Really Simple Security – Simple and Performant Security (formerly Really Simple SSL)
Easily improve site security with WordPress Hardening, Two-Factor Authentication (2FA), Login Protection, Vulnerability Detection and SSL certificate. Really simple, Effective and Performant WordPress Security Really Simple Security is the most lightweight and easy-to-use security plugin for WordPress. It secures your WordPress website with SSL certificate generation, including proper 301 https redirection and SSL enforcement, scanning for possible vulnerabilities, Login Protection and implementing essential WordPress hardening features. We believe that security should have the absolute minimum effect on website performance, user experience and maintainability. Therefore, Really Simple Security is: Lightweight: Every security feature is developed with a modular approach and with performance in mind. Disabled features won’t load any redundant code. Easy-to-use: 1-minute configuration with short onboarding setup. Security Features Easy SSL Migration Migrates your website to HTTPS and enforces SSL in just one click. 301 redirect via PHP or .htaccess Secure cookies Let’s Encrypt: Install an SSL Certificate if your hosting provider supports manual installation. Server Health Check: Your server configuration is every bit as important for your website security. WordPress Hardening Tweak your configuration and keep WordPress fortified and safe by tackling potential weaknesses. Prevent code execution in the uploads folder Prevent login feedback and disable user enumeration Disable XML-RPC Disable directory browsing Username restrictions (block ‘admin’ and public names) and much more.. Vulnerability Detection Get notified when plugins, themes or WP core contain vulnerabilities and need appropriate action. Login Protection Allow or enforce Two-Factor Authentication (2FA) for specific user roles. Users receive a two-factor code via Email. Improve Security with Really Simple Security Pro Protect your site with all essential security features by upgrading to Really Simple Security Pro. Advanced SSL enforcement Mixed Content Scan & Fixer. Detect files that are requested over HTTP and fix them to HTTPS, both Front- and Back-end. Enable HTTP Strict Transport Security and configure your site for the HSTS Preload list. Firewall Really Simple Security Pro includes a performant and efficient WordPress firewall, to stop bots, crawlers and bad actors with IP and username blocks. 404 blocking – Blocks crawlers as they trigger unusual numbers of 404 errors. Region blocking – Only allow/block access to your site from specific regions. Automated and customisable Firewall rules. IP blocklist and allowlist. Security Headers Security headers protect your site visitors against the risk of clickjacking, cross-site-forgery attacks, stealing login credentials and malware. Independent of your Server Configuration, works on Apache, LiteSpeed, NGINX, etc. Protect your website visitors with X-XSS Protection, X-Content-Type-Options, X-Frame-Options, a Referrer Policy and CORS headers. Automatically generate your WordPress-tailored Content Security Policy. Vulnerability Measures When a vulnerability is detected in a plugin, theme or WordPress core you will get notified accordingly. With Vulnerability Measures, you can configure simple but effective measures to make sure that a critical vulnerability won’t remain unattended. Force update: An update process will be tried multiple times until it can be assumed development of a theme or plugin is abandoned. You will be notified during these steps. Quarantine: When a plugin or theme can’t be updated to solve a vulnerability, Really Simple Security can quarantine the plugin. Advanced Site Hardening Choose a custom login URL Automated File Permissions check and fixer Rename and randomize your database prefix Change the debug.log file location to a non-public folder Disable application passwords Control admin creation Disable HTTP methods, reducing HTTP requests Login Protection Secure your website’s login process and user accounts with powerful security measures. Two-Step verification (Email login) 2FA (two factor authentication) with TOTP Passwordless login with passkey login Enforce strong passwords and frequent password change Limit Login Attempts With Limit Login Attempts you can configure a threshold to temporarily or permanently block IP addresses or (non-existing) usernames. You can also throw a CAPTCHA after a failed login (hCaptcha or Google reCaptcha) Access Control Restrict access to your site for specific regions. Add specific IP addresses or IP ranges to the Blocklist or Allowlist. Useful Links Documentation Security Definitions Translate Really Simple Security Issues & pull requests Feature requests Love Really Simple Security? If you want to support the continuing development of this plugin, please consider buying Really Simple Security Pro, which includes some excellent security features and premium support. About Really Simple Plugins Our mission is to make complex WordPress requirements really easy. Really Simple Security is developed by Really Simple Plugins. For generating SSL certificates, Really Simple Security uses the le acme2 PHP Let’s Encrypt client library, thanks to ‘fbett’ for providing it. Vulnerability Detection uses WP Vulnerability, an open-source initiative by Javier Casares. Want to join as a collaborator? We’re on GitHub as well!
