Getting Started With Aegisify: Connect WordPress, Build the Evidence, and Run Your First Audit
Use this quick-start path to move from a new Aegisify subscription to a connected WordPress site with the Audit Agent, telemetry, Aegisify Core, security evidence, and scan workflows ready to use.
The better the authorized WordPress context, logs, plugin intelligence, and security telemetry you provide, the more useful the audit and AI-assisted analysis can become.
Your Start-to-Finish Aegisify Setup Path
Open each stage for a short explanation. Complete them from left to right before relying on deeper scan results.
Click a stage to expand
01SubscribeCreate and activate the account
02Add DomainCreate the authorized target
03Connect AgentKey + sensors + telemetry
04Install CoreRegister and deploy the suite
05Add EvidenceLogs + plugins + domain checks
06Run & AnalyzeStatic + dynamic + advanced
Subscribe, Add the WordPress Domain, and Connect the Aegisify Audit Agent
The first objective is not to run every scan. It is to establish a trusted connection between the Aegisify SaaS target and the WordPress site you are authorized to manage.
Sign Up for Aegisify Audit
Start at Aegisify Audit subscription. Select the plan that matches your domains and administrators, register or sign in, complete checkout, and activate the account.
Add the Target Domain and Install the Audit Agent
Open Target Domain Settings in SaaS and add the WordPress domain you are authorized to manage. Download the Aegisify Audit Agent, then install and activate it through WordPress Admin → Plugins → Add Plugin → Upload Plugin.
After the Agent is active, expand the target’s Agent details in SaaS and generate or copy the Encryption / Security Key. In WordPress, open Aegisify Audit Agent, paste the key, select Save Encryption Key, and return to SaaS to connect and verify the Agent.
Enable WordPress Activity Sensors and Telemetry Access
In WordPress, go to Aegisify Audit Agent → WordPress Activity Log → Sensor and enable the sensors that are appropriate for the site. Sensors provide activity evidence that can help explain logins, changes, plugin activity, administrative events, and other WordPress behavior.
Next, open Telemetry Access Control. The administrator decides which supported WordPress-side intelligence the SaaS service may access. Select sources that match your operational needs and data-handling policy.
Install Aegisify Core and Register the WordPress Product Suite
Aegisify Core is the WordPress control plane for installing and managing supported Aegisify suite applications.
Download Core From Profile Settings → Licenses
Return to the Aegisify SaaS portal and open Profile Settings → Licenses. Download Aegisify Core, upload the ZIP through the normal WordPress plugin installer, and activate it. After activation, the Aegisify menu becomes the administrative entry point for suite management.
Register or activate Aegisify Core as shown in your current installation, then open Aegisify → Plugins to install or activate the products you want. Complete one action at a time.
Before You Run the Main Scans, Confirm These Four Things
This keeps the first full audit from starting with avoidable evidence gaps.
Choose the Scan That Matches What You Need to Learn
Start with the scan that answers the immediate question, review the findings, and move deeper as needed.
Static Security Scans
Use Static Security Scans for vulnerability review and static code scanning. This is the place to begin when you want software, dependency, code, and WordPress-side security findings without depending only on public application behavior.
Dynamic Security Scans
Use Dynamic Security Scans for a detailed external dynamic assessment of the running website and the attack surface it exposes. This view helps examine behavior that may not be visible from inventory or static code alone.
Advanced Security Scans
Use Advanced Security Scans for the fuller advanced workflow and deeper testing available to the target. Review scope before launching the assessment.
Use AI Intelligence After the Evidence Is Ready
Use AI to organize and explain real site evidence, not to replace scans or administrator judgment.
Once the Agent is connected, telemetry is approved, plugin and theme details are current, useful logs are available, and your scans have produced findings, open AI Intelligence. Aegisify can use the available evidence to consolidate related signals, summarize what deserves attention, explain potential impact, and suggest what to review or do next.
Review AI-assisted recommendations before changing production. Updates, firewall rules, code remediation, configuration changes, and risk acceptance should remain deliberate administrator or security-team decisions.
Common Questions During Initial Aegisify Setup
Can I scan before the Aegisify Audit Agent is connected?
External capabilities can provide a different view of the website, but the full connected WordPress audit workflow depends on the Agent being installed, connected, and verified. The Agent adds authorized internal evidence that an external scan cannot see.
Do I have to enable every telemetry source?
No. Telemetry Access Control is there so the authorized administrator can choose what the SaaS service may access. Enable the sources that provide useful security context and fit your organization’s privacy, security, and compliance requirements.
Do I need Aegisify Core to use the product suite?
Aegisify Core is the central WordPress control plane for installing, activating, deactivating, licensing, and managing supported suite products. Audit itself remains a SaaS platform paired with the WordPress Audit Agent.
Which scan should I run first?
Start with the scan that matches your immediate goal. Static Security Scans are useful for vulnerability and code-focused review, Dynamic Security Scans evaluate the live external application, and Advanced Security Scans are for the deeper advanced workflow. Review the target and scope before moving into more extensive testing.
