Really Simple Security – Simple and Performant Security (formerly Really Simple SSL)
Easily improve site security with WordPress Hardening, Two-Factor Authentication (2FA), Login Protection, Vulnerability Detection and SSL certificate. Really simple, Effective and Performant WordPress Security Really Simple Security is the most lightweight and easy-to-use security plugin for WordPress. It secures your WordPress website with SSL certificate generation, including proper 301 https redirection and SSL enforcement, scanning for possible vulnerabilities, Login Protection and implementing essential WordPress hardening features. We believe that security should have the absolute minimum effect on website performance, user experience and maintainability. Therefore, Really Simple Security is: Lightweight: Every security feature is developed with a modular approach and with performance in mind. Disabled features won’t load any redundant code. Easy-to-use: 1-minute configuration with short onboarding setup. Security Features Easy SSL Migration Migrates your website to HTTPS and enforces SSL in just one click. 301 redirect via PHP or .htaccess Secure cookies Let’s Encrypt: Install an SSL Certificate if your hosting provider supports manual installation. Server Health Check: Your server configuration is every bit as important for your website security. WordPress Hardening Tweak your configuration and keep WordPress fortified and safe by tackling potential weaknesses. Prevent code execution in the uploads folder Prevent login feedback and disable user enumeration Disable XML-RPC Disable directory browsing Username restrictions (block ‘admin’ and public names) and much more.. Vulnerability Detection Get notified when plugins, themes or WP core contain vulnerabilities and need appropriate action. Login Protection Allow or enforce Two-Factor Authentication (2FA) for specific user roles. Users receive a two-factor code via Email. Improve Security with Really Simple Security Pro Protect your site with all essential security features by upgrading to Really Simple Security Pro. Advanced SSL enforcement Mixed Content Scan & Fixer. Detect files that are requested over HTTP and fix them to HTTPS, both Front- and Back-end. Enable HTTP Strict Transport Security and configure your site for the HSTS Preload list. Firewall Really Simple Security Pro includes a performant and efficient WordPress firewall, to stop bots, crawlers and bad actors with IP and username blocks. 404 blocking – Blocks crawlers as they trigger unusual numbers of 404 errors. Region blocking – Only allow/block access to your site from specific regions. Automated and customisable Firewall rules. IP blocklist and allowlist. Security Headers Security headers protect your site visitors against the risk of clickjacking, cross-site-forgery attacks, stealing login credentials and malware. Independent of your Server Configuration, works on Apache, LiteSpeed, NGINX, etc. Protect your website visitors with X-XSS Protection, X-Content-Type-Options, X-Frame-Options, a Referrer Policy and CORS headers. Automatically generate your WordPress-tailored Content Security Policy. Vulnerability Measures When a vulnerability is detected in a plugin, theme or WordPress core you will get notified accordingly. With Vulnerability Measures, you can configure simple but effective measures to make sure that a critical vulnerability won’t remain unattended. Force update: An update process will be tried multiple times until it can be assumed development of a theme or plugin is abandoned. You will be notified during these steps. Quarantine: When a plugin or theme can’t be updated to solve a vulnerability, Really Simple Security can quarantine the plugin. Advanced Site Hardening Choose a custom login URL Automated File Permissions check and fixer Rename and randomize your database prefix Change the debug.log file location to a non-public folder Disable application passwords Control admin creation Disable HTTP methods, reducing HTTP requests Login Protection Secure your website’s login process and user accounts with powerful security measures. Two-Step verification (Email login) 2FA (two factor authentication) with TOTP Passwordless login with passkey login Enforce strong passwords and frequent password change Limit Login Attempts With Limit Login Attempts you can configure a threshold to temporarily or permanently block IP addresses or (non-existing) usernames. You can also throw a CAPTCHA after a failed login (hCaptcha or Google reCaptcha) Access Control Restrict access to your site for specific regions. Add specific IP addresses or IP ranges to the Blocklist or Allowlist. Useful Links Documentation Security Definitions Translate Really Simple Security Issues & pull requests Feature requests Love Really Simple Security? If you want to support the continuing development of this plugin, please consider buying Really Simple Security Pro, which includes some excellent security features and premium support. About Really Simple Plugins Our mission is to make complex WordPress requirements really easy. Really Simple Security is developed by Really Simple Plugins. For generating SSL certificates, Really Simple Security uses the le acme2 PHP Let’s Encrypt client library, thanks to ‘fbett’ for providing it. Vulnerability Detection uses WP Vulnerability, an open-source initiative by Javier Casares. Want to join as a collaborator? We’re on GitHub as well!
