Install BoringSec where you already work.
Use the supported WordPress plugin or connect BoringSec to Claude Code, Codex, and Cursor through MCP. Every public install below names its exact requirements and a verification step. Preview channels stay clearly marked until they are ready.
Local security baseline, connected audit, verified-owner deep scans, and privacy-safe monitoring.
Install from WordPress Admin
- 1Download the official versioned ZIP. Do not unzip it.
- 2In WordPress, open Plugins → Add New → Upload Plugin, select the ZIP, then choose Install Now.
- 3Activate BoringSec Security and open BoringSec in the WordPress admin menu. The first local baseline makes no external request.
- 4Select Connect and enrich my report, approve the exact site URL in BoringSec, then return to WordPress.
- 5Review the lightweight report. Verify ownership only when you want to unlock filesystem integrity and the six additional heavy scanners.
Requirements
- WordPress 6.3 or newer
- PHP 7.4 or newer
- HTTPS on the canonical site URL
- Administrator permission to install plugins
Security reviews, fixes, policy bundles, and usage visibility inside Claude Code, Codex, and Cursor.
Install for Claude Code and Cursor
Open a terminal in your project folder, paste all three commands, approve the short browser code, and restart your editor.
npx -y @boringsec/claude-code login
npx -y @boringsec/claude-code init --editor both --scope project --write-rules
npx -y @boringsec/claude-code doctorRequirements
- Node.js 18 or newer
- BoringSec Pro, Business, or Enterprise workspace
- Claude Code, Codex, or Cursor with MCP support
Embedded storefront security audit and badge.
The app is in controlled development-store testing and is not yet a public Shopify App Store install. There is no supported sideload link.
After store approval, installation will start from the Shopify App Store, show the requested scopes, and open BoringSec inside Shopify Admin. This page will gain the official install button only after that channel is live.
Native diagnostics and scan history in VS Code.
Marketplace distribution remains on hold, so BoringSec does not publish an unofficial VSIX or ask users to bypass extension signing.
Cursor users can install the supported MCP package above today. VS Code users can use the REST API while the signed Marketplace release completes review.
View API integration optionsInstall only from the official links on this page. Public version numbers are pinned deliberately; local development builds and held distribution channels are not advertised as released products.