Really Simple Security – Simple and Performant Security (formerly Really Simple SSL)
Easily improve site security with WordPress Hardening, Two-Factor Authentication (2FA), Login Protection, Vulnerability Detection and SSL certificate. Really simple, Effective and Performant WordPress Security Really Simple Security is the most lightweight and easy-to-use security plugin for WordPress. It secures your WordPress website with SSL certificate generation, including proper 301 https redirection and SSL enforcement, scanning for possible vulnerabilities, Login Protection and implementing essential WordPress hardening features. We believe that security should have the absolute minimum effect on website performance, user experience and maintainability. Therefore, Really Simple Security is: Lightweight: Every security feature is developed with a modular approach and with performance in mind. Disabled features won’t load any redundant code. Easy-to-use: 1-minute configuration with short onboarding setup. Security Features Easy SSL Migration Migrates your website to HTTPS and enforces SSL in just one click. 301 redirect via PHP or .htaccess Secure cookies Let’s Encrypt: Install an SSL Certificate if your hosting provider supports manual installation. Server Health Check: Your server configuration is every bit as important for your website security. WordPress Hardening Tweak your configuration and keep WordPress fortified and safe by tackling potential weaknesses. Prevent code execution in the uploads folder Prevent login feedback and disable user enumeration Disable XML-RPC Disable directory browsing Username restrictions (block ‘admin’ and public names) and much more.. Vulnerability Detection Get notified when plugins, themes or WP core contain vulnerabilities and need appropriate action. Login Protection Allow or enforce Two-Factor Authentication (2FA) for specific user roles. Users receive a two-factor code via Email. Improve Security with Really Simple Security Pro Protect your site with all essential security features by upgrading to Really Simple Security Pro. Advanced SSL enforcement Mixed Content Scan & Fixer. Detect files that are requested over HTTP and fix them to HTTPS, both Front- and Back-end. Enable HTTP Strict Transport Security and configure your site for the HSTS Preload list. Firewall Really Simple Security Pro includes a performant and efficient WordPress firewall, to stop bots, crawlers and bad actors with IP and username blocks. 404 blocking – Blocks crawlers as they trigger unusual numbers of 404 errors. Region blocking – Only allow/block access to your site from specific regions. Automated and customisable Firewall rules. IP blocklist and allowlist. Security Headers Security headers protect your site visitors against the risk of clickjacking, cross-site-forgery attacks, stealing login credentials and malware. Independent of your Server Configuration, works on Apache, LiteSpeed, NGINX, etc. Protect your website visitors with X-XSS Protection, X-Content-Type-Options, X-Frame-Options, a Referrer Policy and CORS headers. Automatically generate your WordPress-tailored Content Security Policy. Vulnerability Measures When a vulnerability is detected in a plugin, theme or WordPress core you will get notified accordingly. With Vulnerability Measures, you can configure simple but effective measures to make sure that a critical vulnerability won’t remain unattended. Force update: An update process will be tried multiple times until it can be assumed development of a theme or plugin is abandoned. You will be notified during these steps. Quarantine: When a plugin or theme can’t be updated to solve a vulnerability, Really Simple Security can quarantine the plugin. Advanced Site Hardening Choose a custom login URL Automated File Permissions check and fixer Rename and randomize your database prefix Change the debug.log file location to a non-public folder Disable application passwords Control admin creation Disable HTTP methods, reducing HTTP requests Login Protection Secure your website’s login process and user accounts with powerful security measures. Two-Step verification (Email login) 2FA (two factor authentication) with TOTP Passwordless login with passkey login Enforce strong passwords and frequent password change Limit Login Attempts With Limit Login Attempts you can configure a threshold to temporarily or permanently block IP addresses or (non-existing) usernames. You can also throw a CAPTCHA after a failed login (hCaptcha or Google reCaptcha) Access Control Restrict access to your site for specific regions. Add specific IP addresses or IP ranges to the Blocklist or Allowlist. Useful Links Documentation Security Definitions Translate Really Simple Security Issues & pull requests Feature requests Love Really Simple Security? If you want to support the continuing development of this plugin, please consider buying Really Simple Security Pro, which includes some excellent security features and premium support. About Really Simple Plugins Our mission is to make complex WordPress requirements really easy. Really Simple Security is developed by Really Simple Plugins. For generating SSL certificates, Really Simple Security uses the le acme2 PHP Let’s Encrypt client library, thanks to ‘fbett’ for providing it. Vulnerability Detection uses WP Vulnerability, an open-source initiative by Javier Casares. Want to join as a collaborator? We’re on GitHub as well!
