Really Simple Security – Simple and Performant Security (formerly Really Simple SSL)
Easily improve site security with WordPress Hardening, Two-Factor Authentication (2FA), Login Protection, Vulnerability Detection and SSL certificate. Really simple, Effective and Performant WordPress Security Really Simple Security is the most lightweight and easy-to-use security plugin for WordPress. It secures your WordPress website with SSL certificate generation, including proper 301 https redirection and SSL enforcement, scanning for possible vulnerabilities, Login Protection and implementing essential WordPress hardening features. We believe that security should have the absolute minimum effect on website performance, user experience and maintainability. Therefore, Really Simple Security is: Lightweight: Every security feature is developed with a modular approach and with performance in mind. Disabled features won’t load any redundant code. Easy-to-use: 1-minute configuration with short onboarding setup. Security Features Easy SSL Migration Migrates your website to HTTPS and enforces SSL in just one click. 301 redirect via PHP or .htaccess Secure cookies Let’s Encrypt: Install an SSL Certificate if your hosting provider supports manual installation. Server Health Check: Your server configuration is every bit as important for your website security. WordPress Hardening Tweak your configuration and keep WordPress fortified and safe by tackling potential weaknesses. Prevent code execution in the uploads folder Prevent login feedback and disable user enumeration Disable XML-RPC Disable directory browsing Username restrictions (block ‘admin’ and public names) and much more.. Vulnerability Detection Get notified when plugins, themes or WP core contain vulnerabilities and need appropriate action. Login Protection Allow or enforce Two-Factor Authentication (2FA) for specific user roles. Users receive a two-factor code via Email. Improve Security with Really Simple Security Pro Protect your site with all essential security features by upgrading to Really Simple Security Pro. Advanced SSL enforcement Mixed Content Scan & Fixer. Detect files that are requested over HTTP and fix them to HTTPS, both Front- and Back-end. Enable HTTP Strict Transport Security and configure your site for the HSTS Preload list. Firewall Really Simple Security Pro includes a performant and efficient WordPress firewall, to stop bots, crawlers and bad actors with IP and username blocks. 404 blocking – Blocks crawlers as they trigger unusual numbers of 404 errors. Region blocking – Only allow/block access to your site from specific regions. Automated and customisable Firewall rules. IP blocklist and allowlist. Security Headers Security headers protect your site visitors against the risk of clickjacking, cross-site-forgery attacks, stealing login credentials and malware. Independent of your Server Configuration, works on Apache, LiteSpeed, NGINX, etc. Protect your website visitors with X-XSS Protection, X-Content-Type-Options, X-Frame-Options, a Referrer Policy and CORS headers. Automatically generate your WordPress-tailored Content Security Policy. Vulnerability Measures When a vulnerability is detected in a plugin, theme or WordPress core you will get notified accordingly. With Vulnerability Measures, you can configure simple but effective measures to make sure that a critical vulnerability won’t remain unattended. Force update: An update process will be tried multiple times until it can be assumed development of a theme or plugin is abandoned. You will be notified during these steps. Quarantine: When a plugin or theme can’t be updated to solve a vulnerability, Really Simple Security can quarantine the plugin. Advanced Site Hardening Choose a custom login URL Automated File Permissions check and fixer Rename and randomize your database prefix Change the debug.log file location to a non-public folder Disable application passwords Control admin creation Disable HTTP methods, reducing HTTP requests Login Protection Secure your website’s login process and user accounts with powerful security measures. Two-Step verification (Email login) 2FA (two factor authentication) with TOTP Passwordless login with passkey login Enforce strong passwords and frequent password change Limit Login Attempts With Limit Login Attempts you can configure a threshold to temporarily or permanently block IP addresses or (non-existing) usernames. You can also throw a CAPTCHA after a failed login (hCaptcha or Google reCaptcha) Access Control Restrict access to your site for specific regions. Add specific IP addresses or IP ranges to the Blocklist or Allowlist. Useful Links Documentation Security Definitions Translate Really Simple Security Issues & pull requests Feature requests Love Really Simple Security? If you want to support the continuing development of this plugin, please consider buying Really Simple Security Pro, which includes some excellent security features and premium support. About Really Simple Plugins Our mission is to make complex WordPress requirements really easy. Really Simple Security is developed by Really Simple Plugins. For generating SSL certificates, Really Simple Security uses the le acme2 PHP Let’s Encrypt client library, thanks to ‘fbett’ for providing it. Vulnerability Detection uses WP Vulnerability, an open-source initiative by Javier Casares. Want to join as a collaborator? We’re on GitHub as well!
