Really Simple Security – Simple and Performant Security (formerly Really Simple SSL)
Easily improve site security with WordPress Hardening, Two-Factor Authentication (2FA), Login Protection, Vulnerability Detection and SSL certificate. Really simple, Effective and Performant WordPress Security Really Simple Security is the most lightweight and easy-to-use security plugin for WordPress. It secures your WordPress website with SSL certificate generation, including proper 301 https redirection and SSL enforcement, scanning for possible vulnerabilities, Login Protection and implementing essential WordPress hardening features. We believe that security should have the absolute minimum effect on website performance, user experience and maintainability. Therefore, Really Simple Security is: Lightweight: Every security feature is developed with a modular approach and with performance in mind. Disabled features won’t load any redundant code. Easy-to-use: 1-minute configuration with short onboarding setup. Security Features Easy SSL Migration Migrates your website to HTTPS and enforces SSL in just one click. 301 redirect via PHP or .htaccess Secure cookies Let’s Encrypt: Install an SSL Certificate if your hosting provider supports manual installation. Server Health Check: Your server configuration is every bit as important for your website security. WordPress Hardening Tweak your configuration and keep WordPress fortified and safe by tackling potential weaknesses. Prevent code execution in the uploads folder Prevent login feedback and disable user enumeration Disable XML-RPC Disable directory browsing Username restrictions (block ‘admin’ and public names) and much more.. Vulnerability Detection Get notified when plugins, themes or WP core contain vulnerabilities and need appropriate action. Login Protection Allow or enforce Two-Factor Authentication (2FA) for specific user roles. Users receive a two-factor code via Email. Improve Security with Really Simple Security Pro Protect your site with all essential security features by upgrading to Really Simple Security Pro. Advanced SSL enforcement Mixed Content Scan & Fixer. Detect files that are requested over HTTP and fix them to HTTPS, both Front- and Back-end. Enable HTTP Strict Transport Security and configure your site for the HSTS Preload list. Firewall Really Simple Security Pro includes a performant and efficient WordPress firewall, to stop bots, crawlers and bad actors with IP and username blocks. 404 blocking – Blocks crawlers as they trigger unusual numbers of 404 errors. Region blocking – Only allow/block access to your site from specific regions. Automated and customisable Firewall rules. IP blocklist and allowlist. Security Headers Security headers protect your site visitors against the risk of clickjacking, cross-site-forgery attacks, stealing login credentials and malware. Independent of your Server Configuration, works on Apache, LiteSpeed, NGINX, etc. Protect your website visitors with X-XSS Protection, X-Content-Type-Options, X-Frame-Options, a Referrer Policy and CORS headers. Automatically generate your WordPress-tailored Content Security Policy. Vulnerability Measures When a vulnerability is detected in a plugin, theme or WordPress core you will get notified accordingly. With Vulnerability Measures, you can configure simple but effective measures to make sure that a critical vulnerability won’t remain unattended. Force update: An update process will be tried multiple times until it can be assumed development of a theme or plugin is abandoned. You will be notified during these steps. Quarantine: When a plugin or theme can’t be updated to solve a vulnerability, Really Simple Security can quarantine the plugin. Advanced Site Hardening Choose a custom login URL Automated File Permissions check and fixer Rename and randomize your database prefix Change the debug.log file location to a non-public folder Disable application passwords Control admin creation Disable HTTP methods, reducing HTTP requests Login Protection Secure your website’s login process and user accounts with powerful security measures. Two-Step verification (Email login) 2FA (two factor authentication) with TOTP Passwordless login with passkey login Enforce strong passwords and frequent password change Limit Login Attempts With Limit Login Attempts you can configure a threshold to temporarily or permanently block IP addresses or (non-existing) usernames. You can also throw a CAPTCHA after a failed login (hCaptcha or Google reCaptcha) Access Control Restrict access to your site for specific regions. Add specific IP addresses or IP ranges to the Blocklist or Allowlist. Useful Links Documentation Security Definitions Translate Really Simple Security Issues & pull requests Feature requests Love Really Simple Security? If you want to support the continuing development of this plugin, please consider buying Really Simple Security Pro, which includes some excellent security features and premium support. About Really Simple Plugins Our mission is to make complex WordPress requirements really easy. Really Simple Security is developed by Really Simple Plugins. For generating SSL certificates, Really Simple Security uses the le acme2 PHP Let’s Encrypt client library, thanks to ‘fbett’ for providing it. Vulnerability Detection uses WP Vulnerability, an open-source initiative by Javier Casares. Want to join as a collaborator? We’re on GitHub as well!
