Really Simple Security – Simple and Performant Security (formerly Really Simple SSL)
Easily improve site security with WordPress Hardening, Two-Factor Authentication (2FA), Login Protection, Vulnerability Detection and SSL certificate. Really simple, Effective and Performant WordPress Security Really Simple Security is the most lightweight and easy-to-use security plugin for WordPress. It secures your WordPress website with SSL certificate generation, including proper 301 https redirection and SSL enforcement, scanning for possible vulnerabilities, Login Protection and implementing essential WordPress hardening features. We believe that security should have the absolute minimum effect on website performance, user experience and maintainability. Therefore, Really Simple Security is: Lightweight: Every security feature is developed with a modular approach and with performance in mind. Disabled features won’t load any redundant code. Easy-to-use: 1-minute configuration with short onboarding setup. Security Features Easy SSL Migration Migrates your website to HTTPS and enforces SSL in just one click. 301 redirect via PHP or .htaccess Secure cookies Let’s Encrypt: Install an SSL Certificate if your hosting provider supports manual installation. Server Health Check: Your server configuration is every bit as important for your website security. WordPress Hardening Tweak your configuration and keep WordPress fortified and safe by tackling potential weaknesses. Prevent code execution in the uploads folder Prevent login feedback and disable user enumeration Disable XML-RPC Disable directory browsing Username restrictions (block ‘admin’ and public names) and much more.. Vulnerability Detection Get notified when plugins, themes or WP core contain vulnerabilities and need appropriate action. Login Protection Allow or enforce Two-Factor Authentication (2FA) for specific user roles. Users receive a two-factor code via Email. Improve Security with Really Simple Security Pro Protect your site with all essential security features by upgrading to Really Simple Security Pro. Advanced SSL enforcement Mixed Content Scan & Fixer. Detect files that are requested over HTTP and fix them to HTTPS, both Front- and Back-end. Enable HTTP Strict Transport Security and configure your site for the HSTS Preload list. Firewall Really Simple Security Pro includes a performant and efficient WordPress firewall, to stop bots, crawlers and bad actors with IP and username blocks. 404 blocking – Blocks crawlers as they trigger unusual numbers of 404 errors. Region blocking – Only allow/block access to your site from specific regions. Automated and customisable Firewall rules. IP blocklist and allowlist. Security Headers Security headers protect your site visitors against the risk of clickjacking, cross-site-forgery attacks, stealing login credentials and malware. Independent of your Server Configuration, works on Apache, LiteSpeed, NGINX, etc. Protect your website visitors with X-XSS Protection, X-Content-Type-Options, X-Frame-Options, a Referrer Policy and CORS headers. Automatically generate your WordPress-tailored Content Security Policy. Vulnerability Measures When a vulnerability is detected in a plugin, theme or WordPress core you will get notified accordingly. With Vulnerability Measures, you can configure simple but effective measures to make sure that a critical vulnerability won’t remain unattended. Force update: An update process will be tried multiple times until it can be assumed development of a theme or plugin is abandoned. You will be notified during these steps. Quarantine: When a plugin or theme can’t be updated to solve a vulnerability, Really Simple Security can quarantine the plugin. Advanced Site Hardening Choose a custom login URL Automated File Permissions check and fixer Rename and randomize your database prefix Change the debug.log file location to a non-public folder Disable application passwords Control admin creation Disable HTTP methods, reducing HTTP requests Login Protection Secure your website’s login process and user accounts with powerful security measures. Two-Step verification (Email login) 2FA (two factor authentication) with TOTP Passwordless login with passkey login Enforce strong passwords and frequent password change Limit Login Attempts With Limit Login Attempts you can configure a threshold to temporarily or permanently block IP addresses or (non-existing) usernames. You can also throw a CAPTCHA after a failed login (hCaptcha or Google reCaptcha) Access Control Restrict access to your site for specific regions. Add specific IP addresses or IP ranges to the Blocklist or Allowlist. Useful Links Documentation Security Definitions Translate Really Simple Security Issues & pull requests Feature requests Love Really Simple Security? If you want to support the continuing development of this plugin, please consider buying Really Simple Security Pro, which includes some excellent security features and premium support. About Really Simple Plugins Our mission is to make complex WordPress requirements really easy. Really Simple Security is developed by Really Simple Plugins. For generating SSL certificates, Really Simple Security uses the le acme2 PHP Let’s Encrypt client library, thanks to ‘fbett’ for providing it. Vulnerability Detection uses WP Vulnerability, an open-source initiative by Javier Casares. Want to join as a collaborator? We’re on GitHub as well!