Top keywords
- security27×3.54%
- really15×1.97%
- simple15×1.97%
- login14×1.84%
- really simple14×1.84%
- really simple security11×1.44%
- simple security11×1.44%
- wordpress10×1.31%
- vulnerability9×1.18%
- ssl8×1.05%
- site7×0.92%
- website6×0.79%
Tempmails
Self-hosted. Privacy-first. Fully yours. Tempmails turns your WordPress site into a self-hosted temporary email service. Visitors generate a random disposable email address, receive messages in a real-time inbox, and discard them when done — all without leaving your site. Unlike third-party services, Tempmails runs entirely on your own server and IMAP mailbox. You own the data, the domain, and the brand. 🔒 No third-party email APIs 📬 Real IMAP inbox — not a simulation 🎨 Material Design 3 UI — beautiful out of the box ⚡ AJAX-powered — no page reloads 🚀 Quick Links Everything you need to get started, get help, and stay connected: 🌐 Official Website — tempmails.cv — docs, roadmap, and addon announcements 🎬 Installation Tutorial — Watch the step-by-step video guide below 📺 YouTube Channel — NeoSmartApps on YouTube — tutorials, walkthroughs, and new release demos ☕ Support the Project — Buy us a coffee via PayPal — Tempmails is free forever; your support keeps development alive 🖥️ Need Hosting? — Tempmails works best on a VPS or shared host with catch-all IMAP support. We recommend Hostinger (affiliate link — we earn a small commission at no extra cost to you) 🎬 Watch: Full Installation Tutorial Core Features 📨 Email Engine IMAP Email Fetching — connects to any catch-all IMAP mailbox Auto Email Generation — random disposable addresses on your own domains Real-time Inbox — AJAX-powered message viewer with configurable auto-refresh Attachment Support — download files with 40+ allowed extensions 🎨 Design & UI Material Design 3 UI — modern, responsive inbox with Inter & Poppins fonts White-labeled — fully rebrandable, no third-party branding in the UI Design Panel — live color picker and label customization in admin 🛡️ Privacy & Data Soft Delete — messages are never hard-deleted; safe for compliance Cookie-based sessions — no user accounts or registration required Zero external data transmission — all data stays on your server ⚙️ WordPress Native Uses WP database, cron, options, nonces, and security APIs throughout Settings API compliant admin panel Full i18n/l10n support with .pot file included Shortcode Place the inbox anywhere on your site with one shortcode: [tempmails_inbox] This renders the full inbox UI — email generation, copy button, auto-refresh, message list, and message viewer modal. Addon Ecosystem Tempmails Core is frozen infrastructure. All new functionality is delivered via addons using a documented, stable hook system — your site never breaks on Core updates. Available addon hooks cover: email generation, message routing, inbox access control, multi-domain support, billing integration, and more. See the Hooks section below for the full reference. Privacy Tempmails stores temporary email addresses in browser cookies to maintain inbox sessions between page loads. No personal data is collected, stored against user accounts, or transmitted to any external service. See External Services below for details on the optional GitHub ecosystem feed. Hooks Tempmails exposes a complete hook system for addon developers. All hooks below are stable and frozen — they will not be renamed, removed, or have their signatures changed in any minor version. Action Hooks tempmails_loaded — Core fully initialized; safe for addon bootstrap tempmails_core_ready — fires after DB integrity check; passes Core version string tempmails_activated — fires on plugin activation; safe for addon setup tempmails_deactivated — fires on plugin deactivation tempmails_email_generated — new address generated; params: $email, $ip tempmails_inbox_accessed — user opened inbox; params: $email, $ip tempmails_message_received — new message stored; params: $message_id, $to_address tempmails_message_marked_seen — message read; params: $message_id tempmails_message_deleted — soft delete triggered; params: $message_id, $email tempmails_cleanup_completed — cron cleanup finished; params: $deleted_count tempmails_fetch_completed — fetch cycle finished; params: $results array Filter Hooks tempmails_registered_addons — register your addon for the Addons admin page tempmails_generated_email — modify a generated address before returning it tempmails_available_domains — modify the domain list available for generation tempmails_can_fetch_messages — allow/block a fetch cycle; params: $bool, $engine tempmails_can_process_message — allow/block a single message; params: $bool, $message tempmails_can_store_message — allow/block DB insert; params: $bool, $data tempmails_can_read_inbox — allow/block inbox access; params: $bool, $email