Really Simple Security – Simple and Performant Security (formerly Really Simple SSL)
Easily improve site security with WordPress Hardening, Two-Factor Authentication (2FA), Login Protection, Vulnerability Detection and SSL certificate. Really simple, Effective and Performant WordPress Security Really Simple Security is the most lightweight and easy-to-use security plugin for WordPress. It secures your WordPress website with SSL certificate generation, including proper 301 https redirection and SSL enforcement, scanning for possible vulnerabilities, Login Protection and implementing essential WordPress hardening features. We believe that security should have the absolute minimum effect on website performance, user experience and maintainability. Therefore, Really Simple Security is: Lightweight: Every security feature is developed with a modular approach and with performance in mind. Disabled features won’t load any redundant code. Easy-to-use: 1-minute configuration with short onboarding setup. Security Features Easy SSL Migration Migrates your website to HTTPS and enforces SSL in just one click. 301 redirect via PHP or .htaccess Secure cookies Let’s Encrypt: Install an SSL Certificate if your hosting provider supports manual installation. Server Health Check: Your server configuration is every bit as important for your website security. WordPress Hardening Tweak your configuration and keep WordPress fortified and safe by tackling potential weaknesses. Prevent code execution in the uploads folder Prevent login feedback and disable user enumeration Disable XML-RPC Disable directory browsing Username restrictions (block ‘admin’ and public names) and much more.. Vulnerability Detection Get notified when plugins, themes or WP core contain vulnerabilities and need appropriate action. Login Protection Allow or enforce Two-Factor Authentication (2FA) for specific user roles. Users receive a two-factor code via Email. Improve Security with Really Simple Security Pro Protect your site with all essential security features by upgrading to Really Simple Security Pro. Advanced SSL enforcement Mixed Content Scan & Fixer. Detect files that are requested over HTTP and fix them to HTTPS, both Front- and Back-end. Enable HTTP Strict Transport Security and configure your site for the HSTS Preload list. Firewall Really Simple Security Pro includes a performant and efficient WordPress firewall, to stop bots, crawlers and bad actors with IP and username blocks. 404 blocking – Blocks crawlers as they trigger unusual numbers of 404 errors. Region blocking – Only allow/block access to your site from specific regions. Automated and customisable Firewall rules. IP blocklist and allowlist. Security Headers Security headers protect your site visitors against the risk of clickjacking, cross-site-forgery attacks, stealing login credentials and malware. Independent of your Server Configuration, works on Apache, LiteSpeed, NGINX, etc. Protect your website visitors with X-XSS Protection, X-Content-Type-Options, X-Frame-Options, a Referrer Policy and CORS headers. Automatically generate your WordPress-tailored Content Security Policy. Vulnerability Measures When a vulnerability is detected in a plugin, theme or WordPress core you will get notified accordingly. With Vulnerability Measures, you can configure simple but effective measures to make sure that a critical vulnerability won’t remain unattended. Force update: An update process will be tried multiple times until it can be assumed development of a theme or plugin is abandoned. You will be notified during these steps. Quarantine: When a plugin or theme can’t be updated to solve a vulnerability, Really Simple Security can quarantine the plugin. Advanced Site Hardening Choose a custom login URL Automated File Permissions check and fixer Rename and randomize your database prefix Change the debug.log file location to a non-public folder Disable application passwords Control admin creation Disable HTTP methods, reducing HTTP requests Login Protection Secure your website’s login process and user accounts with powerful security measures. Two-Step verification (Email login) 2FA (two factor authentication) with TOTP Passwordless login with passkey login Enforce strong passwords and frequent password change Limit Login Attempts With Limit Login Attempts you can configure a threshold to temporarily or permanently block IP addresses or (non-existing) usernames. You can also throw a CAPTCHA after a failed login (hCaptcha or Google reCaptcha) Access Control Restrict access to your site for specific regions. Add specific IP addresses or IP ranges to the Blocklist or Allowlist. Useful Links Documentation Security Definitions Translate Really Simple Security Issues & pull requests Feature requests Love Really Simple Security? If you want to support the continuing development of this plugin, please consider buying Really Simple Security Pro, which includes some excellent security features and premium support. About Really Simple Plugins Our mission is to make complex WordPress requirements really easy. Really Simple Security is developed by Really Simple Plugins. For generating SSL certificates, Really Simple Security uses the le acme2 PHP Let’s Encrypt client library, thanks to ‘fbett’ for providing it. Vulnerability Detection uses WP Vulnerability, an open-source initiative by Javier Casares. Want to join as a collaborator? We’re on GitHub as well!
