Really Simple Security – Simple and Performant Security (formerly Really Simple SSL)
Easily improve site security with WordPress Hardening, Two-Factor Authentication (2FA), Login Protection, Vulnerability Detection and SSL certificate. Really simple, Effective and Performant WordPress Security Really Simple Security is the most lightweight and easy-to-use security plugin for WordPress. It secures your WordPress website with SSL certificate generation, including proper 301 https redirection and SSL enforcement, scanning for possible vulnerabilities, Login Protection and implementing essential WordPress hardening features. We believe that security should have the absolute minimum effect on website performance, user experience and maintainability. Therefore, Really Simple Security is: Lightweight: Every security feature is developed with a modular approach and with performance in mind. Disabled features won’t load any redundant code. Easy-to-use: 1-minute configuration with short onboarding setup. Security Features Easy SSL Migration Migrates your website to HTTPS and enforces SSL in just one click. 301 redirect via PHP or .htaccess Secure cookies Let’s Encrypt: Install an SSL Certificate if your hosting provider supports manual installation. Server Health Check: Your server configuration is every bit as important for your website security. WordPress Hardening Tweak your configuration and keep WordPress fortified and safe by tackling potential weaknesses. Prevent code execution in the uploads folder Prevent login feedback and disable user enumeration Disable XML-RPC Disable directory browsing Username restrictions (block ‘admin’ and public names) and much more.. Vulnerability Detection Get notified when plugins, themes or WP core contain vulnerabilities and need appropriate action. Login Protection Allow or enforce Two-Factor Authentication (2FA) for specific user roles. Users receive a two-factor code via Email. Improve Security with Really Simple Security Pro Protect your site with all essential security features by upgrading to Really Simple Security Pro. Advanced SSL enforcement Mixed Content Scan & Fixer. Detect files that are requested over HTTP and fix them to HTTPS, both Front- and Back-end. Enable HTTP Strict Transport Security and configure your site for the HSTS Preload list. Firewall Really Simple Security Pro includes a performant and efficient WordPress firewall, to stop bots, crawlers and bad actors with IP and username blocks. 404 blocking – Blocks crawlers as they trigger unusual numbers of 404 errors. Region blocking – Only allow/block access to your site from specific regions. Automated and customisable Firewall rules. IP blocklist and allowlist. Security Headers Security headers protect your site visitors against the risk of clickjacking, cross-site-forgery attacks, stealing login credentials and malware. Independent of your Server Configuration, works on Apache, LiteSpeed, NGINX, etc. Protect your website visitors with X-XSS Protection, X-Content-Type-Options, X-Frame-Options, a Referrer Policy and CORS headers. Automatically generate your WordPress-tailored Content Security Policy. Vulnerability Measures When a vulnerability is detected in a plugin, theme or WordPress core you will get notified accordingly. With Vulnerability Measures, you can configure simple but effective measures to make sure that a critical vulnerability won’t remain unattended. Force update: An update process will be tried multiple times until it can be assumed development of a theme or plugin is abandoned. You will be notified during these steps. Quarantine: When a plugin or theme can’t be updated to solve a vulnerability, Really Simple Security can quarantine the plugin. Advanced Site Hardening Choose a custom login URL Automated File Permissions check and fixer Rename and randomize your database prefix Change the debug.log file location to a non-public folder Disable application passwords Control admin creation Disable HTTP methods, reducing HTTP requests Login Protection Secure your website’s login process and user accounts with powerful security measures. Two-Step verification (Email login) 2FA (two factor authentication) with TOTP Passwordless login with passkey login Enforce strong passwords and frequent password change Limit Login Attempts With Limit Login Attempts you can configure a threshold to temporarily or permanently block IP addresses or (non-existing) usernames. You can also throw a CAPTCHA after a failed login (hCaptcha or Google reCaptcha) Access Control Restrict access to your site for specific regions. Add specific IP addresses or IP ranges to the Blocklist or Allowlist. Useful Links Documentation Security Definitions Translate Really Simple Security Issues & pull requests Feature requests Love Really Simple Security? If you want to support the continuing development of this plugin, please consider buying Really Simple Security Pro, which includes some excellent security features and premium support. About Really Simple Plugins Our mission is to make complex WordPress requirements really easy. Really Simple Security is developed by Really Simple Plugins. For generating SSL certificates, Really Simple Security uses the le acme2 PHP Let’s Encrypt client library, thanks to ‘fbett’ for providing it. Vulnerability Detection uses WP Vulnerability, an open-source initiative by Javier Casares. Want to join as a collaborator? We’re on GitHub as well!
