Really Simple Security – Simple and Performant Security (formerly Really Simple SSL)
Easily improve site security with WordPress Hardening, Two-Factor Authentication (2FA), Login Protection, Vulnerability Detection and SSL certificate. Really simple, Effective and Performant WordPress Security Really Simple Security is the most lightweight and easy-to-use security plugin for WordPress. It secures your WordPress website with SSL certificate generation, including proper 301 https redirection and SSL enforcement, scanning for possible vulnerabilities, Login Protection and implementing essential WordPress hardening features. We believe that security should have the absolute minimum effect on website performance, user experience and maintainability. Therefore, Really Simple Security is: Lightweight: Every security feature is developed with a modular approach and with performance in mind. Disabled features won’t load any redundant code. Easy-to-use: 1-minute configuration with short onboarding setup. Security Features Easy SSL Migration Migrates your website to HTTPS and enforces SSL in just one click. 301 redirect via PHP or .htaccess Secure cookies Let’s Encrypt: Install an SSL Certificate if your hosting provider supports manual installation. Server Health Check: Your server configuration is every bit as important for your website security. WordPress Hardening Tweak your configuration and keep WordPress fortified and safe by tackling potential weaknesses. Prevent code execution in the uploads folder Prevent login feedback and disable user enumeration Disable XML-RPC Disable directory browsing Username restrictions (block ‘admin’ and public names) and much more.. Vulnerability Detection Get notified when plugins, themes or WP core contain vulnerabilities and need appropriate action. Login Protection Allow or enforce Two-Factor Authentication (2FA) for specific user roles. Users receive a two-factor code via Email. Improve Security with Really Simple Security Pro Protect your site with all essential security features by upgrading to Really Simple Security Pro. Advanced SSL enforcement Mixed Content Scan & Fixer. Detect files that are requested over HTTP and fix them to HTTPS, both Front- and Back-end. Enable HTTP Strict Transport Security and configure your site for the HSTS Preload list. Firewall Really Simple Security Pro includes a performant and efficient WordPress firewall, to stop bots, crawlers and bad actors with IP and username blocks. 404 blocking – Blocks crawlers as they trigger unusual numbers of 404 errors. Region blocking – Only allow/block access to your site from specific regions. Automated and customisable Firewall rules. IP blocklist and allowlist. Security Headers Security headers protect your site visitors against the risk of clickjacking, cross-site-forgery attacks, stealing login credentials and malware. Independent of your Server Configuration, works on Apache, LiteSpeed, NGINX, etc. Protect your website visitors with X-XSS Protection, X-Content-Type-Options, X-Frame-Options, a Referrer Policy and CORS headers. Automatically generate your WordPress-tailored Content Security Policy. Vulnerability Measures When a vulnerability is detected in a plugin, theme or WordPress core you will get notified accordingly. With Vulnerability Measures, you can configure simple but effective measures to make sure that a critical vulnerability won’t remain unattended. Force update: An update process will be tried multiple times until it can be assumed development of a theme or plugin is abandoned. You will be notified during these steps. Quarantine: When a plugin or theme can’t be updated to solve a vulnerability, Really Simple Security can quarantine the plugin. Advanced Site Hardening Choose a custom login URL Automated File Permissions check and fixer Rename and randomize your database prefix Change the debug.log file location to a non-public folder Disable application passwords Control admin creation Disable HTTP methods, reducing HTTP requests Login Protection Secure your website’s login process and user accounts with powerful security measures. Two-Step verification (Email login) 2FA (two factor authentication) with TOTP Passwordless login with passkey login Enforce strong passwords and frequent password change Limit Login Attempts With Limit Login Attempts you can configure a threshold to temporarily or permanently block IP addresses or (non-existing) usernames. You can also throw a CAPTCHA after a failed login (hCaptcha or Google reCaptcha) Access Control Restrict access to your site for specific regions. Add specific IP addresses or IP ranges to the Blocklist or Allowlist. Useful Links Documentation Security Definitions Translate Really Simple Security Issues & pull requests Feature requests Love Really Simple Security? If you want to support the continuing development of this plugin, please consider buying Really Simple Security Pro, which includes some excellent security features and premium support. About Really Simple Plugins Our mission is to make complex WordPress requirements really easy. Really Simple Security is developed by Really Simple Plugins. For generating SSL certificates, Really Simple Security uses the le acme2 PHP Let’s Encrypt client library, thanks to ‘fbett’ for providing it. Vulnerability Detection uses WP Vulnerability, an open-source initiative by Javier Casares. Want to join as a collaborator? We’re on GitHub as well!