Top keywords
- security27×3.54%
- really15×1.97%
- simple15×1.97%
- login14×1.84%
- really simple14×1.84%
- really simple security11×1.44%
- simple security11×1.44%
- wordpress10×1.31%
- vulnerability9×1.18%
- ssl8×1.05%
- site7×0.92%
- website6×0.79%
WP Activity Log
Monitor activity on your WordPress sites and get clear insights into what’s happening with detailed user and event logging. Keep WordPress logs of everything that happens on your sites and multisite networks with WP Activity Log instantly, without writing a line of code. Easily detect suspicious activity on your WordPress site before it escalates Record failed login attempts to detect potential security breaches and strengthen site protection Track user logins and logouts to ensure SLAs are consistently met Monitor user activity and productivity to boost accountability Know exactly what all your users are doing in real time Know what happened before an outage for faster, easier troubleshooting Ensure compliance with regulations and standards like GDPR and PCI DSS Better manage & organize your site and users for smoother operations Simple setup ensures you start benefiting quickly and easily WP Activity Log is a complete logging solution, helping hundreds of thousands of administrators and security professionals track changes on their websites thanks to real-time user activity monitoring. 💎 Need more extensive features? Unlock advanced reporting, exports/mirroring, session management, and real-time alerts with WP Activity Log premium or enterprise. What WordPress changes WP Activity Log tracks A website activity log is important for improving troubleshooting, compliance, user management, and security. Get WP Activity Log and keep track of events on your site. The log not only tells you that a post, a user profile, or an object was updated, it also lets you know exactly what changed, when, and includes a user log (by whom), so you always have the information you need. Below is a summary of the changes that the plugin can keep a record of: Post, page, and custom post type changes: Status, content changes, title, URL, custom field, and other metadata changes Tags and category changes: Creating, modifying, deleting, and adding/removing them from posts Widget and menu changes: Creating, modifying, or deleting them User changes: User created or registered, deleted, or added to a site on multisite network User profile changes: Password, email, display name, and role changes Access logging: User login, logout, failed logins, and terminating other sessions WordPress core and settings changes: Installed updates, permalinks, default role, URL, and other site-wide changes WordPress multisite network changes: Adding, deleting, or archiving sites, adding or removing users from sites, etc. Plugin and Theme changes: Installing, activating, deactivating, uninstalling, and updating WordPress database changes: When a plugin adds or removes a table Third-party plugin changes: WooCommerce Stores & products, Yoast SEO, RankMath, Termly, WPForms, Gravity Forms, Advanced Custom Fields (ACF), MainWP, ManageWP, WP Umbrella, and other popular WordPress plugins WordPress site file changes: New files added, or existing files modified or deleted. Event details recorded Detailed event logging ensures that for every event that the plugin records, it reports the: Date & time (and milliseconds) of when it happened User & role of the user who did the change Source IP address from where the change happened The object on which the change has taken place Refer to WordPress activity log event IDs for a complete list of all the changes WP Activity Log can keep a record of and a detailed explanation of what change every event ID represents. 💎 Upgrade to WP Activity Log Premium and get even more The premium edition of WP Activity Log takes WordPress user activity tracking to the next level. It comes bundled with even more features, including log mirroring, enterprise-grade support, user session management, and much more! Premium features list See who is logged in and monitor their current activities in real-time Log off any user at the click of a button Generate fully-configurable HTML and CSV reports for easy data analysis Receive email, SMS, and Slack notifications for important changes (fully configurable) Use search filters to fine-tune results and find what you need in seconds Store the activity logs in an external database to enhance security and scalability Mirror the activity log to log management systems such as AWS CloudWatch, Loggly, Papertrail, and others in real-time Mirror the logs to business communication systems like Slack Send a copy of your website’s activity log to a log file on your web server Archive old activity log data to another database for improved storage and log management Add notes to activity log entries for better context and internal documentation Refer to the WP Activity Log plugin features and benefits page to learn more about the benefits of upgrading to WP Activity Log Premium. 