Really Simple Security – Simple and Performant Security (formerly Really Simple SSL)
Easily improve site security with WordPress Hardening, Two-Factor Authentication (2FA), Login Protection, Vulnerability Detection and SSL certificate. Really simple, Effective and Performant WordPress Security Really Simple Security is the most lightweight and easy-to-use security plugin for WordPress. It secures your WordPress website with SSL certificate generation, including proper 301 https redirection and SSL enforcement, scanning for possible vulnerabilities, Login Protection and implementing essential WordPress hardening features. We believe that security should have the absolute minimum effect on website performance, user experience and maintainability. Therefore, Really Simple Security is: Lightweight: Every security feature is developed with a modular approach and with performance in mind. Disabled features won’t load any redundant code. Easy-to-use: 1-minute configuration with short onboarding setup. Security Features Easy SSL Migration Migrates your website to HTTPS and enforces SSL in just one click. 301 redirect via PHP or .htaccess Secure cookies Let’s Encrypt: Install an SSL Certificate if your hosting provider supports manual installation. Server Health Check: Your server configuration is every bit as important for your website security. WordPress Hardening Tweak your configuration and keep WordPress fortified and safe by tackling potential weaknesses. Prevent code execution in the uploads folder Prevent login feedback and disable user enumeration Disable XML-RPC Disable directory browsing Username restrictions (block ‘admin’ and public names) and much more.. Vulnerability Detection Get notified when plugins, themes or WP core contain vulnerabilities and need appropriate action. Login Protection Allow or enforce Two-Factor Authentication (2FA) for specific user roles. Users receive a two-factor code via Email. Improve Security with Really Simple Security Pro Protect your site with all essential security features by upgrading to Really Simple Security Pro. Advanced SSL enforcement Mixed Content Scan & Fixer. Detect files that are requested over HTTP and fix them to HTTPS, both Front- and Back-end. Enable HTTP Strict Transport Security and configure your site for the HSTS Preload list. Firewall Really Simple Security Pro includes a performant and efficient WordPress firewall, to stop bots, crawlers and bad actors with IP and username blocks. 404 blocking – Blocks crawlers as they trigger unusual numbers of 404 errors. Region blocking – Only allow/block access to your site from specific regions. Automated and customisable Firewall rules. IP blocklist and allowlist. Security Headers Security headers protect your site visitors against the risk of clickjacking, cross-site-forgery attacks, stealing login credentials and malware. Independent of your Server Configuration, works on Apache, LiteSpeed, NGINX, etc. Protect your website visitors with X-XSS Protection, X-Content-Type-Options, X-Frame-Options, a Referrer Policy and CORS headers. Automatically generate your WordPress-tailored Content Security Policy. Vulnerability Measures When a vulnerability is detected in a plugin, theme or WordPress core you will get notified accordingly. With Vulnerability Measures, you can configure simple but effective measures to make sure that a critical vulnerability won’t remain unattended. Force update: An update process will be tried multiple times until it can be assumed development of a theme or plugin is abandoned. You will be notified during these steps. Quarantine: When a plugin or theme can’t be updated to solve a vulnerability, Really Simple Security can quarantine the plugin. Advanced Site Hardening Choose a custom login URL Automated File Permissions check and fixer Rename and randomize your database prefix Change the debug.log file location to a non-public folder Disable application passwords Control admin creation Disable HTTP methods, reducing HTTP requests Login Protection Secure your website’s login process and user accounts with powerful security measures. Two-Step verification (Email login) 2FA (two factor authentication) with TOTP Passwordless login with passkey login Enforce strong passwords and frequent password change Limit Login Attempts With Limit Login Attempts you can configure a threshold to temporarily or permanently block IP addresses or (non-existing) usernames. You can also throw a CAPTCHA after a failed login (hCaptcha or Google reCaptcha) Access Control Restrict access to your site for specific regions. Add specific IP addresses or IP ranges to the Blocklist or Allowlist. Useful Links Documentation Security Definitions Translate Really Simple Security Issues & pull requests Feature requests Love Really Simple Security? If you want to support the continuing development of this plugin, please consider buying Really Simple Security Pro, which includes some excellent security features and premium support. About Really Simple Plugins Our mission is to make complex WordPress requirements really easy. Really Simple Security is developed by Really Simple Plugins. For generating SSL certificates, Really Simple Security uses the le acme2 PHP Let’s Encrypt client library, thanks to ‘fbett’ for providing it. Vulnerability Detection uses WP Vulnerability, an open-source initiative by Javier Casares. Want to join as a collaborator? We’re on GitHub as well!
