Perfbase
Perfbase profiles WordPress applications and sends performance traces to the Perfbase APM platform. It captures request lifecycle timing, WordPress context, selected metadata, and trace data through the native Perfbase PHP extension and the shared Perfbase PHP SDK. This plugin is a Software-as-a-Service integration. It requires a Perfbase account, a Perfbase API key, and the native ext-perfbase PHP extension. The plugin does not submit traces until profiling is enabled and an API key is configured. The plugin can profile: Standard HTTP requests. Admin requests when enabled. AJAX requests. WordPress cron runs. WP-CLI commands when enabled. WordPress, theme, plugin, REST, and WooCommerce context when available. For privacy and cardinality control, request URLs are stored without query strings. Important WordPress query parameters are stored separately where useful. External Services This plugin connects to the Perfbase APM platform, an external application performance monitoring service, when profiling is enabled. Service name: Perfbase APM platform and the configured Perfbase ingest API endpoint. The default endpoint is https://ingress.perfbase.cloud. Service policies: Perfbase Privacy Policy and Perfbase Terms. When data is sent: trace data is sent only after a Perfbase API key is configured, profiling is enabled, the request passes the configured sampling rate, include/exclude filters, user-agent exclusions, request-type toggles, and HTTP status-code rules. For HTTP, AJAX, cron, and WP-CLI lifecycles, submission normally happens at the end of the lifecycle or during shutdown. The plugin does not submit profiling traces while profiling is disabled or while no API key is configured. Perfbase can send: Native trace payloads: function call trees, function names, source file paths and line numbers, timing, CPU, memory, host resource metrics, call context, and runtime error or exception context. System/resource data: host operating system, kernel, hostname, CPU architecture, CPU details, disk capacity details, memory usage, CPU usage, disk I/O, and network I/O samples. Process-list tracking when enabled: capped process snapshots with process ID, executable basename, OS user, CPU usage, memory usage, and process runtime. Command-line arguments are not included in process snapshots. Additional native trace metadata: normalized SQL query text and query type, database DSN/host/database/username/port metadata, MongoDB or Elasticsearch query/filter payload summaries, Redis or Memcached keys and fields, HTTP URL or URI metadata that may include query strings depending on the PHP API or HTTP library used, HTTP method/status/timing/byte-count metadata, file paths and file operation metadata, mail recipient and subject metadata, shell/process command strings, AWS operation names, OPcache and JIT statistics, PHP error or exception samples, compiled file paths, magic method counts, and truncated function argument values if argument capture is separately configured. WordPress request metadata: action name, HTTP method, request URL without query string, HTTP status code, user IP address, user agent, logged-in user ID when available, hostname, environment, application version, PHP version, WordPress version, and Perfbase plugin version. WordPress context metadata: AJAX action, REST route, admin page, post/page identifiers, post type/status, taxonomy context, template and theme information, conditional page type flags, plugin lifecycle context, and WooCommerce page, cart, product, or order context when available. Operational summaries: memory usage, database query count and timing summaries when available, and sanitized outbound HTTP request metadata when HTTP tracking is enabled. Perfbase does not collect: Source code. Request bodies, full POST payloads ($_POST), arbitrary form fields, or uploaded file contents. Cookie values ($_COOKIE) or PHP session data ($_SESSION). Authorization header values. Passwords, API keys, nonces, or session IDs from WordPress request, cookie, or session data. Command-line arguments for process-list snapshots. Feature flags control the extra native trace metadata listed under “Perfbase can send”, including outbound HTTP URLs or URIs with query strings for some HTTP libraries and truncated function argument values if argument capture is separately configured. Administrators should review enabled Perfbase extension feature flags before profiling sensitive workloads. Extension installer and CDN: the plugin runtime does not call cdn.perfbase.com. The optional extension installer and manual extension binary downloads use https://cdn.perfbase.com only when a server administrator downloads or runs those installation assets. Privacy This plugin connects to Perfbase’s external service when profiling is enabled. It sends profiling trace data and request metadata to the configured Perfbase API endpoint. Data submission requires explicit configuration of a Perfbase API key and the Enable Profiling setting. The plugin does not submit traces while profiling is disabled or while no API key is configured. Administrators should review their site’s privacy policy and disclose their use of Perfbase where appropriate.
