Aegisify company logo
Getting Started with Aegisify QuickStart2026-08-08T19:00:11+00:00

Aegisify Audit Quick Start

Getting Started With Aegisify: Connect WordPress, Build the Evidence, and Run Your First Audit

Use this quick-start path to move from a new Aegisify subscription to a connected WordPress site with the Audit Agent, telemetry, Aegisify Core, security evidence, and scan workflows ready to use.

Start simple: connect first, collect evidence second, scan third.
The better the authorized WordPress context, logs, plugin intelligence, and security telemetry you provide, the more useful the audit and AI-assisted analysis can become.

1ConnectAccount + domain + Agent
2EnrichTelemetry + logs + plugins
3AnalyzeScans + AI intelligence

Interactive Setup Map

Your Start-to-Finish Aegisify Setup Path

Open each stage for a short explanation. Complete them from left to right before relying on deeper scan results.

Click a stage to expand

01SubscribeCreate and activate the account
Choose the Aegisify Audit plan that matches your target-domain and user requirements, complete registration, and activate the account.
02Add DomainCreate the authorized target
Add the WordPress domain you are authorized to manage, download the Audit Agent, install it in WordPress, and prepare the connection.
03Connect AgentKey + sensors + telemetry
Generate the security key in SaaS, save it in the Agent, connect the target, then enable the activity sensors and telemetry you approve.
04Install CoreRegister and deploy the suite
Download Aegisify Core from your license area, install it in WordPress, register the Core application, and install the suite products you want to use.
05Add EvidenceLogs + plugins + domain checks
Enable useful WordPress logging, add Aegisify Shield/WAF logs when installed, fetch plugin and theme intelligence, and review basic domain blocklist checks.
06Run & AnalyzeStatic + dynamic + advanced
Run the scan type that matches your task, then use AI Intelligence after the environment has enough authorized evidence to summarize priorities and next steps.
Phase 1 — Account and Connection

Subscribe, Add the WordPress Domain, and Connect the Aegisify Audit Agent

The first objective is not to run every scan. It is to establish a trusted connection between the Aegisify SaaS target and the WordPress site you are authorized to manage.

01

Sign Up for Aegisify Audit

Start at Aegisify Audit subscription. Select the plan that matches your domains and administrators, register or sign in, complete checkout, and activate the account.

02

Add the Target Domain and Install the Audit Agent

Open Target Domain Settings in SaaS and add the WordPress domain you are authorized to manage. Download the Aegisify Audit Agent, then install and activate it through WordPress Admin → Plugins → Add Plugin → Upload Plugin.

After the Agent is active, expand the target’s Agent details in SaaS and generate or copy the Encryption / Security Key. In WordPress, open Aegisify Audit Agent, paste the key, select Save Encryption Key, and return to SaaS to connect and verify the Agent.

Connection checkpoint: deeper Agent-assisted scanning depends on the Agent being installed, connected, and verified against the correct target domain.

03

Enable WordPress Activity Sensors and Telemetry Access

In WordPress, go to Aegisify Audit Agent → WordPress Activity Log → Sensor and enable the sensors that are appropriate for the site. Sensors provide activity evidence that can help explain logins, changes, plugin activity, administrative events, and other WordPress behavior.

Next, open Telemetry Access Control. The administrator decides which supported WordPress-side intelligence the SaaS service may access. Select sources that match your operational needs and data-handling policy.

Privacy and compliance note: optional logs and telemetry can contain sensitive technical or application values. Aegisify’s published privacy guidance keeps telemetry customer-controlled and focuses the audit on security-relevant evidence. For regulated environments involving PII, PHI, PCI, CUI, or similar data, approve only the sources you need and validate your organization’s current redaction, retention, and handling requirements rather than treating telemetry as an automatic compliance guarantee.

Phase 2 — Aegisify Core

Install Aegisify Core and Register the WordPress Product Suite

Aegisify Core is the WordPress control plane for installing and managing supported Aegisify suite applications.

04

Download Core From Profile Settings → Licenses

Return to the Aegisify SaaS portal and open Profile Settings → Licenses. Download Aegisify Core, upload the ZIP through the normal WordPress plugin installer, and activate it. After activation, the Aegisify menu becomes the administrative entry point for suite management.

Register or activate Aegisify Core as shown in your current installation, then open Aegisify → Plugins to install or activate the products you want. Complete one action at a time.

Core installation guideFollow the Aegisify Core User Guide for the current installation workflow.
Product documentationUse the Aegisify WordPress Product Suite guides for product-specific setup and administration.

