Really Simple Security – Simple and Performant Security (formerly Really Simple SSL)
Easily improve site security with WordPress Hardening, Two-Factor Authentication (2FA), Login Protection, Vulnerability Detection and SSL certificate. Really simple, Effective and Performant WordPress Security Really Simple Security is the most lightweight and easy-to-use security plugin for WordPress. It secures your WordPress website with SSL certificate generation, including proper 301 https redirection and SSL enforcement, scanning for possible vulnerabilities, Login Protection and implementing essential WordPress hardening features. We believe that security should have the absolute minimum effect on website performance, user experience and maintainability. Therefore, Really Simple Security is: Lightweight: Every security feature is developed with a modular approach and with performance in mind. Disabled features won’t load any redundant code. Easy-to-use: 1-minute configuration with short onboarding setup. Security Features Easy SSL Migration Migrates your website to HTTPS and enforces SSL in just one click. 301 redirect via PHP or .htaccess Secure cookies Let’s Encrypt: Install an SSL Certificate if your hosting provider supports manual installation. Server Health Check: Your server configuration is every bit as important for your website security. WordPress Hardening Tweak your configuration and keep WordPress fortified and safe by tackling potential weaknesses. Prevent code execution in the uploads folder Prevent login feedback and disable user enumeration Disable XML-RPC Disable directory browsing Username restrictions (block ‘admin’ and public names) and much more.. Vulnerability Detection Get notified when plugins, themes or WP core contain vulnerabilities and need appropriate action. Login Protection Allow or enforce Two-Factor Authentication (2FA) for specific user roles. Users receive a two-factor code via Email. Improve Security with Really Simple Security Pro Protect your site with all essential security features by upgrading to Really Simple Security Pro. Advanced SSL enforcement Mixed Content Scan & Fixer. Detect files that are requested over HTTP and fix them to HTTPS, both Front- and Back-end. Enable HTTP Strict Transport Security and configure your site for the HSTS Preload list. Firewall Really Simple Security Pro includes a performant and efficient WordPress firewall, to stop bots, crawlers and bad actors with IP and username blocks. 404 blocking – Blocks crawlers as they trigger unusual numbers of 404 errors. Region blocking – Only allow/block access to your site from specific regions. Automated and customisable Firewall rules. IP blocklist and allowlist. Security Headers Security headers protect your site visitors against the risk of clickjacking, cross-site-forgery attacks, stealing login credentials and malware. Independent of your Server Configuration, works on Apache, LiteSpeed, NGINX, etc. Protect your website visitors with X-XSS Protection, X-Content-Type-Options, X-Frame-Options, a Referrer Policy and CORS headers. Automatically generate your WordPress-tailored Content Security Policy. Vulnerability Measures When a vulnerability is detected in a plugin, theme or WordPress core you will get notified accordingly. With Vulnerability Measures, you can configure simple but effective measures to make sure that a critical vulnerability won’t remain unattended. Force update: An update process will be tried multiple times until it can be assumed development of a theme or plugin is abandoned. You will be notified during these steps. Quarantine: When a plugin or theme can’t be updated to solve a vulnerability, Really Simple Security can quarantine the plugin. Advanced Site Hardening Choose a custom login URL Automated File Permissions check and fixer Rename and randomize your database prefix Change the debug.log file location to a non-public folder Disable application passwords Control admin creation Disable HTTP methods, reducing HTTP requests Login Protection Secure your website’s login process and user accounts with powerful security measures. Two-Step verification (Email login) 2FA (two factor authentication) with TOTP Passwordless login with passkey login Enforce strong passwords and frequent password change Limit Login Attempts With Limit Login Attempts you can configure a threshold to temporarily or permanently block IP addresses or (non-existing) usernames. You can also throw a CAPTCHA after a failed login (hCaptcha or Google reCaptcha) Access Control Restrict access to your site for specific regions. Add specific IP addresses or IP ranges to the Blocklist or Allowlist. Useful Links Documentation Security Definitions Translate Really Simple Security Issues & pull requests Feature requests Love Really Simple Security? If you want to support the continuing development of this plugin, please consider buying Really Simple Security Pro, which includes some excellent security features and premium support. About Really Simple Plugins Our mission is to make complex WordPress requirements really easy. Really Simple Security is developed by Really Simple Plugins. For generating SSL certificates, Really Simple Security uses the le acme2 PHP Let’s Encrypt client library, thanks to ‘fbett’ for providing it. Vulnerability Detection uses WP Vulnerability, an open-source initiative by Javier Casares. Want to join as a collaborator? We’re on GitHub as well!