Top keywords
- security27×3.54%
- really15×1.97%
- simple15×1.97%
- login14×1.84%
- really simple14×1.84%
- really simple security11×1.44%
- simple security11×1.44%
- wordpress10×1.31%
- vulnerability9×1.18%
- ssl8×1.05%
- site7×0.92%
- website6×0.79%
Asset CleanUp
WordPress themes and plugins often load CSS and JavaScript on pages that do not use them. A contact form may load on the homepage, a slider may load on a plain article, or store-related files may load outside the shop. Asset CleanUp shows you what each page loads and lets you unload what is not needed. This can reduce HTTP requests, page weight, and browser work while complementing your existing caching setup. Use Test Mode to validate changes as an administrator before they affect visitors. Asset CleanUp gives you precise, testable control over every optimization. A safer workflow, without giving up control The Dashboard keeps the technical detail experienced users need while guiding first-time users through Getting Started, Test Mode, and the central Overview page. Test changes before they affect visitors, then review and manage existing or leftover rules from one place. CSS and JavaScript management View loaded stylesheets and scripts, organized by their source. Unload unnecessary CSS and JavaScript on the homepage and on individual posts, pages, and custom post types. Manage assets from the Dashboard, the post/page edit screen, or the front-end view. Review unload rules, exceptions, asset attributes, page options, and leftover entries from the Overview page. Minify and combine supported CSS and JavaScript, including supported inline code. Preload selected CSS and JavaScript files when they need to be discovered earlier. Granular manual Critical CSS management Add, edit, and remove your own Critical CSS directly from the Dashboard. Keep manual CSS organized by supported page context instead of maintaining one large global block. Asset CleanUp does not automatically generate Critical CSS. It gives you a structured way to manage CSS that you prepare yourself. Fonts and resource loading Combine, preload, asynchronously load, or remove Google Fonts requests, with font-display and preconnect controls. Preload local font files and apply font-display. Add fetchpriority, loading, and decoding attributes to images using simple matching or regular expressions. Lazy-load images where appropriate. WordPress cleanup options Remove unused WordPress features such as Emojis, Dashicons for guests, and Comment Reply. Remove selected discovery links, metadata, and oEmbed resources from the document HEAD. Disable RSS feed links or feeds when they are not needed. Restrict or disable XML-RPC when your site does not rely on it. Strip supported HTML comments, with exceptions where required. Works with your caching setup, it does not replace it Asset CleanUp is not a page-caching plugin. It controls what WordPress outputs; a page cache, server cache, or CDN can then store and deliver the optimized result. After changing rules, clear every active cache layer. Avoid enabling the same minify or combine feature in multiple optimization plugins at the same time. Asset CleanUp Lite and Pro Lite includes page-level asset management, Test Mode, manual Critical CSS for supported contexts, resource-loading controls, and WordPress cleanup options. Go beyond individual CSS and JavaScript files with the Plugins Manager. Lite includes an interactive preview of the Plugins Manager (rules can be explored, but saved only in Pro). In Pro, it can prevent entire plugins from running on frontend or Dashboard pages where they are not needed, not merely remove their CSS and JavaScript. This can reduce PHP work, database queries, and potential conflicts before the page is generated. Asset CleanUp Pro also adds broader conditional rules, hardcoded asset management, device-specific rules, and advanced JavaScript attribute and placement controls. Documentation and support Read the Asset CleanUp documentation. Ask a question in the WordPress.org support forum. External Services and Privacy WordPress.org plugin icon service When an authorized administrator opens an Asset CleanUp Dashboard screen and the local plugin-icon cache is missing or incomplete, Asset CleanUp may request public plugin information from https://api.wordpress.org/plugins/info/1.2/. The request is used only to retrieve icons for active plugins displayed inside Asset CleanUp. It can include the corresponding WordPress.org plugin slugs and standard HTTP metadata, including the server IP address. Asset CleanUp does not intentionally include the site URL, administrator details, or site content. See the WordPress.org Privacy Policy. Google Fonts preload audit When an authorized administrator explicitly runs the Google Fonts preload audit, Asset CleanUp may request discovered Google Fonts stylesheets from https://fonts.googleapis.com/ and process font-file URLs from https://fonts.gstatic.com/. Requests can include the stylesheet URL and its font-family, variant, subset, or text parameters; the browser user-agent used by the audit; and standard HTTP metadata, including the server IP address. These requests are made only as part of the administrator-initiated audit. See the Google Privacy Policy. The following two Asset CleanUp-operated services are optional. Both are disabled by default and require an administrator to opt in from Asset CleanUp > Settings > Plugin Usage Preferences. Dashboard announcements When an administrator explicitly enables announcements, Asset CleanUp periodically requests the Asset CleanUp Lite announcements feed. The feed is used to show maintenance information, important update notices, optimization guides, and occasional product offers in the WordPress Dashboard. Asset CleanUp does not intentionally add the site URL, administrator details, or site content to this request. As with any HTTP request, the service receives the server IP address and standard HTTP metadata. When announcements are disabled, this feed is not requested. Optional usage tracking When an administrator explicitly enables usage tracking, Asset CleanUp sends an initial technical check-in and then no more than one check-in per week to the Asset CleanUp usage-tracking endpoint. The payload can include the PHP, WordPress, and Asset CleanUp versions; Asset CleanUp settings; first-use and review-notice state; server software; multisite status; the active theme name and version; active and inactive plugin file identifiers; and the WordPress locale. The site URL, administrator name, and administrator email are not intentionally included in the tracking payload. Disabling the setting stops future check-ins. The announcements and usage-tracking services are operated by the Asset CleanUp developer. See the privacy policy. CloudFront infrastructure is provided by Amazon Web Services and is also subject to the AWS Privacy Notice.