Top keywords
- security27×3.54%
- really15×1.97%
- simple15×1.97%
- login14×1.84%
- really simple14×1.84%
- really simple security11×1.44%
- simple security11×1.44%
- wordpress10×1.31%
- vulnerability9×1.18%
- ssl8×1.05%
- site7×0.92%
- website6×0.79%
SMT Toolkit for WooCommerce
SMT Toolkit for WooCommerce is a modular automation and management toolkit designed for WooCommerce-based stores. The plugin provides a collection of independent modules that can be enabled or disabled as needed, allowing store owners to build flexible workflows without unnecessary features or performance overhead. SMT Toolkit focuses on automation, data consistency, and repeatable processes – especially for stores that rely on bulk imports, scheduled updates, and advanced pricing logic. Available Modules Google Drive Importer Import products, images, and updates directly from Google Drive using CSV files. Features: – Import products and images from Google Drive folders – Batch processing with progress tracking – Detailed logs and safety checks – Update rules for existing products – Optional cron-based automation Setup note: To use this module, you must create a Google Cloud project, enable the Drive API and obtain an API key. Source folders and files must be accessible through the Drive API without an OAuth user session. Official documentation: https://developers.google.com/drive/api/guides/enable-drive-api Automation: For scheduled or unattended imports, a WordPress cron task is required. CSV File Structure The importer uses CSV files to create or update products. Required fields: – id or sku (at least one is required) Optional fields: – type – barcode – short_description – description – sale_start – sale_end – in_stock – price – sale_price – categories – tags – custom meta fields (any column name will be treated as a meta key) – images (image and photo remain supported aliases) – image_alt (use | to separate values for multiple images) – image_caption (use | to separate values for multiple images) – image_description (use | to separate values for multiple images) – alt_text (legacy alias for image alt text; comma-separated) Custom meta fields are stored as product meta keys without overwriting protected WooCommerce core fields. The CSV structure is flexible. Only the required identifier field must be present. All other fields are optional and processed only if provided. Discount Engine Create flexible discount profiles with conditions, priorities, schedules, and visual indicators. Features: – Rule-based discount profiles – Support for scheduled discounts – Priority handling and conflict resolution – Customizable discount badges – Cron-based recalculation support Automation: A cron task is required to automatically apply, update, or expire scheduled discounts. Theme compatibility note: To replace the default sale badge, the theme must include a span.onsale element (the wrapper does not matter, but the onsale class must be present). Transliteration Automatically transliterate non-Latin product URLs and filenames. Features: – URL and filename transliteration – Custom rule editor – Testing and preview tools – Bulk conversion and rollback support Language support: Predefined rules are included for: – Ukrainian – Russian – Bulgarian For other languages, custom transliteration rules can be added manually. This module does not require cron configuration. Store Settings The Store Settings module centralizes WooCommerce configuration in one place – no need to edit theme files or functions.php. It allows you to safely manage store behavior, performance tweaks, product badges, and Classic checkout fields through a clean admin interface. Key Features – Disable unused frontend scripts and styles – Add context-based inline CSS and JavaScript – Clean up unnecessary WordPress and WooCommerce head output – Configure product badges (Sale, New, Sold Out, Featured, Best Seller) – Customize Classic WooCommerce checkout fields – Define custom product fields with tab display support Checkout customization works with Classic WooCommerce checkout (shortcode). Blocks checkout is automatically detected. Ajax Archive Engine AJAX-powered WooCommerce archive system with: – AJAX pagination – AJAX sorting – Lazy-loaded filters sidebar – Clean URL handling – History (back/forward) state support – Mobile-first optimized behavior Centralized SVG Registry Secure SVG management module: – Centralized SVG storage – Sanitized SVG processing – Automatic CSS generation – Base64 background rendering – Hash-based file versioning – Automatic cleanup of old files – Security-hardened SVG sanitizer Role-Based Pricing Assign custom prices or percentage discounts based on the customer’s WordPress user role. Features: – Per-role price overrides (fixed price or percentage discount) – Works with simple and variable products – Role-specific prices visible only to the matching role – Per-product manual price override via product edit screen – Fully integrated with WooCommerce