Top keywords
- security27×3.54%
- really15×1.97%
- simple15×1.97%
- login14×1.84%
- really simple14×1.84%
- really simple security11×1.44%
- simple security11×1.44%
- wordpress10×1.31%
- vulnerability9×1.18%
- ssl8×1.05%
- site7×0.92%
- website6×0.79%
WindCodex ScraperBlock – Block AI Scrapers & Bots from WordPress & WooCommerce
WindCodex ScraperBlock is a free WordPress plugin that blocks AI scrapers, content crawlers, and unwanted bots from harvesting your site. Protect blog posts, product pages, and proprietary content from being fed into AI training datasets – without slowing your site down for real visitors. Setup takes under two minutes: install, enable the protections you want, save. Why Your Site Needs Bot Protection AI crawlers – including GPTBot (OpenAI), ClaudeBot (Anthropic), Google-Extended, ByteSpider, CCBot (Common Crawl), and dozens more – continuously scrape WordPress sites for training data. For content creators, WooCommerce store owners, and publishers, this means: Your original content gets harvested and used without permission or attribution. AI training traffic inflates your server load and bandwidth costs. WooCommerce store owners face a specific threat – price bots and competitor scrapers continuously harvest product prices, stock levels, and catalog data to undercut your pricing in real time. Proprietary product descriptions, pricing strategies, and business data are exposed to competitors and AI systems. Scraper traffic can mask real user patterns in your analytics. ScraperBlock gives you practical, layered defences against these threats – all from one settings screen. Free Features Protection Controls * Master protection switch – Enable or disable all ScraperBlock protections with a single toggle. * 50+ default bot signatures – Pre-loaded, categorized list of known AI scrapers, content crawlers, and price bots including GPTBot (OpenAI), ClaudeBot (Anthropic), Google-Extended, ByteSpider (ByteDance), CCBot (Common Crawl), Diffbot, PerplexityBot, and more. Maintained and updated regularly. * Custom user-agent rules – Add your own bot signatures, one per line. Target bots not in the default list. Blocking Methods * Runtime user-agent blocking – Intercepts matching bots at the PHP layer before any content is served. Works on all server types. * robots.txt blocking – Automatically injects Disallow directives for blocked bots into your robots.txt file. Signals crawlers to stay away before they visit. * Apache .htaccess blocking – Adds server-level RewriteRule blocks for matched user-agents. Stops bots before they reach PHP (Apache only). AI Opt-Out Meta Tags * noai and noimageai meta tags – Outputs on your pages. Signals AI training opt-out to crawlers that respect meta directives. * Per-page meta control – Override protection settings on individual posts and pages using a meta box in the editor. Enable, disable, or customize protection per page. Monitoring * Basic block log – Stores the last 50 blocked request events with IP, user-agent, URL path, reason, and timestamp. * Live dashboard count – Shows a basic count of blocked requests from the last 24 hours. See activity at a glance without leaving wp-admin. * Basic rate limiting – Limit request frequency from individual IPs to reduce scraper throughput. Who Needs ScraperBlock? Bloggers and content creators – Protect original articles and creative work from AI training scrapes. WooCommerce store owners – Block competitor price scrapers and AI bots that harvest product prices, descriptions, and stock levels to undercut your pricing or feed your catalog into AI systems. News and media publishers – Opt out of AI content aggregation and training dataset inclusion. Membership and course sites – Prevent paid content from being scraped by bots that bypass login pages via API or sitemap traversal. Agencies – Deploy consistent bot protection across client sites. How It Works Install and activate ScraperBlock. Go to Settings > ScraperBlock. Enable the protection modules you want (runtime blocking, robots.txt, meta tags, per-page control). Save settings. Monitor blocked requests in the Logs panel and Dashboard count widget. 🚀 Pro Version Need content poisoning, honeypot traps, behavioural detection, real-time threat feed, geo-based blocking, IP allowlists, block scheduling, and advanced analytics? ScraperBlock Pro is available at windcodex.com ScraperBlock Pro adds advanced features for high-traffic sites and serious content protection: Content poisoning – Serve subtly corrupted content to detected scrapers, degrading the value of stolen data. Honeypot traps – Invisible links that only bots follow – automatically flag and block crawlers. Behavioural detection – Identify bots by traffic pattern, not just user-agent string. Real-time threat feed – Cloud-updated block list with new bot signatures pushed automatically. Geo-based blocking – Block all traffic from specific countries at the application layer. IP allowlists & blocklists – Block individual IP addresses and CIDR ranges in addition to user-agents. Block scheduling – Define time windows when protection is active or relaxed. Advanced analytics – Full traffic breakdown by bot, country, URL, and time range with CSV export. Requirements WordPress 5.8 or higher PHP 7.4 or higher Apache is required only for .htaccess blocking mode. All other modes work on any server. Privacy ScraperBlock stores technical security data (IP address, user-agent string, URL path, block reason, action, and timestamp) in your WordPress database for local monitoring purposes. The free plugin does not require or contact any third-party API. No data is transmitted off your server.