Top keywords
- security27×3.54%
- really15×1.97%
- simple15×1.97%
- login14×1.84%
- really simple14×1.84%
- really simple security11×1.44%
- simple security11×1.44%
- wordpress10×1.31%
- vulnerability9×1.18%
- ssl8×1.05%
- site7×0.92%
- website6×0.79%
RescueFill
68% of visitors who start your form never finish it. RescueFill captures their email the instant they type it — before they leave — and gives you a complete toolkit to bring them back automatically. No code. No complex setup. Works with Contact Form 7, WPForms, Gravity Forms, Ninja Forms, Elementor Forms, and any HTML form on your site. Learn more at rescuefill.com | Pro Addon How to Capture Leads BEFORE They Hit Submit 🚀 What the Free Plugin Includes Real-time Lead Capture The tracker fires the moment a visitor types their email. Leads are saved silently in the background — zero impact on page speed, fully async. Dashboard See your recovery rate, total abandoned leads, recovered leads, and a live feed of recent activity — all from one clean screen. Audience Lists Create unlimited colour-tagged lists (e.g. “US Leads”, “High Value”, “Newsletter Opt-in”) to segment leads for targeted campaigns. Broadcast Campaigns Send targeted recovery emails to any audience list via your site’s built-in WordPress SMTP. Template tags include {name}, {email}, {recovery_link}, {site_name}, and more. Lead Management Full leads table with email search, status filter (Active / Abandoned / Recovered / Submitted), list filter, inline assign, and bulk assign. REST API Full CRUD REST API under /wp-json/rescue/v1/ for programmatic access to leads, lists, campaigns, and settings. ⚡ Pro Addon — Everything in Free, Plus: The optional RescueFill Pro addon (rescuefill-pro) extends the free plugin with advanced automation features: ⚡ Free vs Pro Features Free Version Includes: ✔ Real-time lead capture ✔ Dashboard & analytics ✔ Audience list segmentation ✔ Broadcast email campaigns (via SMTP) ✔ Lead management table (search, filter, status) ✔ Full REST API access Pro Version Adds Advanced Capabilities: ✔ IP Geolocation (country, city, region detection) ✔ Multi-step drip email sequences ✔ Visual drag-and-drop funnel builder ✔ Location-based automatic list assignment ✔ Email API integrations (Brevo, SendGrid) ✔ Webhook integrations (Zapier, Make, n8n, CRM tools) ✔ CSV & JSON export (up to 50,000 records) ✔ Multi-sequence campaign flows ✔ A/B testing for campaigns ✔ GDPR / CCPA consent mode ✔ White-label / Agency features 👉 Get RescueFill Pro → 📊 Visual Funnel Builder (Pro) Build n8n-style automation canvases with drag-drop nodes: ⚡ Trigger — fires when a lead is abandoned 📧 Send Email — personalised email with merge tags ⏰ Wait / Delay — pause for minutes, hours, or days 🔀 Condition — branch Yes/No on country, status, email, or any lead field 📋 Assign List — move the lead to a segment 🔗 Webhook — POST to Zapier, Make, n8n, HubSpot, or any URL 🏁 End — mark enrollment complete Ready-made templates: Welcome Sequence (3 emails over 3 days) and Abandoned Lead Recovery (conditional branching). 🔗 Webhook Integrations (Pro) Connect to 12+ apps with one-click webhook setup: Automation: Zapier, Make (Integromat), n8n CRM: HubSpot, Salesforce, ActiveCampaign Notifications: Slack Email Marketing: Mailchimp, Google Sheets SMS: Twilio Custom: any HTTP endpoint with HMAC signature verification Webhook events: lead.created, lead.abandoned, lead.recovered, lead.submitted, email.sent, list.assigned 📧 Email Sending Providers WordPress SMTP (Free) Works with any WordPress SMTP plugin. Send recovery and campaign emails using your existing email setup. Brevo (Sendinblue) (Pro) Use Brevo’s transactional email API for improved deliverability and performance. SendGrid (Pro) Designed for high-volume email sending with advanced analytics and reliability. 🏆 Supported Form Plugins Works out of the box with Contact Form 7, WPForms (Lite & Pro), Gravity Forms, Ninja Forms, Elementor Forms, Formidable Forms, and any HTML with an email field. 🔐 Privacy & GDPR GDPR Mode (Pro) — requires explicit consent before tracking IP tracking on/off toggle Location tracking on/off toggle Data retention: auto-purge old leads after configurable days Right to deletion: delete individual leads from the admin 🛠 Developer Friendly Full REST API: GET/POST/PATCH/DELETE for leads, lists, campaigns, settings WordPress action hooks: rescue_lead_saved, rescue_lead_abandoned, rescue_lead_recovered Filter hooks: rescue_allow_list_auto_assign_rules, rescue_list_auto_assign_rules, RESCUE_js_data Pro funnel API: /wp-json/rfpro/v1/funnels/* GPLv2 licensed — full source code available External Services This plugin connects to the following third-party services when configured: ip-api.com — IP Geolocation (Pro addon only) Used to automatically detect the country, region, and city of each lead based on their IP address. Only called when a new lead is saved and geolocation is enabled. Service URL: https://ip-api.com | Privacy Policy: https://ip-api.com/docs/legal Disable in: Pro addon → Settings → Advanced → Disable IP Geolocation