🔌 WP Activity Log third-party plugin support All WP Activity Log editions include activity tracking for third-party plugins, including (in alphabetical order): Advanced Custom Fields (ACF) – Log changes to post types, taxonomies, and taxonomy terms bbPress – Track changes to forums, topics, and bbPress settings Gravity Forms – Track changes to Gravity Forms settings, forms, and entries (leads) LearnDash – Track changes to courses, lessons, and other system changes, as well as student activity such as course, lesson, and quiz enrollments and completions. MemberPress – Log changes to plugin settings, memberships, payments, subscriptions, and other actions Multisite & management tools – Track changes across your network for MainWP, ManageWP, Modular DS, Infinite WP, WP Umbrella, WP Remote, and other multisite management plugins Paid Membership Pro – Log changes to membership levels, user assignments, and more. Premium users can also track order and checkout activity, and access a Members Activity panel inside each member’s profile for instant visibility into recent actions. RankMath – Log changes to RankMath settings, SEO configurations, and on-page SEO edits Redirection – Keep a log of changes to redirections and redirection groups Termly – Log changes to Termly settings and configurations WooCommerce – Keep a log of changes to store settings, orders, products, coupons, and more WPForms – Log changes to WPForms settings, forms, form files, and entries (leads) Yoast SEO – Track changes to Yoast SEO settings and on-page SEO in the Yoast SEO meta box Extra Features for Enhanced Monitoring and Management Both free and premium editions of WP Activity Log include a number of non-logging specific features that make the plugin a complete WordPress monitoring solution. Here is what is included: Free Built-in support for reverse proxies and web application firewalls Integration with WhatIsMyIpAddress.com – get all information about an IP address with a single click Limit who can view the WordPress activity log by users or roles Enable or disable individual event IDs from the activity log Configurable dashboard widget highlighting the most recent critical activity Configurable WordPress activity log retention policies Display user avatars in events for better recognizability And much more! Premium Everything that’s included in the Free edition, plus: Full WordPress multisite support Create custom alerts & notifications to monitor additional functionality Import and export plugin settings Real-time activity log visible in the WordPress admin toolbar And much more! 🛠️ Free and premium plugin support If you encounter any issues with the free edition of WP Activity Log, you can post and get help on the WordPress.org support forums. You can also find more technical information and plugin documentation on the Melapress knowledge base. Premium plugins include a full year of free updates and dedicated one-to-one premium email support. This means you get direct access to our support team who will assist you with any questions or issues related to the plugins. As featured on: Kinsta Pagely Shout Me Loud The Dev Couple WPKube Techwibe Tidy Repo KitPloit and many others. MAINTAINED & SUPPORTED BY MELAPRESS Melapress develops high-quality WordPress management and security plugins such as Melapress Login Security, WP 2FA, and Melapress Role Editor. Browse our list of WordPress security and administration plugins to see how our plugins can help you better manage and improve the security and administration of your WordPress websites and users. Installing WP Activity Log Install WP Activity Log from within WordPress Visit ‘Plugins > Add New’ Search for ‘WP Activity Log’ Install and activate the WP Activity Log plugin Allow or skip diagnostic tracking Install WP Activity Log manually Extract the plugin ZIP file and upload it to the /wp-content/plugins/ directory Activate the WP Activity Log plugin from the ‘Plugins’ menu in WordPress Allow or skip diagnostic tracking