Top keywords
- security27×3.54%
- really15×1.97%
- simple15×1.97%
- login14×1.84%
- really simple14×1.84%
- really simple security11×1.44%
- simple security11×1.44%
- wordpress10×1.31%
- vulnerability9×1.18%
- ssl8×1.05%
- site7×0.92%
- website6×0.79%
SSL Zen
Secure your website with a Free Let’s Encrypt SSL certificate. SSL Zen is a ‘Free SSL certificate’ plugin that helps you to secure your website, protect your customer’s data and show your visitors you’re trustworthy and authentic. Manually installing a free Let’s Encrypt SSL certificate involves editing SSL configuration files on your web server and troubleshooting issues. With this plugin, you can follow a few steps to get your free Let’s Encrypt SSL certificate. No coding required, no more mixed content, or insecure content warnings. You require no special developer experience to move your HTTP web pages to HTTPS or to force SSL on your website. Features of Free Version: Generate a free SSL certificate by verifying your domain ownership Install the free SSL certificate on your server or cPanel by following our video tutorials Renew the free SSL certificate by re-verifying and re-installing the SSL certificate every 90 days Settings page that shows your SSL certificate validity duration Get an email reminder 30 days before the free SSL certificate expires Secure padlock in the browser using Let’s Encrypt™ Free SSL certificate SSL certificate is a ranking factor for search engines SSL certificate displays information about your domain name and is verified by Let’s Encrypt™ Enable secure payment processing on websites with SSL certificates Note: The free version requires you to manually verify your domain name with Let’s Encrypt by uploading a file on your server. You will also need to upload the free SSL certificate on your server and configure them. SSL certificate from Let’s Encrypt is only valid for 90 days and need to be manually renewed. If you fail to renew your free SSL certificate, your website will start showing a not secure warning to the visitors. If you want the plugin to automatically install the SSL certificate and auto-renew it, please check the premium version of the plugin. Features of Premium Version: Automatic domain verification Automatic free SSL certificate generation Automatic free SSL certificate installation Automatic free SSL certificate renewal Automatic HTTP to HTTPS redirection Premium support – Live Chat & Email CLICK HERE TO BUY THE PREMIUM VERSION Why get an SSL certificate? Trust – Starting from July 2018, Google Chrome has begun to mark all non-SSL websites as ‘Not-Secure’. When your users see the broken padlock, their trust wavers! Security – SSL certificate provides authentication, trust and compliance. If your customer is filling out forms, or making payments on your website, you need an SSL certificate to protect sensitive data from eavesdroppers. SEO – Google ranks SSL-enabled websites higher than unsecured websites. Hence, securing your website also helps get you on top of Google’s search results. Facing problems with the plugin? We have detailed documentation for the most common issues you might face while installing SSL using our plugin. Please visit our documentation site at docs.sslzen.com Please leave a review If our plugin helped you secure your website, please leave a review here For more information about our plugin, please visit sslzen.com Want SSL Zen plugin in your language? You can directly translate the plugin in your language here When you add translations, get in touch with us as we will get you listed as a Project Translation Editor for our plugin. Legal: By downloading our plugin, You agree to Let’s Encrypt® Terms of Service By downloading our plugin, You agree to LEClient license terms, a PHP LetsEncrypt client library to verify domain ownership and generate an SSL certificate for your website. We use Let’s Debug API, a diagnostic tool to help figure out why you might not be able to issue a certificate for Let’s Encrypt®. We use Freemius to collect non-sensitive diagnostic data about your website should you opt-in. Optional email updates: if you tick the optional “email me SSL tips and updates” box during setup, your email address and site domain are sent to SSL Zen (sslzen.com) to add you to our mailing list. This is entirely optional — leaving it unticked has no effect on the plugin, and you can unsubscribe from any email at any time. See our privacy policy at https://sslzen.com/privacy-policy/. Internet Security Research Group™, Let’s Encrypt®, ISRG™ are trademarks of the Internet Security Research Group. All rights reserved.