Really Simple Security – Simple and Performant Security (formerly Really Simple SSL)
Easily improve site security with WordPress Hardening, Two-Factor Authentication (2FA), Login Protection, Vulnerability Detection and SSL certificate. Really simple, Effective and Performant WordPress Security Really Simple Security is the most lightweight and easy-to-use security plugin for WordPress. It secures your WordPress website with SSL certificate generation, including proper 301 https redirection and SSL enforcement, scanning for possible vulnerabilities, Login Protection and implementing essential WordPress hardening features. We believe that security should have the absolute minimum effect on website performance, user experience and maintainability. Therefore, Really Simple Security is: Lightweight: Every security feature is developed with a modular approach and with performance in mind. Disabled features won’t load any redundant code. Easy-to-use: 1-minute configuration with short onboarding setup. Security Features Easy SSL Migration Migrates your website to HTTPS and enforces SSL in just one click. 301 redirect via PHP or .htaccess Secure cookies Let’s Encrypt: Install an SSL Certificate if your hosting provider supports manual installation. Server Health Check: Your server configuration is every bit as important for your website security. WordPress Hardening Tweak your configuration and keep WordPress fortified and safe by tackling potential weaknesses. Prevent code execution in the uploads folder Prevent login feedback and disable user enumeration Disable XML-RPC Disable directory browsing Username restrictions (block ‘admin’ and public names) and much more.. Vulnerability Detection Get notified when plugins, themes or WP core contain vulnerabilities and need appropriate action. Login Protection Allow or enforce Two-Factor Authentication (2FA) for specific user roles. Users receive a two-factor code via Email. Improve Security with Really Simple Security Pro Protect your site with all essential security features by upgrading to Really Simple Security Pro. Advanced SSL enforcement Mixed Content Scan & Fixer. Detect files that are requested over HTTP and fix them to HTTPS, both Front- and Back-end. Enable HTTP Strict Transport Security and configure your site for the HSTS Preload list. Firewall Really Simple Security Pro includes a performant and efficient WordPress firewall, to stop bots, crawlers and bad actors with IP and username blocks. 404 blocking – Blocks crawlers as they trigger unusual numbers of 404 errors. Region blocking – Only allow/block access to your site from specific regions. Automated and customisable Firewall rules. IP blocklist and allowlist. Security Headers Security headers protect your site visitors against the risk of clickjacking, cross-site-forgery attacks, stealing login credentials and malware. Independent of your Server Configuration, works on Apache, LiteSpeed, NGINX, etc. Protect your website visitors with X-XSS Protection, X-Content-Type-Options, X-Frame-Options, a Referrer Policy and CORS headers. Automatically generate your WordPress-tailored Content Security Policy. Vulnerability Measures When a vulnerability is detected in a plugin, theme or WordPress core you will get notified accordingly. With Vulnerability Measures, you can configure simple but effective measures to make sure that a critical vulnerability won’t remain unattended. Force update: An update process will be tried multiple times until it can be assumed development of a theme or plugin is abandoned. You will be notified during these steps. Quarantine: When a plugin or theme can’t be updated to solve a vulnerability, Really Simple Security can quarantine the plugin. Advanced Site Hardening Choose a custom login URL Automated File Permissions check and fixer Rename and randomize your database prefix Change the debug.log file location to a non-public folder Disable application passwords Control admin creation Disable HTTP methods, reducing HTTP requests Login Protection Secure your website’s login process and user accounts with powerful security measures. Two-Step verification (Email login) 2FA (two factor authentication) with TOTP Passwordless login with passkey login Enforce strong passwords and frequent password change Limit Login Attempts With Limit Login Attempts you can configure a threshold to temporarily or permanently block IP addresses or (non-existing) usernames. You can also throw a CAPTCHA after a failed login (hCaptcha or Google reCaptcha) Access Control Restrict access to your site for specific regions. Add specific IP addresses or IP ranges to the Blocklist or Allowlist. Useful Links Documentation Security Definitions Translate Really Simple Security Issues & pull requests Feature requests Love Really Simple Security? If you want to support the continuing development of this plugin, please consider buying Really Simple Security Pro, which includes some excellent security features and premium support. About Really Simple Plugins Our mission is to make complex WordPress requirements really easy. Really Simple Security is developed by Really Simple Plugins. For generating SSL certificates, Really Simple Security uses the le acme2 PHP Let’s Encrypt client library, thanks to ‘fbett’ for providing it. Vulnerability Detection uses WP Vulnerability, an open-source initiative by Javier Casares. Want to join as a collaborator? We’re on GitHub as well!
