Really Simple Security – Simple and Performant Security (formerly Really Simple SSL)
Easily improve site security with WordPress Hardening, Two-Factor Authentication (2FA), Login Protection, Vulnerability Detection and SSL certificate. Really simple, Effective and Performant WordPress Security Really Simple Security is the most lightweight and easy-to-use security plugin for WordPress. It secures your WordPress website with SSL certificate generation, including proper 301 https redirection and SSL enforcement, scanning for possible vulnerabilities, Login Protection and implementing essential WordPress hardening features. We believe that security should have the absolute minimum effect on website performance, user experience and maintainability. Therefore, Really Simple Security is: Lightweight: Every security feature is developed with a modular approach and with performance in mind. Disabled features won’t load any redundant code. Easy-to-use: 1-minute configuration with short onboarding setup. Security Features Easy SSL Migration Migrates your website to HTTPS and enforces SSL in just one click. 301 redirect via PHP or .htaccess Secure cookies Let’s Encrypt: Install an SSL Certificate if your hosting provider supports manual installation. Server Health Check: Your server configuration is every bit as important for your website security. WordPress Hardening Tweak your configuration and keep WordPress fortified and safe by tackling potential weaknesses. Prevent code execution in the uploads folder Prevent login feedback and disable user enumeration Disable XML-RPC Disable directory browsing Username restrictions (block ‘admin’ and public names) and much more.. Vulnerability Detection Get notified when plugins, themes or WP core contain vulnerabilities and need appropriate action. Login Protection Allow or enforce Two-Factor Authentication (2FA) for specific user roles. Users receive a two-factor code via Email. Improve Security with Really Simple Security Pro Protect your site with all essential security features by upgrading to Really Simple Security Pro. Advanced SSL enforcement Mixed Content Scan & Fixer. Detect files that are requested over HTTP and fix them to HTTPS, both Front- and Back-end. Enable HTTP Strict Transport Security and configure your site for the HSTS Preload list. Firewall Really Simple Security Pro includes a performant and efficient WordPress firewall, to stop bots, crawlers and bad actors with IP and username blocks. 404 blocking – Blocks crawlers as they trigger unusual numbers of 404 errors. Region blocking – Only allow/block access to your site from specific regions. Automated and customisable Firewall rules. IP blocklist and allowlist. Security Headers Security headers protect your site visitors against the risk of clickjacking, cross-site-forgery attacks, stealing login credentials and malware. Independent of your Server Configuration, works on Apache, LiteSpeed, NGINX, etc. Protect your website visitors with X-XSS Protection, X-Content-Type-Options, X-Frame-Options, a Referrer Policy and CORS headers. Automatically generate your WordPress-tailored Content Security Policy. Vulnerability Measures When a vulnerability is detected in a plugin, theme or WordPress core you will get notified accordingly. With Vulnerability Measures, you can configure simple but effective measures to make sure that a critical vulnerability won’t remain unattended. Force update: An update process will be tried multiple times until it can be assumed development of a theme or plugin is abandoned. You will be notified during these steps. Quarantine: When a plugin or theme can’t be updated to solve a vulnerability, Really Simple Security can quarantine the plugin. Advanced Site Hardening Choose a custom login URL Automated File Permissions check and fixer Rename and randomize your database prefix Change the debug.log file location to a non-public folder Disable application passwords Control admin creation Disable HTTP methods, reducing HTTP requests Login Protection Secure your website’s login process and user accounts with powerful security measures. Two-Step verification (Email login) 2FA (two factor authentication) with TOTP Passwordless login with passkey login Enforce strong passwords and frequent password change Limit Login Attempts With Limit Login Attempts you can configure a threshold to temporarily or permanently block IP addresses or (non-existing) usernames. You can also throw a CAPTCHA after a failed login (hCaptcha or Google reCaptcha) Access Control Restrict access to your site for specific regions. Add specific IP addresses or IP ranges to the Blocklist or Allowlist. Useful Links Documentation Security Definitions Translate Really Simple Security Issues & pull requests Feature requests Love Really Simple Security? If you want to support the continuing development of this plugin, please consider buying Really Simple Security Pro, which includes some excellent security features and premium support. About Really Simple Plugins Our mission is to make complex WordPress requirements really easy. Really Simple Security is developed by Really Simple Plugins. For generating SSL certificates, Really Simple Security uses the le acme2 PHP Let’s Encrypt client library, thanks to ‘fbett’ for providing it. Vulnerability Detection uses WP Vulnerability, an open-source initiative by Javier Casares. Want to join as a collaborator? We’re on GitHub as well!
