Really Simple Security – Simple and Performant Security (formerly Really Simple SSL)
Easily improve site security with WordPress Hardening, Two-Factor Authentication (2FA), Login Protection, Vulnerability Detection and SSL certificate. Really simple, Effective and Performant WordPress Security Really Simple Security is the most lightweight and easy-to-use security plugin for WordPress. It secures your WordPress website with SSL certificate generation, including proper 301 https redirection and SSL enforcement, scanning for possible vulnerabilities, Login Protection and implementing essential WordPress hardening features. We believe that security should have the absolute minimum effect on website performance, user experience and maintainability. Therefore, Really Simple Security is: Lightweight: Every security feature is developed with a modular approach and with performance in mind. Disabled features won’t load any redundant code. Easy-to-use: 1-minute configuration with short onboarding setup. Security Features Easy SSL Migration Migrates your website to HTTPS and enforces SSL in just one click. 301 redirect via PHP or .htaccess Secure cookies Let’s Encrypt: Install an SSL Certificate if your hosting provider supports manual installation. Server Health Check: Your server configuration is every bit as important for your website security. WordPress Hardening Tweak your configuration and keep WordPress fortified and safe by tackling potential weaknesses. Prevent code execution in the uploads folder Prevent login feedback and disable user enumeration Disable XML-RPC Disable directory browsing Username restrictions (block ‘admin’ and public names) and much more.. Vulnerability Detection Get notified when plugins, themes or WP core contain vulnerabilities and need appropriate action. Login Protection Allow or enforce Two-Factor Authentication (2FA) for specific user roles. Users receive a two-factor code via Email. Improve Security with Really Simple Security Pro Protect your site with all essential security features by upgrading to Really Simple Security Pro. Advanced SSL enforcement Mixed Content Scan & Fixer. Detect files that are requested over HTTP and fix them to HTTPS, both Front- and Back-end. Enable HTTP Strict Transport Security and configure your site for the HSTS Preload list. Firewall Really Simple Security Pro includes a performant and efficient WordPress firewall, to stop bots, crawlers and bad actors with IP and username blocks. 404 blocking – Blocks crawlers as they trigger unusual numbers of 404 errors. Region blocking – Only allow/block access to your site from specific regions. Automated and customisable Firewall rules. IP blocklist and allowlist. Security Headers Security headers protect your site visitors against the risk of clickjacking, cross-site-forgery attacks, stealing login credentials and malware. Independent of your Server Configuration, works on Apache, LiteSpeed, NGINX, etc. Protect your website visitors with X-XSS Protection, X-Content-Type-Options, X-Frame-Options, a Referrer Policy and CORS headers. Automatically generate your WordPress-tailored Content Security Policy. Vulnerability Measures When a vulnerability is detected in a plugin, theme or WordPress core you will get notified accordingly. With Vulnerability Measures, you can configure simple but effective measures to make sure that a critical vulnerability won’t remain unattended. Force update: An update process will be tried multiple times until it can be assumed development of a theme or plugin is abandoned. You will be notified during these steps. Quarantine: When a plugin or theme can’t be updated to solve a vulnerability, Really Simple Security can quarantine the plugin. Advanced Site Hardening Choose a custom login URL Automated File Permissions check and fixer Rename and randomize your database prefix Change the debug.log file location to a non-public folder Disable application passwords Control admin creation Disable HTTP methods, reducing HTTP requests Login Protection Secure your website’s login process and user accounts with powerful security measures. Two-Step verification (Email login) 2FA (two factor authentication) with TOTP Passwordless login with passkey login Enforce strong passwords and frequent password change Limit Login Attempts With Limit Login Attempts you can configure a threshold to temporarily or permanently block IP addresses or (non-existing) usernames. You can also throw a CAPTCHA after a failed login (hCaptcha or Google reCaptcha) Access Control Restrict access to your site for specific regions. Add specific IP addresses or IP ranges to the Blocklist or Allowlist. Useful Links Documentation Security Definitions Translate Really Simple Security Issues & pull requests Feature requests Love Really Simple Security? If you want to support the continuing development of this plugin, please consider buying Really Simple Security Pro, which includes some excellent security features and premium support. About Really Simple Plugins Our mission is to make complex WordPress requirements really easy. Really Simple Security is developed by Really Simple Plugins. For generating SSL certificates, Really Simple Security uses the le acme2 PHP Let’s Encrypt client library, thanks to ‘fbett’ for providing it. Vulnerability Detection uses WP Vulnerability, an open-source initiative by Javier Casares. Want to join as a collaborator? We’re on GitHub as well!