Top keywords
- security27×3.54%
- really15×1.97%
- simple15×1.97%
- login14×1.84%
- really simple14×1.84%
- really simple security11×1.44%
- simple security11×1.44%
- wordpress10×1.31%
- vulnerability9×1.18%
- ssl8×1.05%
- site7×0.92%
- website6×0.79%
AI Chatbot & Support Agent
You already know the old kind. A visitor asks a real question, the bot replies with a link to your FAQ page, and the visitor leaves. This is the other kind. Ultimo Bots puts a real AI support agent on your WordPress site. It answers from your own content, and then it does the actual work: books the meeting, looks up the order, saves the lead, and pulls you into the conversation when it matters. You describe it. It builds itself. There is no canvas to drag boxes around on. You open the builder and type what should happen, in your own words: “When someone asks about pricing, explain the plans and offer a demo call. If they want one, book it in my Cal.com and send the lead to HubSpot.” That is the entire build step. The agent is configured from that sentence. No code, no flowcharts, no developer, no agency. Changed your mind? Tell it. That is the edit step too. It doesn’t just answer. It acts. Connect the tools you already run, and the agent uses them mid-conversation: Books appointments in Cal.com, including reschedule and cancel, or hands over your Calendly link Takes payments and manages subscriptions through Stripe links. It can list, change, or cancel a subscription. Card details never enter the chat Saves and finds contacts in HubSpot, and subscribes visitors to Mailchimp with proper double opt-in Answers from your product catalog, with prices and stock, so “do you have this in blue” gets a real answer Calls your own API with your own credentials when you need something nobody else offers Captures leads inside the conversation and emails them to you the second they land Before the agent touches anything private, it emails the visitor a six-digit code and waits for it. Verified first, every time. One agent. Every channel. The same agent runs on your WordPress site, on a shareable chat link, in Facebook Messenger, Instagram DMs, Telegram, and Slack. You train it once and it shows up everywhere. Nothing to duplicate, nothing to keep in sync. It knows your business, and it will not invent Point it at your WordPress site and it reads it. Add PDFs, Word files, spreadsheets, Google Drive, OneDrive, Notion. Every answer is built from your material, and one click re-scans your site whenever it changes. When it does not know something, it says so and offers you instead. That one habit is why people trust it on a live site. It detects the language your visitor is writing in and answers in it. You configure nothing. You stay in control Write your rules in plain words and the agent holds them, even when a visitor pushes back. Watch conversations as they happen and jump in yourself with one click. The agent goes quiet the moment you start typing and picks up again when you leave. Get pinged in Slack, Telegram, Teams, or email whenever someone wants a human. Everything is included Every capability above is on every plan. Plans differ in volume, not in what your agent can do. No per-seat pricing, no per-resolution fees, no “contact sales”. Start with a free trial, then from $19 a month. Live in about two minutes Activate the plugin, answer a few questions, and your agent is on your site. That is the whole setup. External services This plugin connects to external services operated by Ultimo Bots to function. The integration is required to register your site securely and render your AI assistant. Below are the services, what they are used for, and what data is transmitted. Policies for all of them: Terms of Service: https://www.ultimo-bots.com/terms – Privacy Policy: https://www.ultimo-bots.com/privacy 1) Ultimo Bots Portal API – site registration What: https://portal.ultimo-bots.com/api/auth/wordpress/save_secret When: On plugin activation (and retried if the first attempt failed). Purpose: Register your WordPress site and exchange a site-specific identifier used for secure operations. Data sent: site_id (random UUID generated in your WordPress site), site_url (your WordPress home URL), site_secret (random secret generated in your WordPress site), and the admin user’s email, first_name, last_name (used only to prefill the onboarding form; transferred server-side, never placed in a URL). Data received: wordpress_secret_id (an internal identifier) and a one-time connect code (valid 15 minutes, single use). 2) Ultimo Bots Portal API – connect code What: https://portal.ultimo-bots.com/api/auth/wordpress/connect_code When: When you click “Connect to Ultimo Bots” in the plugin settings, and right before the one-time onboarding redirect. Purpose: Mint a fresh one-time connect code so the onboarding can be opened without any personal data in the URL. Data sent: site_id, site_secret, and the admin user’s email, first_name, last_name (prefill, server-side only). Data received: a one-time connect code. 3) Ultimo Bots Portal API – assistant lookup What: https://portal.ultimo-bots.com/api/wordpress/my_bot When: On WP-Admin page loads (throttled to once per 5 minutes), on the plugin settings page, and once daily via WP-Cron. Purpose: Fetch the ID of the assistant connected to this site, so the assistant activates automatically after onboarding. Data sent: site_id, site_secret. Data received: bot_id and its creation status. 4) Ultimo Bots Widget Configuration API What: https://portal.ultimo-bots.com/api/widget_configuration/{bot_id} When: On public page views where the assistant is displayed, and on activation to check whether an existing Bot ID is active. Purpose: Retrieve the widget configuration for your Bot ID (colors, sizes, welcome messages). Data sent: bot_id (path parameter); optionally host_url when provided by the widget for basic operational analytics. Data received: widget configuration JSON. 5) Ultimo Bots Widget Script Host – static asset What: https://robert-kloepsch.github.io/ultimo-bots-widget/dist/bundle.js When: On public page views where the assistant is displayed. Purpose: Load the widget client code. Data sent: standard CDN/HTTP request metadata (IP, user agent) as with any static asset request. Important: This plugin does not accept or store arbitrary HTML/JS/CSS from users. It only stores a Bot ID and generates safe markup internally. The widget script is properly enqueued via WordPress functions. Privacy This plugin communicates with Ultimo Bots services as described in External services. Please review: – Terms of Service: https://www.ultimo-bots.com/terms – Privacy Policy: https://www.ultimo-bots.com/privacy