tempmails_message_content — filter body before display; params: $content, $message_id tempmails_default_settings — modify default option values on activation tempmails_inbox_attributes — modify shortcode default attributes tempmails_admin_dashboard_stats — extend dashboard stat cards tempmails_settings_tabs — add custom tabs to the Settings page External Services Ecosystem Feed (Optional — Default On) Tempmails fetches a public JSON file from GitHub to display addon and ecosystem information inside the WordPress admin panel. What this connection does: Fires only when viewing Tempmails admin pages Retrieves only public, non-personal JSON content Transmits no user data, site URL, or any identifiable information Results are cached locally for 1 hour to minimize requests Remote endpoint: https://raw.githubusercontent.com/ubermensch-site/tempmails-ecosystem/main/ecosystem.json Service provider: GitHub Privacy policy: https://docs.github.com/en/site-policy/privacy-policies/github-general-privacy-statement To disable this connection entirely, uncheck Ecosystem Feed under Tempmails → Settings → General. Hardcoded fallback content is shown instead — no requests are made. Google Fonts The frontend inbox loads the Inter and Poppins typefaces and the Material Symbols icon font from Google Fonts CDN. What this connection does: Fires only on pages where [tempmails_inbox] is rendered Transmits the visitor’s IP address to Google as part of a standard font request Service provider: Google Fonts Privacy policy: https://developers.google.com/fonts/faq/privacy To avoid this (e.g. for GDPR compliance), dequeue tempmails-google-fonts and load self-hosted font copies instead. Developers This section documents internal implementation details, security practices, and notes for addon developers. Security Hardening Log All security changes are tracked here for auditing purposes. 2026-04-04 — Security Review Pass (v1.0.7 patch) class-core.php — ajax_delete_message(): $_POST['message_id'] was wp_unslash()-ed but not sanitized, with a phpcs:ignore suppression comment masking the warning. Now wrapped with sanitize_text_field( wp_unslash( … ) ). Suppression comment removed. 2026-04-02 — Security Review Pass (v1.0.7 patch) class-design.php — Removed raw echo from render_page(). Static CSS moved to assets/css/admin.css. class-design.php — inject_css_variables() refactored: replaced echo “…” with wp_add_inline_style('tempmails-admin', ...). All $v() return values now pass through esc_attr(). class-design.php — inject_frontend_css_variables() refactored: all CSS values escaped with esc_attr(), wp_strip_all_tags() applied. class-design.php — wp_footer fallback replaced raw echo ' ' with a dummy registered style handle. class-tempmails-shortcodes.php — Inline replaced with wp_add_inline_script(‘tempmails-frontend’, …). class-ecosystem.php — Inline replaced with wp_add_inline_script(‘tempmails-admin’, …). class-core.php — ajax_mark_seen(): sanitized with sanitize_text_field( wp_unslash( … ) ). class-admin.php — save_settings(): Raw $_POST replaced with $clean_post = array_map(‘sanitize_text_field’, wp_unslash($_POST)). class-email-generator.php — get_emails(): Cookie data sanitized with array_values(array_filter(array_map('sanitize_email', $raw))). Addon Development Notes Hook Stability Guarantee All hooks listed in the == Hooks == section are frozen. Signatures will not change in any 1.x release. Breaking changes will only occur in a major version bump with a migration guide. $clean_post in save_settings hooks As of the 2026-04-02 security patch, both tempmails_before_save_settings and tempmails_before_save_imap_settings receive a sanitized copy of $_POST. If your addon previously relied on raw values via these hooks, retrieve those fields directly from $_POST with appropriate sanitization. CSS Variable Injection inject_css_variables() now attaches inline CSS to the `tempmails-admin` style handle. If your addon dequeues tempmails-admin, Design color variables will not be applied on admin pages. inject_frontend_css_variables() uses a priority waterfall: 1. Attaches to tempmails-frontend if registered/enqueued 2. Falls back to tempmails-frontend-css 3. Registers a dummy handle tempmails-design-vars in wp_footer at priority 1 File Structure tempmails/ ├── assets/ │ ├── css/ │ │ ├── admin.css │ │ ├── frontend.css │ │ └── ecosystem.css │ └── js/ │ ├── admin.js │ ├── admin-design.js │ └── frontend.js ├── core/ │ ├── class-core.php │ ├── class-admin.php │ ├── class-design.php │ ├── class-ecosystem.php │ ├── class-email-generator.php │ └── class-addon-handler.php ├── includes/ │ ├── class-tempmails-shortcodes.php │ ├── class-tempmails-database.php │ ├── class-tempmails-settings.php │ ├── class-tempmails-imap.php │ └── class-tempmails-fetcher.php └── tempmails.php