Top keywords
- security27×3.54%
- really15×1.97%
- simple15×1.97%
- login14×1.84%
- really simple14×1.84%
- really simple security11×1.44%
- simple security11×1.44%
- wordpress10×1.31%
- vulnerability9×1.18%
- ssl8×1.05%
- site7×0.92%
- website6×0.79%
Simple History – Track, Log, and Audit WordPress Changes
Trusted by 300,000+ WordPress sites, rated 4.9 stars with 450+ five-star reviews, actively developed for 10+ years, and translated into 15+ languages. Simple History is the complete audit log for WordPress. It tracks every meaningful change — content edits, user logins, plugin updates, security events, and more — so site owners, teams, agencies, and developers always know who did what and when. Just install and activate; no configuration required. Every event is written to be read: plain language like Updated page “About us”, relative timestamps such as “5 minutes ago”, and before/after comparisons instead of raw data dumps. 🔍 How Simple History Helps in Real Situations Track what’s happening on your site “Has anyone done anything today? Ah, Sarah uploaded the new press release and created an article for it. Great — now I don’t have to do that.” Identify issues and debug faster “The site feels slow since yesterday. Has anyone done anything special? … Ah, Steven activated ‘naughty-plugin-x’, that must be it.” Keep freelancers & agencies accountable “I hired a developer to optimize my site. But did they actually do anything? A quick glance at Simple History shows me exactly what they worked on.” Spot suspicious activity early “I see three failed logins from an unfamiliar IP address overnight. Let me click the IP to check all activity from that address — just those attempts, nothing else. Good to know.” ✨ What Simple History Tracks Security & Monitoring Failed user logins with IP tracking and filtering by type (wrong password vs. non-existent username) Core file integrity checks against official checksums Forced security auto-updates from WordPress.org Site Health status changes Admin page access denied events Content & Users Posts, pages, and custom post types — create, edit, delete, and homepage assignment Attachments with image edit details (crop, rotate, flip, scale) and thumbnail previews Taxonomies with detailed diffs of name, slug, description, and parent Comments, menus (with item-level detail), and widgets User profiles, logins, logouts, and role changes Notes — the collaboration feature in WordPress 6.9 System & Updates Plugin lifecycle: install, update, activate, deactivate, delete, and auto-update toggle Theme install, update, activate, switch, and delete WordPress core updates (manual and automatic) Translation and language pack updates Available update notifications Settings and option screen changes Privacy & Compliance Privacy data export and user data erasure requests Privacy page changes IP addresses anonymized by default — no cookies, no external fonts WordPress AI plugin activity is logged without ever storing API keys or prompt content 🔌 Built-in Third-Party Plugin Support Simple History includes built-in logging for: WordPress AI plugin – Feature toggles, AI provider and model changes, and connector approval requests, grants, and revocations Jetpack – Module activations and deactivations Advanced Custom Fields (ACF) – Field group and field changes User Switching – User switch events WP Crontrol – Cron event and schedule changes Enable Media Replace – File replacement details Limit Login Attempts – Login attempts, lockouts, and config changes Redirection – Redirect and group changes, global settings Duplicate Post – Post and page cloning Beaver Builder – Layout, template, and settings saves Is your plugin missing? Plugin authors can add support using the logging API. 💬 What Users Say 450+ five-star reviews on WordPress.org: “So far the best and most comprehensive logging plugin” – @herrschuessler “The best history plugin I’ve found” – Rich Mehta “Fantastic plugin I use on all sites” – Duncan Michael-MacGregor “It is a standard plugin for all of our sites” – Mr Tibbs 🚀 View Your Log Everywhere Simple History starts tracking instantly after activation — no setup needed. It even imports recent activity so your log isn’t empty on day one. Access your log from: Dashboard widget – Activity stats summary and recent events Admin bar quick view – Dropdown with latest events on any admin page Command palette – Type “Simple History” to jump to the log for the current post Dedicated admin page – Full log with search, filters, and insights sidebar Email reports – Weekly summary delivered to your inbox RSS feed – Password-protected feed for your favorite reader WP-CLI – Command-line access for automation and scripting REST API – Programmatic access for custom integrations 📧 Weekly Email Reports – Stay Informed Without Logging In Weekly email reports deliver a summary of your site’s activity every Monday morning — total activity, daily breakdown, key metrics (logins, content updates, plugin changes), and direct links to the full log. Perfect for site owners, agencies managing client sites, and teams who need regular updates without logging in. Enable it in settings and see what the email looks like before turning it on. 🛠️ For Developers & Power Users WP-CLI – List, search, and export events from the command line — perfect for automation and managing multiple sites REST API – Full programmatic access to query the log and add custom events. See the documentation Logging API – Log your own events from themes and plugins with a single line of code RSS feed – Subscribe to changes using any feed reader AI & agent-friendly – The REST API and RSS feed make Simple History accessible to AI agents and automated workflows like Claude Code Stealth Mode – Run Simple History completely hidden from the admin interface via code; Premium adds a GUI. Ideal for agencies and client sites 🔆 Extend with Add-ons Simple History Premium Alerts & Notifications – Get notified instantly via Email, Slack, Discord, or Telegram when important events occur. Start quickly with preset rules for common scenarios or build custom rules filtered by event type, user, role, and log level. Log Forwarding – Stream events to external destinations: local log files, syslog servers (UDP/TCP/TLS), Datadog, Splunk, webhooks, or external MySQL/MariaDB databases. Perfect for centralized logging, compliance, and backup. Enhanced Controls – Custom retention periods (or keep logs forever), CSV/JSON export of filtered search results, post activity panel in the block editor, custom log entries for team decisions, stealth mode GUI, logger control to fine-tune which events are recorded, and an ad-free experience. WooCommerce Logger Track WooCommerce activity: orders, refunds, stock changes, product updates, pricing adjustments, settings modifications, and coupon usage. Debug and Monitor Monitor outgoing HTTP requests and emails, debug API calls, and see what’s happening under the hood. Essential for developers and support teams. 💚 Sponsor this project If you like this plugin please consider sponsoring the development of the free plugin. The plugin has been free for over 10 years and will continue to be free.