cart and checkout totals – Compatible with WooCommerce price display hooks Setup note: Role configurations are managed globally from the plugin settings. Per-product price overrides are set directly on each product’s edit screen. AI Search Smart product search powered by OpenAI intent parsing and optional embeddings. Customers find products by intent and natural-language queries, not just exact keywords. Features: – OpenAI-backed intent parsing for natural-language queries – Optional OpenAI-backed embeddings index (built incrementally in the background) – Live drop-down with brand, attribute and price chips – Quick-view + add-to-cart directly from results – Configurable result count, image size and ranking – Rate limiting (burst, per-minute, per-hour, global hourly cap) – Index status dashboard with manual rebuild and per-product diagnostics – Works with simple and variable products Setup note: An OpenAI API key is required for AI parsing and embeddings. Index build is throttled and can be paused. Wishlist Personal wishlists with shareable links and multi-list support. Features: – One default list plus user-created named lists – Guest wishlists merge into the user account after login – Shareable public link per list (read-only by default) – AJAX add/remove without page reload – Wishlist counter in header (theme-friendly via hooks and helper functions) – Quick-view and add-to-cart from the wishlist modal – Optional auto-cleanup of old guest sessions Rewards / Loyalty Points Points-based rewards programme. Customers earn points on completed orders and use them as partial payment on future purchases. Features: – Per-role or per-user-level earn rate (integrates with Discount user levels) – Configurable bonus-payment cap as a percentage of the cart total – Auto-actions: registration bonus, review bonus, birthday gift, level-up bonus – Popup + email notifications (rate-limited, branded via Newsletter settings) – Refund-aware: points reverse on cancel/refund and re-credit on subsequent re-completion – Points history with paginated load-more – Opt-in/opt-out toggle on the customer’s account page – Optional self-hosted “do not load module CSS” switch for themed stores Abandon Cart Recover sales from carts that customers leave behind. Features: – Tracks logged-in and guest carts (via email capture on checkout) – Configurable reminder schedule (multiple stages) – Branded reminder emails (template shared with Newsletter / Rewards) – Rate-limited send queue with admin dashboard and per-cart audit – One-click cart restore link (token-protected) – Auto-prune of recovered or aged-out carts Newsletter Lightweight newsletter system: subscriber list, campaign composer and email branding. Features: – Subscriber list with import / export and bulk actions – Visual template with logo, From-name/address and footer (shared by all modules) – Composer with token replacement ({first_name}, {site_name}, etc.) – Per-hour send cap and queue worker (cron-based) – Unsubscribe handling with one-click token link – Bounce/error logging – Integration hook so other modules (Rewards, Abandon Cart) re-use the same branding Social Social touchpoints in a single module: share buttons, login providers and a floating contact CTA. Features: – Share buttons (Facebook, X/Twitter, Telegram, Viber, copy-link) – Social login (Google and Facebook) with token validation – Floating CTA dock with Phone / Telegram / Viber / WhatsApp / Instagram / Messenger channels – Per-channel labels (translatable) – Hover-to-reveal label on desktop, full label on mobile – Theme-friendly: every block is exposed via shortcode or hook Modular Architecture Each module operates independently and can be enabled or disabled at any time. This allows you to use only the functionality you need while keeping the system lightweight and predictable. External Services This plugin connects to external services to provide its functionality. Google Drive API The Google Drive Importer module connects to the Google Drive API to allow users to import files and images from their own Google Drive accounts into WooCommerce. What data is sent: – Google Drive file IDs – Google Drive folder IDs – API key supplied by the site owner When data is sent: – When an administrator starts an import manually – When an administrator-configured scheduled import runs Why data is sent: – To retrieve selected files and images from the user’s Google Drive account Service provider: – Google LLC Terms of Service: https://policies.google.com/terms Privacy Policy: https://policies.google.com/privacy OpenAI API The AI Search module connects to the OpenAI API to parse natural-language search queries and, when enabled, build a semantic embeddings index from your product catalog. What data is sent: – Customer search queries typed into the AI Search widget, used for intent parsing – Product titles, short descriptions, brand and taxonomy terms, used for embeddings indexing (no customer account data) – API key