Really Simple Security – Simple and Performant Security (formerly Really Simple SSL)
Easily improve site security with WordPress Hardening, Two-Factor Authentication (2FA), Login Protection, Vulnerability Detection and SSL certificate. Really simple, Effective and Performant WordPress Security Really Simple Security is the most lightweight and easy-to-use security plugin for WordPress. It secures your WordPress website with SSL certificate generation, including proper 301 https redirection and SSL enforcement, scanning for possible vulnerabilities, Login Protection and implementing essential WordPress hardening features. We believe that security should have the absolute minimum effect on website performance, user experience and maintainability. Therefore, Really Simple Security is: Lightweight: Every security feature is developed with a modular approach and with performance in mind. Disabled features won’t load any redundant code. Easy-to-use: 1-minute configuration with short onboarding setup. Security Features Easy SSL Migration Migrates your website to HTTPS and enforces SSL in just one click. 301 redirect via PHP or .htaccess Secure cookies Let’s Encrypt: Install an SSL Certificate if your hosting provider supports manual installation. Server Health Check: Your server configuration is every bit as important for your website security. WordPress Hardening Tweak your configuration and keep WordPress fortified and safe by tackling potential weaknesses. Prevent code execution in the uploads folder Prevent login feedback and disable user enumeration Disable XML-RPC Disable directory browsing Username restrictions (block ‘admin’ and public names) and much more.. Vulnerability Detection Get notified when plugins, themes or WP core contain vulnerabilities and need appropriate action. Login Protection Allow or enforce Two-Factor Authentication (2FA) for specific user roles. Users receive a two-factor code via Email. Improve Security with Really Simple Security Pro Protect your site with all essential security features by upgrading to Really Simple Security Pro. Advanced SSL enforcement Mixed Content Scan & Fixer. Detect files that are requested over HTTP and fix them to HTTPS, both Front- and Back-end. Enable HTTP Strict Transport Security and configure your site for the HSTS Preload list. Firewall Really Simple Security Pro includes a performant and efficient WordPress firewall, to stop bots, crawlers and bad actors with IP and username blocks. 404 blocking – Blocks crawlers as they trigger unusual numbers of 404 errors. Region blocking – Only allow/block access to your site from specific regions. Automated and customisable Firewall rules. IP blocklist and allowlist. Security Headers Security headers protect your site visitors against the risk of clickjacking, cross-site-forgery attacks, stealing login credentials and malware. Independent of your Server Configuration, works on Apache, LiteSpeed, NGINX, etc. Protect your website visitors with X-XSS Protection, X-Content-Type-Options, X-Frame-Options, a Referrer Policy and CORS headers. Automatically generate your WordPress-tailored Content Security Policy. Vulnerability Measures When a vulnerability is detected in a plugin, theme or WordPress core you will get notified accordingly. With Vulnerability Measures, you can configure simple but effective measures to make sure that a critical vulnerability won’t remain unattended. Force update: An update process will be tried multiple times until it can be assumed development of a theme or plugin is abandoned. You will be notified during these steps. Quarantine: When a plugin or theme can’t be updated to solve a vulnerability, Really Simple Security can quarantine the plugin. Advanced Site Hardening Choose a custom login URL Automated File Permissions check and fixer Rename and randomize your database prefix Change the debug.log file location to a non-public folder Disable application passwords Control admin creation Disable HTTP methods, reducing HTTP requests Login Protection Secure your website’s login process and user accounts with powerful security measures. Two-Step verification (Email login) 2FA (two factor authentication) with TOTP Passwordless login with passkey login Enforce strong passwords and frequent password change Limit Login Attempts With Limit Login Attempts you can configure a threshold to temporarily or permanently block IP addresses or (non-existing) usernames. You can also throw a CAPTCHA after a failed login (hCaptcha or Google reCaptcha) Access Control Restrict access to your site for specific regions. Add specific IP addresses or IP ranges to the Blocklist or Allowlist. Useful Links Documentation Security Definitions Translate Really Simple Security Issues & pull requests Feature requests Love Really Simple Security? If you want to support the continuing development of this plugin, please consider buying Really Simple Security Pro, which includes some excellent security features and premium support. About Really Simple Plugins Our mission is to make complex WordPress requirements really easy. Really Simple Security is developed by Really Simple Plugins. For generating SSL certificates, Really Simple Security uses the le acme2 PHP Let’s Encrypt client library, thanks to ‘fbett’ for providing it. Vulnerability Detection uses WP Vulnerability, an open-source initiative by Javier Casares. Want to join as a collaborator? We’re on GitHub as well!
