Skip to content
Official downloadsChecksums and versioned releases

Install BoringSec where you already work.

Use the supported WordPress plugin or connect BoringSec to Claude Code, Codex, and Cursor through MCP. Every public install below names its exact requirements and a verification step. Preview channels stay clearly marked until they are ready.

BoringSec Security for WordPress

Local security baseline, connected audit, verified-owner deep scans, and privacy-safe monitoring.

Availablev1.3.0

Install from WordPress Admin

  1. 1Download the official versioned ZIP. Do not unzip it.
  2. 2In WordPress, open Plugins → Add New → Upload Plugin, select the ZIP, then choose Install Now.
  3. 3Activate BoringSec Security and open BoringSec in the WordPress admin menu. The first local baseline makes no external request.
  4. 4Select Connect and enrich my report, approve the exact site URL in BoringSec, then return to WordPress.
  5. 5Review the lightweight report. Verify ownership only when you want to unlock filesystem integrity and the six additional heavy scanners.

Requirements

  • WordPress 6.3 or newer
  • PHP 7.4 or newer
  • HTTPS on the canonical site URL
  • Administrator permission to install plugins
The ZIP is versioned and published on this domain. Connected update checks verify the declared byte size and SHA-256 checksum before installation; automatic installation stays under WordPress administrator control.
BoringSec MCP

Security reviews, fixes, policy bundles, and usage visibility inside Claude Code, Codex, and Cursor.

Available on npmlatest 0.4.5

Install for Claude Code and Cursor

Open a terminal in your project folder, paste all three commands, approve the short browser code, and restart your editor.

terminal
npx -y @boringsec/claude-code login
npx -y @boringsec/claude-code init --editor both --scope project --write-rules
npx -y @boringsec/claude-code doctor

Requirements

  • Node.js 18 or newer
  • BoringSec Pro, Business, or Enterprise workspace
  • Claude Code, Codex, or Cursor with MCP support
Device login avoids copying a raw API key. Codex uses the manual TOML setup shown in the full guide until a compatible public initializer is released.
Shopify app

Embedded storefront security audit and badge.

Private test

The app is in controlled development-store testing and is not yet a public Shopify App Store install. There is no supported sideload link.

After store approval, installation will start from the Shopify App Store, show the requested scopes, and open BoringSec inside Shopify Admin. This page will gain the official install button only after that channel is live.

VS Code extension

Native diagnostics and scan history in VS Code.

Private preview

Marketplace distribution remains on hold, so BoringSec does not publish an unofficial VSIX or ask users to bypass extension signing.

Cursor users can install the supported MCP package above today. VS Code users can use the REST API while the signed Marketplace release completes review.

View API integration options

Install only from the official links on this page. Public version numbers are pinned deliberately; local development builds and held distribution channels are not advertised as released products.