Top keywords
- security27×3.54%
- really15×1.97%
- simple15×1.97%
- login14×1.84%
- really simple14×1.84%
- really simple security11×1.44%
- simple security11×1.44%
- wordpress10×1.31%
- vulnerability9×1.18%
- ssl8×1.05%
- site7×0.92%
- website6×0.79%
Registration
Registration Email Blocker decides which email domains are acceptable on your site. Run it as a blocklist to refuse the providers you name, or as an allowlist to accept only the ones you approve. The check is applied everywhere an address can be set, not only on the registration form: the WordPress registration form the profile screen and “Add New User” in wp-admin the WordPress REST API WooCommerce registration the WooCommerce checkout, both the classic shortcode and the newer block based checkout the “Account details” page of the WooCommerce My Account area Checking email changes matters as much as checking registration. If only the registration form is guarded, an account can be created with an accepted address and switched to any other one a minute later. That option is on by default and can be turned off. What it does Two modes. Blocklist refuses the domains you list; allowlist accepts only the domains you list. Subdomains are matched in both directions, so listing example.com also covers mail.example.com. Two levels of strictness. Refuse the address outright, or allow it and record the attempt. Internationalized domains. Names such as почта.рф are converted to their punycode form when saved, so they match real addresses. Entries that are not valid domain names are reported back to you rather than silently dropped. Administrators are exempt by default, so a mistake in a domain list cannot lock you out of your own site. Report on existing accounts. See which accounts use a rejected domain, grouped by domain, and export the list as CSV. Batched notifications. Ask affected users to change their address. Mail is sent in small batches with a progress bar and a stop button, and anyone notified recently is skipped, so a timeout cannot restart the run from the beginning. A log you can live with. Attempts are recorded with a configurable level of detail, kept only as long as you choose, and trimmed automatically once a day. Repeated attempts from the same IP address within a minute are recorded once, so a bot cycling through addresses cannot inflate the table. Editable defaults. Both domain lists ship pre-filled and can be changed freely; a button restores them to the versions shipped with the plugin whenever you want the newest entries. Privacy The plugin stores registration attempts in a table in your own database. Nothing is sent anywhere else, and no external service is contacted. You decide how much is kept: email addresses in full, partially masked, reduced to the domain, or not stored at all IP addresses in full, anonymized, or not stored at all a retention period after which entries are deleted automatically The plugin registers a personal data exporter and eraser, so log entries are included in the export and erasure requests WordPress produces under Tools → Export/Erase Personal Data, and it suggests text for your privacy policy. The connection address is used by default; forwarded headers such as X-Forwarded-For are trusted only if you state that the site is behind a reverse proxy, because a visitor can otherwise put any value there. A note on what a blocklist can do A blocklist only refuses the domains you thought of. Somebody who wants an account will find a provider that is not on the list. When the set of acceptable providers is actually known, the allowlist is the mode that holds. The plugin is a technical control over email domains. It does not by itself make a site compliant with any particular legislation, and the site owner remains responsible for their own legal obligations. Russian Federal Law 406-FZ The plugin was originally written for Russian site owners working towards Federal Law No. 406-FZ, which requires authorization through a phone number, ESIA, a biometric system or another Russian-controlled system. This plugin implements none of those. It only controls the email domain used at registration, which the law does not address directly. Treat it as one piece of housekeeping, not as a compliance solution, and take legal advice about your own obligations. Support Questions and bug reports are welcome on the plugin’s support forum on WordPress.org. Developer: Studio Playner — https://profiles.wordpress.org/altcreative/ Support Development This plugin is free and will stay free. If it saves you time, you can support its development through YooKassa. Contributions go towards new features, compatibility with new WordPress and WooCommerce releases, and answering support questions. License This plugin is licensed under the GPL v2 or later. Copyright (C) 2026 Studio Playner This program is free software: you can redistribute it and/or modify it under the terms of the GNU General Public License as published by the Free Software Foundation, either version 2 of the License, or (at your option) any later version.