Top keywords
- security27×3.54%
- really15×1.97%
- simple15×1.97%
- login14×1.84%
- really simple14×1.84%
- really simple security11×1.44%
- simple security11×1.44%
- wordpress10×1.31%
- vulnerability9×1.18%
- ssl8×1.05%
- site7×0.92%
- website6×0.79%
Speed in China | Test Website Speed from Mainland China | GFW Optimization & Google Fonts
How fast is your website for visitors in mainland China? Speed in China runs real HTTP speed tests from Chinese servers, scans for Great Firewall blocked resources, and localizes Google Fonts — all from your WordPress Dashboard. ⚡ FREE MAINLAND CHINA SPEED TESTS Run one free speed test every 30 days using multiple servers in mainland China with the click of a button. 🌏 MULTIPLE SERVER LOCATIONS Speed tests run from servers in different Chinese provinces — including Beijing, Shenzhen, Guangzhou, Shanghai, and Qingdao — to give you a comprehensive picture of your site’s performance in China. 🔍 CHINA RESOURCE ANALYSIS Automatically scan your site for resources blocked by the Great Firewall (GFW). Detects Google services, social media embeds, blocked CDNs, and other China-incompatible resources. 🔤 LOCALIZE GOOGLE FONTS Google Fonts (fonts.googleapis.com) are blocked in China. Enable one-click localization to download and serve Google Fonts locally so Chinese visitors see your site with the correct fonts. 📊 OPTIMIZATION INSIGHTS After each speed test, get actionable suggestions to improve your site’s performance in China based on DNS, TCP, TLS, TTFB, and total load time metrics. ⏰ UPGRADE FOR MORE FREQUENT TESTS Because of API limitations and usage, you can upgrade to one of our paid plans to run speed tests more frequently. ✅ PERFECT FOR: eCommerce stores selling to China. Agencies and developers with China-focused clients. Global websites with significant Chinese traffic. Anyone optimizing site speed behind the Great Firewall. 🆘 TOP-NOTCH SUPPORT Get red-carpet support from the Gaucho Plugins team. Just submit a ticket. 🧠 LEARN MORE > 🌱 PLANS & PRICING > ⭐️ CHINA PLUGINS BUNDLE Roadmap: Email notifications about speed test results. Scheduled automatic speed tests. A map of your website’s speed in each region in China. Export your speed test history. Display the latest speed results on the front-end. Feel free to contact our team to request other features. Our plugin relies on the Speed in China API for speed tests. See our terms of use and privacy policy. 📕 DOCUMENTATION 🤝 JOIN THE COMMUNITY ⭐️ SAVE 35% WITH CHINA PLUGINS BUNDLE ⭐️ Like the plugins? China Plugins Bundle covers eCommerce, uptime, and speed optimization to ensure your China-based website visitors have the best possible experience on your website. SAVE 35% | LEARN MORE CHINA PAYMENTS PLUGIN Easily accept WeChat Pay and Alipay payments from Chinese customers. DOWNLOAD FREE | WEBSITE BLOCKED IN CHINA Check if your site is available from mainland China servers. DOWNLOAD FREE | WEBSITE SPEED IN CHINA Run website speed tests from mainland China servers. DOWNLOAD FREE | WEBSITE GAUCHO PLUGINS PORTFOLIO Payment Page: Start accepting payments in a beautiful payment form in less than 60 seconds Split Pay Plugin: Split WooCommerce payments across multiple connected Stripe accounts. Login for Stripe Customer Portal: Create an Account login area for your Stripe customers. Gyta Buyback: Create a trade-in / buyback business using WooCommerce. Version Info: Show WP, PHP, MySQL & Web Server Versions in the WP-Admin Dashboard. China Payments Plugin: Accept WeChat Pay and Alipay payments from Chinese customers. Blocked in China: Check if your website is available in the Chinese mainland. Speed in China: Check your website’s speed in the Chinese mainland. External Services This plugin connects to the following external services. None are contacted until you explicitly opt in (click “Allow & Continue” on the connect screen), with the single exception of the Google Fonts download flow, which only runs when you separately enable the “Localize Google Fonts” toggle on the Optimizations tab. Speed in China API (api.speedinchinaplugin.com) This plugin sends your public site URL to our backend API at https://api.speedinchinaplugin.com/wp-json/speed-in-china-api/v1/speed-test each time you click “Start Speed Test”, which proxies the request to the Globalping network (api.globalping.io) to run real HTTP timings from probes in mainland China. We also perform a once-per-hour reachability health check by GETting https://api.speedinchinaplugin.com/wp-json/; no site data is sent. Speed test results are stored in your WordPress options table only; we do not retain them server-side. Terms of Use Privacy Policy Globalping (api.globalping.io) Our Speed in China API runs your speed test through the Globalping network (operated by jsDelivr). Globalping probes in mainland China receive only your public site URL — no user-identifying data — and return raw timing/HTTP-status data to our API, which forwards it back to your WordPress site. Globalping Terms Globalping Privacy Freemius (api.freemius.com, freemius.com) This plugin uses the Freemius SDK for license activation and opt-in management. When you click “Allow & Continue” on the opt-in screen, Freemius receives your admin email, site URL, WordPress and PHP versions, and the plugin version, in order to issue a license token and (for premium customers) deliver license updates. Nothing is sent before you opt in; clicking “Skip” or “Maybe Later” keeps the plugin in anonymous mode and no Freemius requests are made. Freemius Terms of Service Freemius Privacy Policy Google Fonts (fonts.googleapis.com, fonts.gstatic.com) When you enable Google Fonts localization on the Optimizations tab, this plugin connects to Google’s Fonts API (fonts.googleapis.com and fonts.gstatic.com) to download font stylesheets and font files, which are then stored and served locally from your server. The font family names already present in your site’s HTML are sent to Google as part of the download URL. No personal visitor data is transmitted to Google by this plugin. The toggle is off by default; no Google Fonts request is ever made until you enable it. Google Terms of Service Google Privacy Policy