Phase 3 — Build Useful Evidence

Work Through the Aegisify Audit Left Menu Before Running the Deepest Scans

The platform becomes more useful when logs, sensors, software inventory, defensive-tool evidence, and domain intelligence are available first.

01 — WordPress Logs

Start With WordPress Logs

Read the instructions before enabling production debugging. The WordPress debugging guide explains how to write errors to debug.log without displaying them publicly. Do not leave debugging enabled unnecessarily on production.

Then follow the WordPress Sensors & Telemetry guide to enable the activity sensors you want and allow the SaaS application to fetch the approved evidence.

02 — Aegisify Logs

Add Shield and WAF Evidence

If Aegisify Shield and Aegisify WAF are installed, use the Add Aegisify Logs button in the upper-right area of the logs workflow. Aegisify can then add the supported log sources automatically so Audit has more security context to correlate with scan findings.

03 — Application Plugins

Fetch Plugin & Theme Details

Open Application Plugins and select Fetch Plugin & Theme Details. This gives the audit fresher software inventory and version context for installed plugins and themes instead of relying only on what an external scanner can observe.

04 — Domain Intelligence

Review Dark Web & Domain BL

Use Dark Web & Domain BL as a basic external reputation and blocklist check. It can surface public signals that the domain or website may be blocked or listed, but it does not replace deeper Audit scans.

Recommended Checkpoint

Before You Run the Main Scans, Confirm These Four Things

This keeps the first full audit from starting with avoidable evidence gaps.

Agent ConnectedThe correct SaaS target and WordPress Agent show a successful connection.
Telemetry ApprovedSensors and telemetry permissions match what the administrator intentionally authorized.
Inventory FetchedPlugin and theme details have been refreshed for the target site.
Useful Logs AddedWordPress, Shield, and WAF evidence is available when those sources are relevant and approved.

Phase 4 — Run Security Scans

Choose the Scan That Matches What You Need to Learn

Start with the scan that answers the immediate question, review the findings, and move deeper as needed.

Scan 01

Static Security Scans

Use Static Security Scans for vulnerability review and static code scanning. This is the place to begin when you want software, dependency, code, and WordPress-side security findings without depending only on public application behavior.

Scan 02

Dynamic Security Scans

Use Dynamic Security Scans for a detailed external dynamic assessment of the running website and the attack surface it exposes. This view helps examine behavior that may not be visible from inventory or static code alone.

Scan 03

Advanced Security Scans

Use Advanced Security Scans for the fuller advanced workflow and deeper testing available to the target. Review scope before launching the assessment.

Phase 5 — AI Intelligence

Use AI Intelligence After the Evidence Is Ready

Use AI to organize and explain real site evidence, not to replace scans or administrator judgment.

Once the Agent is connected, telemetry is approved, plugin and theme details are current, useful logs are available, and your scans have produced findings, open AI Intelligence. Aegisify can use the available evidence to consolidate related signals, summarize what deserves attention, explain potential impact, and suggest what to review or do next.

Review AI-assisted recommendations before changing production. Updates, firewall rules, code remediation, configuration changes, and risk acceptance should remain deliberate administrator or security-team decisions.

Best practice: collect → scan → analyze → remediate → retest. AI Intelligence is strongest when it sits on top of current evidence instead of trying to replace it.

Quick Start FAQ

Common Questions During Initial Aegisify Setup

Can I scan before the Aegisify Audit Agent is connected?

External capabilities can provide a different view of the website, but the full connected WordPress audit workflow depends on the Agent being installed, connected, and verified. The Agent adds authorized internal evidence that an external scan cannot see.

Do I have to enable every telemetry source?

No. Telemetry Access Control is there so the authorized administrator can choose what the SaaS service may access. Enable the sources that provide useful security context and fit your organization’s privacy, security, and compliance requirements.

Do I need Aegisify Core to use the product suite?

Aegisify Core is the central WordPress control plane for installing, activating, deactivating, licensing, and managing supported suite products. Audit itself remains a SaaS platform paired with the WordPress Audit Agent.

Which scan should I run first?

Start with the scan that matches your immediate goal. Static Security Scans are useful for vulnerability and code-focused review, Dynamic Security Scans evaluate the live external application, and Advanced Security Scans are for the deeper advanced workflow. Review the target and scope before moving into more extensive testing.

Ready to Start?

Connect the Site First. Build the Evidence. Then Let the Audit Work.

Aegisify becomes more useful as the authorized WordPress context becomes clearer. Follow the sequence, verify each checkpoint, and expand scanning only after the foundation is ready.