supplied by the site owner When data is sent: – When a visitor submits an uncached search query that is long enough to use AI parsing – During an index build or rebuild, manually triggered by an administrator or by an admin-configured cron task – Short/local-only searches and cached searches may be handled without an OpenAI request Why data is sent: – To convert natural-language search text into structured WooCommerce filters – To compute vector embeddings used for semantic matching Service provider: – OpenAI, L.L.C. Terms of Service: https://openai.com/policies/terms-of-use Privacy Policy: https://openai.com/policies/privacy-policy Nova Poshta API (optional) The Store Settings module can connect to the Nova Poshta API to provide city autocomplete and a warehouse/parcel-locker picker during Classic checkout. What data is sent: – Nova Poshta API key supplied by the site owner – City search text entered by the visitor – Selected settlement reference when loading warehouses When data is sent: – Only when the Nova Poshta picker is enabled and a visitor searches for a city or loads warehouses Why data is sent: – To find Nova Poshta settlements, branches and parcel lockers Service provider: – Nova Poshta LLC API License Agreement: https://static.novaposhta.ua/sitecard/misc/doc/API_license_agreement.pdf Privacy Policy: https://static.novaposhta.ua/sitecard/misc/doc/Privacy_policy.pdf Social Login Providers (optional) The Social module can optionally connect to Google and Facebook for one-click login. These connections only run when an administrator has configured the corresponding OAuth credentials and a user clicks the login button. What data is sent: – OAuth token round-trips initiated by the visitor’s click When data is sent: – Only on explicit user action (clicking a social-login button) Why data is sent: – To authenticate the user via the chosen provider Service providers: – Google LLC: https://policies.google.com/terms / https://policies.google.com/privacy – Meta Platforms, Inc. (Facebook): https://www.facebook.com/legal/terms / https://www.facebook.com/privacy/policy/ Social Publishing, Instagram Feed and Sharing Links (optional) The Social module can publish newly created posts or products to configured social accounts, retrieve an Instagram Business feed, and create visitor-initiated sharing/contact links. Nothing is sent unless the relevant feature and provider are configured; sharing and contact links send data only after the visitor clicks them. What data is sent: – Site owner credentials or access tokens for enabled publishing/feed providers – Published post or product title, permalink and generated sharing message – Instagram Business account ID when retrieving feed items – The current page URL, sharing text or configured contact identifier when a visitor clicks a sharing/contact link When data is sent: – After a post or product is first published and automatic publishing is enabled – When an enabled Instagram feed is loaded or its cache is refreshed – When a visitor explicitly clicks a social sharing or contact link Why data is sent: – To publish content, retrieve configured Instagram media, or open the selected third-party sharing/contact service Service providers: – Meta Platforms, Inc. (Facebook, Instagram, Threads and Messenger): https://www.facebook.com/legal/terms / https://www.facebook.com/privacy/policy/ – X Corp.: https://x.com/en/tos / https://x.com/en/privacy – LinkedIn Corporation: https://www.linkedin.com/legal/user-agreement / https://www.linkedin.com/legal/privacy-policy – Tumblr, Inc.: https://www.tumblr.com/policy/en/terms-of-service / https://www.tumblr.com/privacy – Mastodon: the service provider, terms and privacy policy depend on the instance URL configured by the site owner – Telegram Messenger Inc.: https://telegram.org/tos / https://telegram.org/privacy – Viber Media S.a r.l.: https://www.viber.com/en/terms/ / https://www.viber.com/en/terms/viber-privacy-policy/ – WhatsApp LLC: https://www.whatsapp.com/legal/terms-of-service / https://www.whatsapp.com/legal/privacy-policy Google and Meta Analytics Scripts (optional) The Store Settings module can load Google Analytics/Google Ads and Meta Pixel scripts after interaction when a site owner enables delayed analytics and supplies the corresponding IDs. What data is sent: – Configured measurement, advertising or pixel ID – Page, browser, device, cookie and interaction data collected by the enabled provider’s script according to that provider’s configuration and policies When data is sent: – Only when the site owner enables the corresponding analytics integration and the delayed script is loaded in a visitor’s browser Why data is sent: – To provide analytics, advertising measurement and configured conversion tracking Service providers: – Google LLC: https://policies.google.com/terms / https://policies.google.com/privacy – Meta Platforms, Inc.: https://www.facebook.com/legal/terms / https://www.facebook.com/privacy/policy/