Top keywords
- security27×3.54%
- really15×1.97%
- simple15×1.97%
- login14×1.84%
- really simple14×1.84%
- really simple security11×1.44%
- simple security11×1.44%
- wordpress10×1.31%
- vulnerability9×1.18%
- ssl8×1.05%
- site7×0.92%
- website6×0.79%
WP Encryption – One Click SSL / HTTPS & Free SSL Certificate, HTTPS Redirect, Security
HTTPS Secure your WordPress site with SSL certificate provided by Let’s Encrypt® and force HTTPS / SSL sitewide, check your SSL score, fix insecure content & mixed content issues easily. Enable HTTPS secure padlock on your site within minutes. 5M+ SSL certificates generated – Switch to HTTPS easily WP Encryption plugin registers your site, verifies your domain, generates SSL certificate for your site in simple mouse clicks without the need of any technical knowledge. A typical SSL installation without WP Encryption would require you to generate CSR, prove domain ownership, provide your bussiness data and deal with many more technical tasks!. PRO FEATURES WORTH UPGRADING Automatic domain verification Automatic SSL certificate installation Automatic SSL renewal (Auto renews SSL certificate 30 days prior to expiry date) Wildcard SSL support – Install Wildcard SSL certificate for your primary domain that covers ALL sub-domains. Automatic DNS based domain verification for Wildcard SSL installation (DNS should be managed by cPanel or Godaddy) Multisite + Mapped domains support – Supports SSL installation for mapped domains Advanced security headers & SSL monitoring Top notch one to one priority support – Live Chat, Email, Premium Support Forum SSL installation help for non-cPanel sites Login security via passkeys (powered by WebAuthn) – No passwords. No brute force. Log in with passkeys protected by your browser or password manager — fast, secure, and frictionless. Automated daily vulnerability scanning & reporting. Automated daily malware & integrity scan Instant notification for threats & security issues BUY PREMIUM VERSION FREE SSL PLUGIN FEATURES Unlock every premium feature other plugins charge for — absolutely Free. Verify domain ownership and generate free SSL certificate Secure webmail and email with HTTPS Download generated SSL certificate, key and Intermediate certificate files Force HTTPS / Enable HTTPS with 301 htaccess redirection sitewide in one click HTTPS redirection includes redirect loop fix for Cloudflare, StackPath, Load balancers and reverse proxies. SSL Health page – Track your SSL score and control various SSL & Security features like HSTS strict transport security Header, HttpOnly secure cookies, etc,. Enable important security headers including X-XSS-Protection, X-Content-Type-Options, Referrer-Policy Enable mixed content / insecure content fixer SSL monitoring & Automatic email notification prior to SSL certificate expiration Advanced security features – stop user enumeration, disable file editing, hide login error, hide wp version and much more Security score & security scanners including malware & integrity scanner, vulnerability scanner. (Optional) Running WordPress on a specialized VPS/Dedicated server without cPanel? You can download the generated SSL certificate files easily via “Download SSL Certificates” page and install it on your server by modifying server config file via SSH access as explained in our DOCS. (7.8.6.0) PASSKEY LOGIN SECURITY Introducing ‘Login Security – Passkeys’ page – Enable passwordless biometric login powered by WebAuthn. Register secure passkey via profile page and enjoy seamless login experience without the need of remembering any password. (7.8.0) NEW ADVANCED SECURITY PAGE WITH INTEGRITY SCAN & MALWARE SCAN Discover the brand-new ‘Advanced Security & Scanner’ page — your command center for the most powerful protection your WordPress site has ever seen. Run malware and integrity scans to detect modified, additional, or suspicious files in your installation. Stay ahead of threats and keep your security score at its peak. ADVANCED HTTPS SECURITY HEADERS Safeguard your site from cross-site scripting attacks, clickjacking, MIME sniffing attacks. Enable HTTPS Strict Transport Security Header to avoid request protocol downgrading Disable directory listing to avoid directory traversing Enable X-XSS protection, secure cookies, X-Content-Type-Options to avoid cross site scripting and MIME sniffing Force HTTPS with 301 redirect One click enable HTTP to HTTPS redirection via FORCE HTTPS page if you already have valid SSL certificate installed on site. We highly recommend using Force HTTPS via htaccess method to enable server level faster redirection, use Force HTTPS via WordPress method only if you are using Cloudflare or other reverse proxies. Also, make sure to enable important security headers and implement advanced SSL features from the SSL Health page. Switch to HTTPS in seconds Secure HTTPS browser padlock in minutes. Free domain validated (DV) SSL certificates are provided by Let’s Encrypt (A non profit Global certificate Authority). SSL encryption ensures protection against man-in-middle attacks by securely encrypting the data transfer between client and your server. Optimized for Cloudflare and Reverse Proxies Forcing HTTPS using the .htaccess method prevents redirect loops when your site is behind Cloudflare. Compatible with reverse proxies and load balancers — avoids redirection conflicts. Top Reasons Your WordPress Site Needs an SSL Certificate SEO Benefit: Major search engines like Google ranks SSL enabled sites higher compared to non SSL sites. Thus bringing more organic traffic for your site. Data Encryption: Data transmission between server and visitor are securely encrypted on a SSL site thus avoiding any data hijacks in-between the transmission(Ex: personal information, credit card information). Trust: Google chrome shows non-SSL sites as ‘insecure’, bringing a feel of insecurity in website visitors. Authentic: HTTPS green padlock represents symbol of trust, authenticity and security. REQUIREMENTS Linux hosting, OpenSSL, CURL, allow_url_fopen should be enabled. Translations Many thanks to the generous efforts of our translators. If you would like to translate plugin to your language, Feel free to sign up and start translating! LOVE WP ENCRYPTION SSL PLUGIN? If you find this plugin useful, please leave a positive review. Your reviews are our biggest motivation for further development of plugin. Disclaimer WP Encryption uses SSLLabs API for SSL scan & detection. By using the plugin, you agree to terms & conditions of SSLLabs By enabling the Vulnerability Scan feature, you agree to terms & conditions of WPVulnerability Database API. The information provided by the information database comes from different sources that have been reviewed by third parties. There is no liability of any kind for the information. Security is an important subject regarding SSL/TLS certificates, of course. It is obvious that your private key, stored on your web server, should never be accessible from the web. When the plugin created the keys directory for the first time, it will store a .htaccess file in this directory, denying all visitors. Always make sure yourself your keys aren’t accessible from the web! We are in no way responsible if your private keys go public. If this does happen, the easiest solution is to check folder permissions on your server and make sure public access is forbidden for root folders. Next, create a new certificate.