Top keywords
- security27×3.54%
- really15×1.97%
- simple15×1.97%
- login14×1.84%
- really simple14×1.84%
- really simple security11×1.44%
- simple security11×1.44%
- wordpress10×1.31%
- vulnerability9×1.18%
- ssl8×1.05%
- site7×0.92%
- website6×0.79%
IntakeFlow Forms – Multi-Step Form Builder, File Upload & Client Intake
IntakeFlow is a secure, GDPR-compliant multi-step form builder and client document collection portal for WordPress. It includes a 100% free, fully featured local submission inbox in wp-admin allowing you to manage, review, and assign submissions to your team without third-party SaaS accounts or expensive user-seat upgrades. Unlike traditional form plugins that lock team collaboration tools behind expensive licenses, IntakeFlow enables assignment and status workflows out-of-the-box, storing all submissions and file uploads safely in your own WordPress database. 🔌 100% Offline-First & Local (SaaS connection is completely optional) You do not need a cloud account to use IntakeFlow. The core form builder, local wp-admin inbox, team assignment queue, email alerts, and the Contact Form 7 / Gravity Forms migrator run entirely within your WordPress hosting environment. An optional account on intakeflow.dev is only required if you want advanced cloud services such as digital signatures, document scanner fields, real-time Stripe/card checkout, or automatic backups. 🔄 Already using Contact Form 7 or Gravity Forms? Convert your existing forms to IntakeFlow in just 3 clicks. Our migration wizard preserves inputs, options, and required rules, generating a clean multi-step form and a dedicated shortcode instantly. 🌐 Clean HTML Rendering (No Bloated Iframes) Forms render natively using pure HTML/JS, inheriting your theme’s active CSS and typography. This ensures lightning-fast page speed, excellent SEO indexing, and perfect mobile responsiveness. Key features Import from Contact Form 7 & Gravity Forms — migrate your existing forms in a few clicks; field types, choices and required rules are preserved. Works with the block editor & page builders — embed via the [xpressui] shortcode, the native Gutenberg block, or the Elementor widget. One-click installation — upload the exported .zip file from the IntakeFlow console directly inside wp-admin. Shortcode embed — [xpressui id="your-project-slug"] works in any page, post, or block-editor paragraph block. The form renders inline, inheriting your theme’s page layout. Submission inbox — all submissions land in a private wp-admin post list with status badges, filtering by project, status, and assignee, and detailed review metaboxes. Status workflow — mark submissions New, In review, or Done from the list or the detail view. Every status change is recorded in a per-submission history log. Team assignment — assign any WordPress user to a submission. The My Queue page shows each reviewer their personal backlog at a glance. Email notifications — configure a notification address per project and receive a plain-text summary email the moment a new submission arrives. Post-submit redirect — optionally redirect the visitor to a thank-you page after a successful submission. Configured per project from wp-admin. File uploads — uploaded files are stored as WordPress media attachments and linked back to their submission. REST API endpoint — submissions are received via a standard WordPress REST route (POST /wp-json/xpressui/v1/submit). No extra server configuration required. Bundled runtime — the XPressUI standard runtime is bundled inside the plugin. No JavaScript is loaded from the uploads directory or external CDNs. Product & booking catalogs (with a Console account) — product and service / time-slot booking catalogs render server-side in WordPress (SEO-friendly, no iframe) with a built-in checkout step; orders are recorded in your submission inbox. Who is this for? Businesses and developers who use the IntakeFlow console to build document-intake or multi-step application forms and want to manage the collected data inside their existing WordPress environment without an external SaaS inbox. The Ultimate Alternative for Team Intake Unlike generic form builders (like Contact Form 7, WPForms, or Gravity Forms), IntakeFlow is built specifically for client intake and document collection. * No paywall on team inbox: Assign submissions to specific WordPress users without upgrading to expensive Enterprise plans (unlike JotForm or Typeform). * No bloated iframes: Forms render natively in clean, fast HTML/JS, inheriting your active theme’s styling. * 100% GDPR-compliant: Your submissions and uploaded files are stored entirely in your local database. No data is stored on third-party servers. External Services This plugin can optionally connect to the IntakeFlow SaaS platform (hosted at intakeflow.dev) to enable real-time cloud synchronization, advanced field types, and centralized workflow management. When connected to IntakeFlow: * The plugin makes outbound HTTP requests to https://app.intakeflow.dev (or the custom console URL you configure under Settings) to verify your subscription status, sync project schemas, and download workflow packages. * Outbound requests include an API Token (X-Api-Token) generated from your IntakeFlow dashboard so the service can identify your account. * When you connect an account, the plugin sends the token to validate it and to look up the owner of the account. * When you use the Form Importer with an account connected, the structure of the imported Contact Form 7 / Gravity Forms form (field names, labels and types — not visitor submissions) is sent to the console to create the corresponding workflow, which is then downloaded back to this site. * No visitor or submission data is transmitted to the IntakeFlow console unless specifically configured by the administrator for cloud backup or webhook routing. * When you use a product / booking catalog with checkout, the order details (cart or chosen slot, and the payment proof or card payment) are sent to the IntakeFlow Console, which owns payment and order status; a copy of the order is also recorded locally in your wp-admin inbox. A connection is required to sync custom workflows. The bundled starter workflow functions fully offline without a connection. Use of the IntakeFlow service is governed by its terms and privacy policy: * Terms of Service: https://intakeflow.dev/terms * Privacy Policy: https://intakeflow.dev/privacy The bundled XPressUI standard runtime (JavaScript) is served directly from the plugin directory — it is never loaded from a CDN or external URL. Privacy This plugin stores data submitted by your site visitors (form field values, uploaded files, and metadata such as submission timestamps). All data is stored locally in your WordPress database and media library. No data is transmitted to external servers. When a submission is permanently deleted, its linked uploaded files are deleted as well. Users may request access to or deletion of their personal data. This plugin integrates with the WordPress Personal Data tools (Tools › Erase Personal Data and Tools › Export Personal Data). For full details on what data is collected and how to manage it, refer to your site’s privacy policy. Source Code The full source code for this plugin is available at: https://github.com/lybaba/xpressui-wordpress-bridge Bundled JavaScript runtime The file runtime/xpressui-*.umd.js is the compiled output of the XPressUI library. The unminified TypeScript source files used to produce this bundle are included in the xpressui-src/ directory of this plugin. To rebuild the runtime from those sources: Navigate to the source directory: cd xpressui-src Install dependencies: npm install Build the runtime: npm run build The output file is produced in xpressui-src/dist/xpressui-*.umd.js.