Really Simple Security – Simple and Performant Security (formerly Really Simple SSL)
Easily improve site security with WordPress Hardening, Two-Factor Authentication (2FA), Login Protection, Vulnerability Detection and SSL certificate. Really simple, Effective and Performant WordPress Security Really Simple Security is the most lightweight and easy-to-use security plugin for WordPress. It secures your WordPress website with SSL certificate generation, including proper 301 https redirection and SSL enforcement, scanning for possible vulnerabilities, Login Protection and implementing essential WordPress hardening features. We believe that security should have the absolute minimum effect on website performance, user experience and maintainability. Therefore, Really Simple Security is: Lightweight: Every security feature is developed with a modular approach and with performance in mind. Disabled features won’t load any redundant code. Easy-to-use: 1-minute configuration with short onboarding setup. Security Features Easy SSL Migration Migrates your website to HTTPS and enforces SSL in just one click. 301 redirect via PHP or .htaccess Secure cookies Let’s Encrypt: Install an SSL Certificate if your hosting provider supports manual installation. Server Health Check: Your server configuration is every bit as important for your website security. WordPress Hardening Tweak your configuration and keep WordPress fortified and safe by tackling potential weaknesses. Prevent code execution in the uploads folder Prevent login feedback and disable user enumeration Disable XML-RPC Disable directory browsing Username restrictions (block ‘admin’ and public names) and much more.. Vulnerability Detection Get notified when plugins, themes or WP core contain vulnerabilities and need appropriate action. Login Protection Allow or enforce Two-Factor Authentication (2FA) for specific user roles. Users receive a two-factor code via Email. Improve Security with Really Simple Security Pro Protect your site with all essential security features by upgrading to Really Simple Security Pro. Advanced SSL enforcement Mixed Content Scan & Fixer. Detect files that are requested over HTTP and fix them to HTTPS, both Front- and Back-end. Enable HTTP Strict Transport Security and configure your site for the HSTS Preload list. Firewall Really Simple Security Pro includes a performant and efficient WordPress firewall, to stop bots, crawlers and bad actors with IP and username blocks. 404 blocking – Blocks crawlers as they trigger unusual numbers of 404 errors. Region blocking – Only allow/block access to your site from specific regions. Automated and customisable Firewall rules. IP blocklist and allowlist. Security Headers Security headers protect your site visitors against the risk of clickjacking, cross-site-forgery attacks, stealing login credentials and malware. Independent of your Server Configuration, works on Apache, LiteSpeed, NGINX, etc. Protect your website visitors with X-XSS Protection, X-Content-Type-Options, X-Frame-Options, a Referrer Policy and CORS headers. Automatically generate your WordPress-tailored Content Security Policy. Vulnerability Measures When a vulnerability is detected in a plugin, theme or WordPress core you will get notified accordingly. With Vulnerability Measures, you can configure simple but effective measures to make sure that a critical vulnerability won’t remain unattended. Force update: An update process will be tried multiple times until it can be assumed development of a theme or plugin is abandoned. You will be notified during these steps. Quarantine: When a plugin or theme can’t be updated to solve a vulnerability, Really Simple Security can quarantine the plugin. Advanced Site Hardening Choose a custom login URL Automated File Permissions check and fixer Rename and randomize your database prefix Change the debug.log file location to a non-public folder Disable application passwords Control admin creation Disable HTTP methods, reducing HTTP requests Login Protection Secure your website’s login process and user accounts with powerful security measures. Two-Step verification (Email login) 2FA (two factor authentication) with TOTP Passwordless login with passkey login Enforce strong passwords and frequent password change Limit Login Attempts With Limit Login Attempts you can configure a threshold to temporarily or permanently block IP addresses or (non-existing) usernames. You can also throw a CAPTCHA after a failed login (hCaptcha or Google reCaptcha) Access Control Restrict access to your site for specific regions. Add specific IP addresses or IP ranges to the Blocklist or Allowlist. Useful Links Documentation Security Definitions Translate Really Simple Security Issues & pull requests Feature requests Love Really Simple Security? If you want to support the continuing development of this plugin, please consider buying Really Simple Security Pro, which includes some excellent security features and premium support. About Really Simple Plugins Our mission is to make complex WordPress requirements really easy. Really Simple Security is developed by Really Simple Plugins. For generating SSL certificates, Really Simple Security uses the le acme2 PHP Let’s Encrypt client library, thanks to ‘fbett’ for providing it. Vulnerability Detection uses WP Vulnerability, an open-source initiative by Javier Casares. Want to join as a collaborator? We’re on GitHub as well!
