers & community free plan
When you first connect your WordPress site to the KoraScan SaaS Cloud Hub, an account is automatically created on the Community Plan (Free). This community entitlement unlocks basic cloud visibility, site health sync, and dashboard onboarding.
To unlock advanced multi-site management, real-time WAF rule synchronization, automated email/Slack alerts, and unlimited agency fleet controls, KoraScan offers three professional tiers:
- Starter: Essential cloud protection and automated monitoring for small sites and freelancers.
- Business: Advanced real-time threat protection, automated reporting, and multi-site management.
- Agency: Complete white-label branding, client reporting portals, and unlimited fleet control.
Tip: To compare feature quotas or upgrade your subscription tier, visit the official KoraScan Plans & Pricing page.