Top keywords
- security27×3.54%
- really15×1.97%
- simple15×1.97%
- login14×1.84%
- really simple14×1.84%
- really simple security11×1.44%
- simple security11×1.44%
- wordpress10×1.31%
- vulnerability9×1.18%
- ssl8×1.05%
- site7×0.92%
- website6×0.79%
sqrip.ch
At the end of September 2022, the traditional inpayment slips (ISR) for bank transfers in Switzerland have disappeared. The replacement is the “QR bill” (https://www.einfach-zahlen.ch/), which was introduced in July 2020. In order to offer this cost-effective payment option with all its advantages in the future, we have developed sqrip. sqrip for WooCommerce consists of a universal API (http://api.sqrip.ch/) and a WordPress plugin, which connects seamlessly with WooCommerce and comes up with various options. The plugin is “open source” (https://github.com/netmex/sqrip-woocommerce) and can thus be adapted for other store systems. Names and terms you may be looking for The Swiss QR bill goes by many names: in German QR-Rechnung, QR-Einzahlungsschein or simply Einzahlungsschein; in French QR-facture, bulletin de versement or code QR; in Italian QR-fattura or polizza di versamento. sqrip produces this Swiss QR Code payment part for all of them from the same WooCommerce order. It also covers payment reconciliation (Kontoabgleich) — manually or automatically via EBICS and camt.053 — as well as WPML, multi-store and multi-site setups, an integration with PDF Invoices & Packing Slips, and multiple invoice installments. Functionality sqrip is listed as an additional payment method in WooCommerce and can be configured there. For identification and billing purposes, but also for security aspects, the plugin is connected to the sqrip account via an API key/token. The QR invoice is created by the API, delivered and saved in the desired format in the media library. From there, the file can be integrated in various places (e.g. as an insert in the confirmation email) and reopened at any time. If the invoice has been changed, the QR payment part can be updated with one click. The reference number is prominently displayed with the order so that reconciliation is quickly possible. Good to know The invoice from WooCommerce is not touched. The QR invoice is a separate PDF document. The normal IBAN or the new QR-IBAN can be used as the recipient account. With a QR-IBAN, payments can only be executed with the specification of a QR reference (number). This allows each individual deposit to be uniquely assigned to a customer / order. Automatic matching of payments received with orders is thus possible. This is the basis for further (partial) automation. One sqrip account can be connected to multiple stores. Multiple API keys are possible. Each API key should be replaced after a self-selected duration. Therefore, it is possible to define an expiration date. After this date, QR Invoice can no longer be offered without adjustments from the store owner. A new API key must be created and linked. Options sqrip offers several options: a) Name and description of payment method Name the payment method ‘Bank Transfer’ or ‘Deposit’ or whatever you want. b) b) Payee The payee is automatically taken from the sqrip account or the WooCommerce settings. A manual adjustment is possible. c) (QR-)IBAN The bank account to which the invoice amount should be transferred. If this account number is changed intentionally or unintentionally, the owner of the sqrip account will be informed of this change by e-mail. He can actively confirm the change or passively allow it. d) (QR) reference number The reference number is either created randomly or calculated on the basis of the order number. Inital 6 digits can be defined for easier identification. It automatically adapts to the IBAN format used. e) additional information On up to five lines or 140 characters additional information can be added to the QR invoice. This includes – the due date (The time given to the payer to settle the invoice may be communicated as text on the payment part.). – the order number (Be aware: sqrip not use the order# of the plugin “WoCommerce Sequential Order Numbers”) – any additional text (e.g. URL of webshop, thank you message) This field supports WPML. f) Integration Define the e-mail to which the qr-invoice will be attached to. It can also be offered for download on the confirmation page. If you generally need to adjust pricing or quantity after an order has been placed, you can suppress a QR invoice generation at the checkout and generate it manually later; Merge the QR bill slip with the invoice created with the Plugin ‘PDF Invoices & Packing Slips for WooCommerce’ into one single PDF file; Use sqrip in multiple stores installed on the same server instance. g) E-mail enclosure The QR invoice can be enclosed with the e-mail in two ways: – page A4 (blank) with payment section at the bottom; – only the payment section (formerly “payment slip”) in A6 format; – add the QR invoice to multiple e-mails; h) Language – The language to be used on the QR invoice (de, fr, it, en) is set per store. i) Test e-mail With one click, you can test the settings and see how the QR invoice is received by your customers. j) Add sqrip payment method manually – Suppress the creation of the QR invoice at checkout and define the status of the order. – Add sqrip as payment method for manually created orders. k) Use sqrip QR-Codes for Refunds Scan the QR-Code with your Banking App to initiate refunds. Remember: IBAN of client required! l) Manual payment comparison Once an order has a defined order status you can confirm that the payment was done by the client and the status of the order can be changed to another status. If there is no suitable status available, you can create one in seconds. You can confirm the payments either on the list of orders or on the order detail page. m) Payer Name – For corporate payers, choose to show either the Company name or the Firstname / Name. Or show all names together. – sqrip is ready for ‘structured addresses’ for QR invoices. n) File Name The QR invoice file names can be defined individually. Add date, order number and any other information as shop name to make the QR invoice more personal. o) Delete unneeded QR invoice automatically Keeps the size of the media library small. sqrip deletes all QR invoice files if – certain status of the order are met (e.g. Cancelled); – x days after the creation have passed. p) Adjustable to your process sqrip is flexible enough to be adopted to your individual process. – Define your own order status for payments made with sqrip; – Define the moment you expect the payment to arrive (prior to shipment or thereafter); – Define the status after payment has arrived; – Use multiple payment installments (e.g. Pay 30% when the order is placed; Pay the remaining 70% 30 days after delivery); q) Shows when something is wrong, turns off automatically Instead of showing technical, unuseful error messages to your clients, we turn the service off automatically and show you where to look at for resolving the issue. Requirements Besides a current WordPress and WooCommerce installation, an account on sqrip.ch is required. You need a (QR-)IBAN of a Swiss/Liechtenstein bank. Customers must be able to transfer payments using this method. Invoice amounts must be in CHF or EUR. Privacy The data transmitted to sqrip for the purpose of creating the QR invoice (e.g. payer, amount) will be deleted within a defined period. On https://api.sqrip.ch each production/delivery is recorded in a logbook with date/time, origin (e.g. WooCommerce), API key called and product delivered.