Top keywords
- security27×3.54%
- really15×1.97%
- simple15×1.97%
- login14×1.84%
- really simple14×1.84%
- really simple security11×1.44%
- simple security11×1.44%
- wordpress10×1.31%
- vulnerability9×1.18%
- ssl8×1.05%
- site7×0.92%
- website6×0.79%
WP-PostViews
WP-PostViews counts how many times each post, page or custom post type has been read and gives you somewhere to show the number. The count is kept as post meta, so it sorts, queries and exports like anything else WordPress stores about a post. Features A view count on any post, page or custom post type, printed by a template tag or by the [views] shortcode. Two templates you edit yourself, with tokens for the count, the title, the date, the excerpt, the thumbnail, the author and more. Choose who is counted — everyone, guests only or logged in users only — and leave known robots out. Template tags and a widget for the most and least viewed posts, optionally within a category or a tag. A sortable Views column on the post and page list tables. The count on the REST API as a views field, and an AJAX counting path for sites behind a page cache. A section on the WP-Stats page when that plugin is installed. Donations I spent most of my free time creating, updating, maintaining and supporting these plugins, if you really love my plugins and could spare me a couple of bucks, I will really appreciate it. If not feel free to use it without any obligations. Usage The simplest way, and the only one that works in a block theme without editing template files, is the shortcode. Put it in the post or page whose count you want shown: [views] shows the count for the post it appears in. [views id="1"] shows the count for post 1, wherever you put it. To show the count on every post automatically, a classic theme calls the template tag from index.php, archive.php, single.php or page.php, anywhere inside the loop: The settings live at WP-Admin -> Settings -> WP-PostViews, on two tabs. Settings is where you choose who gets counted and whether WP-Stats is offered a Views section; Templates is where you edit the markup a count is rendered with. Where the count appears is decided by where your theme calls the_views() or where you put the shortcode. To hide it somewhere in particular, answer the wp_postviews_should_display filter: add_filter( 'wp_postviews_should_display', function ( $show ) { return ! is_archive() && ! is_search(); } ); Showing The View Count In A Block One block is available in the editor, under Widgets: Post Views — the view count, rendered with the template from the Templates tab. Leave Post ID at zero to show the count of the post the block is in, which is what an empty [views] does, or set it to another post’s ID to show that post’s count instead. It renders on the server, so the block preview in the editor is the real number rather than an approximation, and the count keeps rising in every post showing it without anything being re-saved. Previewing the block in the editor does not count a view. The shortcode still works and is not going anywhere. [views] and [views id="1"] behave exactly as they always have, and a post already containing one needs no change. The block calls the same code the shortcode calls, so the two render identically — use whichever suits the post. WP-CLI wp postviews list wp postviews list --limit=50 --format=json wp postviews get 42 The command reads and never writes. No screen in this plugin edits a view count, so the command does not offer one either — wp post meta update views is still there for whoever genuinely needs it, and says plainly that it is reaching past the plugin. REST API POST /wp-json/postviews/v1/post/ /view Reading a count needs no route of its own. The count is already published as a read-only views field on the core post resource, so /wp-json/wp/v2/posts/ answers with the post and its count together, and a list of posts carries every count in one response. What the core field cannot do is write, which is what this route is for: it counts a view, and it exists for sites serving cached pages, where the view has to be reported after the page is delivered. It takes the same wp_postviews_nonce the counting script is given, as a nonce parameter. It is refused unless the site defers counting — that is, unless it has a page cache and has turned the AJAX counting path on. Otherwise the view has already been counted while the page rendered, and counting again here would record every view twice. A refusal answers 403 — a bad nonce, or a site that counts views while the page renders. A post that does not exist is 404. This route is an addition. The admin-ajax.php wp_postviews action is unchanged and still supported.