Top keywords
- security27×3.54%
- really15×1.97%
- simple15×1.97%
- login14×1.84%
- really simple14×1.84%
- really simple security11×1.44%
- simple security11×1.44%
- wordpress10×1.31%
- vulnerability9×1.18%
- ssl8×1.05%
- site7×0.92%
- website6×0.79%
Seonix SEO – llms.txt, IndexNow & AI Search Visibility (GEO/AEO)
Seonix SEO serves llms.txt and pings IndexNow from the moment you activate it — free, no account, no configuration. That covers the technical layer of generative engine optimization (GEO) and answer engine optimization (AEO): AI assistants like ChatGPT, Perplexity, and Gemini get a machine-readable index of your content to discover and cite, and IndexNow-participating search engines (Bing, Yandex, Seznam, Naver) learn about every publish or update within minutes. Connect a Seonix account and the plugin becomes a full growth agent: it brings your site audit into WordPress, receives AI-written articles, applies one-click technical fixes, and publishes on autopilot — for Google and AI search alike. Free — works right after activation, no account needed llms.txt for AI search — your site serves /llms.txt and /llms-full.txt, a machine-readable index of your published content that AI assistants use to discover and cite your pages. Generated live, always in sync with your content. IndexNow auto-submit — publishing or updating a post pings IndexNow, so participating search engines (Bing, Yandex, Seznam, Naver) re-crawl the changed URL within minutes. The verification key is provisioned automatically; toggle it any time from the plugin settings. Free with a Seonix account Site Health inside WordPress — your site’s SEO audit as a task list: overall score, SEO / technical / AI-search breakdowns, and every issue explained (what it means, why it matters, how to fix it). Checks cover broken links, duplicate content, missing meta descriptions, image alt issues, schema gaps, sitemap problems, and dozens more. Page audit in the editor — the current page’s issues from the last scan, in the block editor sidebar and the classic editor. Structured data (JSON-LD) on articles published through Seonix — and it stays silent when another SEO plugin already outputs schema. What requires a paid Seonix plan One-click SEO fixes — apply AI-suggested fixes for the most common technical issues directly from WordPress or the Seonix dashboard. Rollback any change if you don’t like the result. AI-written articles, SEO-tuned end-to-end — Seonix learns your site, audience, voice, and topics, then generates articles with optimized titles, meta descriptions, internal links, headings, and schema markup. Autonomous publishing on a schedule — pick a cadence (daily, every 3 days, weekly), and the AI agent plans, generates, and publishes for you. Pause anytime. Plays well with your stack Works alongside your existing SEO plugin — Seonix writes SEO titles and descriptions into your SEO plugin’s own storage (and syncs your edits back), so your current setup keeps working. No SEO plugin? Seonix renders the meta tags itself. WooCommerce-ready — product pages flow into the AI context for relevant internal linking. How the WordPress plugin fits in The Seonix WordPress plugin is the bridge between your site and the Seonix service. The plugin handles the WordPress side — serving llms.txt, pinging IndexNow, receiving published articles, syncing your site structure for internal linking, and applying SEO fixes — while the AI heavy-lifting runs on the Seonix platform. How it works: Install and activate this plugin. Open the Seonix menu in your WordPress admin and click “Connect to Seonix” — pick your project in the Seonix app and the connection completes in one click. Seonix analyzes your site and starts publishing, syncing, and applying fixes via the REST API. Prefer to connect manually? Copy the auto-generated API key from Seonix → Settings and paste it into your Seonix project’s WordPress channel. No WordPress passwords either way. External Service This plugin connects your WordPress site to the Seonix service (https://seonix.ai), a third-party SaaS platform that generates and publishes SEO-optimized articles to your site. Using Seonix requires a Seonix account. What the service does Seonix uses AI to generate articles based on your site’s topic, optimize them for SEO (titles, meta descriptions, internal links, schema), and publish them back to WordPress through this plugin’s REST API. It also consumes a lightweight snapshot of your existing pages, posts, and WooCommerce products so generated articles can include relevant internal links. How you connect There are two ways to link your site, and BOTH require an explicit action by you: One-click connect (recommended): from the Seonix Dashboard inside wp-admin, click “Connect to Seonix”. Your browser opens https://app.seonix.ai/connect, where you sign in (or sign up) and pick the project to link. Seonix then calls back to your site’s REST API to finish the handshake. Your site URL is passed in the link; a single one-time security code is passed in the URL fragment so it stays out of server logs. No WordPress password leaves your site. Manual connect: copy the API key from Seonix > Settings and paste it into the Seonix dashboard. Seonix calls back to your REST API using the key. When the plugin contacts Seonix The plugin does NOT contact any external server until you connect it to a Seonix project: Install and activate the plugin — no external request is made. Connect via either method above. Until a connection succeeds, no outbound calls leave your site (clicking “Connect to Seonix” only opens the Seonix site in your browser — that browser navigation is initiated by you, not a background request from the plugin). Seonix calls back to your WordPress REST API to complete the handshake. After that, the Seonix engine URL is stored on your site. From that point on, the plugin can push a one-time site snapshot and per-post events to that engine URL, and can pull your SEO task list back from it. Until step 3 succeeds, no outbound calls leave your site. What data is sent Site snapshot (manual “Sync Now” button or weekly cron): for each public page, post, and WooCommerce product — wp_id, content_type, title, slug, url, status, updated_at. Post content body is NOT sent. Per-post events on save/delete: same shape as above plus an action flag (created / updated / deleted). Connect handshake: when Seonix completes the connection it reads your site name and site URL and stores the plugin’s API key so it can call your site later. Outbound calls go only to the Seonix endpoint authorized during connection. What data is received SEO tasks: after Seonix scans your site (on connect and weekly), it sends your site’s audit results — a list of SEO/technical/AI-search issues with a title, description, recommendation, severity, and the affected URL — which the plugin stores locally and shows on the Seonix Dashboard. The plugin can also pull this same list on demand via the “Refresh tasks” button. No personal data is received; the tasks describe your own site’s content and configuration. Terms and Privacy By installing the plugin and connecting it to a Seonix project, you accept the Seonix Terms of Service and Privacy Policy: Service: https://seonix.ai Terms of Service: https://seonix.ai/terms-of-use Privacy Policy: https://seonix.ai/privacy-policy