Top keywords
- perfbase24×3.23%
- http12×1.62%
- metadata12×1.62%
- api10×1.35%
- profiling10×1.35%
- configured9×1.21%
- enabled9×1.21%
- query9×1.21%
- request9×1.21%
- wordpress9×1.21%
- context8×1.08%
- data8×1.08%
Really Simple Security – Simple and Performant Security (formerly Really Simple SSL)
Easily improve site security with WordPress Hardening, Two-Factor Authentication (2FA), Login Protection, Vulnerability Detection and SSL certificate. Really simple, Effective and Performant WordPress Security Really Simple Security is the most lightweight and easy-to-use security plugin for WordPress. It secures your WordPress website with SSL certificate generation, including proper 301 https redirection and SSL enforcement, scanning for possible vulnerabilities, Login Protection and implementing essential WordPress hardening features. We believe that security should have the absolute minimum effect on website performance, user experience and maintainability. Therefore, Really Simple Security is: Lightweight: Every security feature is developed with a modular approach and with performance in mind. Disabled features won’t load any redundant code. Easy-to-use: 1-minute configuration with short onboarding setup. Security Features Easy SSL Migration Migrates your website to HTTPS and enforces SSL in just one click. 301 redirect via PHP or .htaccess Secure cookies Let’s Encrypt: Install an SSL Certificate if your hosting provider supports manual installation. Server Health Check: Your server configuration is every bit as important for your website security. WordPress Hardening Tweak your configuration and keep WordPress fortified and safe by tackling potential weaknesses. Prevent code execution in the uploads folder Prevent login feedback and disable user enumeration Disable XML-RPC Disable directory browsing Username restrictions (block ‘admin’ and public names) and much more.. Vulnerability Detection Get notified when plugins, themes or WP core contain vulnerabilities and need appropriate action. Login Protection Allow or enforce Two-Factor Authentication (2FA) for specific user roles. Users receive a two-factor code via Email. Improve Security with Really Simple Security Pro Protect your site with all essential security features by upgrading to Really Simple Security Pro. Advanced SSL enforcement Mixed Content Scan & Fixer. Detect files that are requested over HTTP and fix them to HTTPS, both Front- and Back-end. Enable HTTP Strict Transport Security and configure your site for the HSTS Preload list. Firewall Really Simple Security Pro includes a performant and efficient WordPress firewall, to stop bots, crawlers and bad actors with IP and username blocks. 404 blocking – Blocks crawlers as they trigger unusual numbers of 404 errors. Region blocking – Only allow/block access to your site from specific regions. Automated and customisable Firewall rules. IP blocklist and allowlist. Security Headers Security headers protect your site visitors against the risk of clickjacking, cross-site-forgery attacks, stealing login credentials and malware. Independent of your Server Configuration, works on Apache, LiteSpeed, NGINX, etc. Protect your website visitors with X-XSS Protection, X-Content-Type-Options, X-Frame-Options, a Referrer Policy and CORS headers. Automatically generate your WordPress-tailored Content Security Policy. Vulnerability Measures When a vulnerability is detected in a plugin, theme or WordPress core you will get notified accordingly. With Vulnerability Measures, you can configure simple but effective measures to make sure that a critical vulnerability won’t remain unattended. Force update: An update process will be tried multiple times until it can be assumed development of a theme or plugin is abandoned. You will be notified during these steps. Quarantine: When a plugin or theme can’t be updated to solve a vulnerability, Really Simple Security can quarantine the plugin. Advanced Site Hardening Choose a custom login URL Automated File Permissions check and fixer Rename and randomize your database prefix Change the debug.log file location to a non-public folder Disable application passwords Control admin creation Disable HTTP methods, reducing HTTP requests Login Protection Secure your website’s login process and user accounts with powerful security measures. Two-Step verification (Email login) 2FA (two factor authentication) with TOTP Passwordless login with passkey login Enforce strong passwords and frequent password change Limit Login Attempts With Limit Login Attempts you can configure a threshold to temporarily or permanently block IP addresses or (non-existing) usernames. You can also throw a CAPTCHA after a failed login (hCaptcha or Google reCaptcha) Access Control Restrict access to your site for specific regions. Add specific IP addresses or IP ranges to the Blocklist or Allowlist. Useful Links Documentation Security Definitions Translate Really Simple Security Issues & pull requests Feature requests Love Really Simple Security? If you want to support the continuing development of this plugin, please consider buying Really Simple Security Pro, which includes some excellent security features and premium support. About Really Simple Plugins Our mission is to make complex WordPress requirements really easy. Really Simple Security is developed by Really Simple Plugins. For generating SSL certificates, Really Simple Security uses the le acme2 PHP Let’s Encrypt client library, thanks to ‘fbett’ for providing it. Vulnerability Detection uses WP Vulnerability, an open-source initiative by Javier Casares. Want to join as a collaborator? We’re on GitHub as well!