New Feature: Earn 12 Badges
Collect up to 12 exclusive badges by sharing your plugin collections and engaging with the community.
See all Badgesby Really Simple Plugins
Description
Easily improve site security with WordPress hardening, vulnerability detection and SSL certificate generation.
Really simple, effective and lightweight WordPress Security
Really Simple SSL is the most lightweight and easy-to-use security plugin for WordPress. It lays the foundation of your WordPress website’s security by leveraging your SSL certificate, scanning for possible vulnerabilities and implementing essential WordPress hardening features.
We believe that security should have the absolute minimum effect on website performance, user experience and maintainability. Therefore, Really Simple SSL is:
Lightweight: Every security feature is developed with a modular approach and with performance in mind. Disabled features won’t load any redundant code.
Easy-to-use: 1-minute configuration with short onboarding setup.
Security Features
Easy SSL Migration
Migrates your website to HTTPS and enforces SSL in just one click.
301 redirect via PHP or .htaccess
Secure cookies
Let’s Encrypt: Install an SSL Certificate if your hosting provider supports manual installation.
Server Health Check: Your server configuration is every bit as important for your website security.
WordPress Hardening
Tweak your configuration and keep WordPress fortified and safe by tackling potential weaknesses.
Prevent code execution in the uploads folder
Prevent login feedback and disable user enumeration
Disable XML-RPC
Disable directory browsing
Username restrictions (block ‘admin’ and public names)
and much more..
Vulnerability Detection
Get notified when plugins, themes or WP core contain vulnerabilities and need appropriate action.
Improve Security with Really Simple SSL Pro
Protect your site with all essential security features by upgrading to Really Simple SSL Pro.
Advanced SSL enforcement
Mixed Content Scan & Fixer. Detect files that are requested over HTTP and fix it, both Front- and Back-end.
Enable HTTP Strict Transport Security and configure your site for the HSTS Preload list.
Security Headers
Security headers protect your site visitors against the risk of clickjacking, cross-site-forgery attacks, stealing login credentials and malware.
Independent of your Server Configuration, works on Apache, LiteSpeed, NGINX, etc.
Protect your website visitors with X-XSS Protection, X-Content-Type-Options, X-Frame-Options, a Referrer Policy and CORS headers.
Automatically generate your WordPress-tailored Content Security Policy.
Vulnerability Measures
When a vulnerability is detected in a plugin, theme or WordPress core you will get notified accordingly. With Vulnerability Measures, you can configure simple but effective measures to make sure that a critical vulnerability won’t remain unattended.
Force update: An update process will be tried multiple times until it can be assumed development of a theme or plugin is abandoned. You will be notified during these steps.
Quarantine: When a plugin or theme can’t be updated to solve a vulnerability, Really Simple SSL can quarantine the plugin.
Advanced Site Hardening
Choose a custom login URL
Automated File Permissions check and fixer
Rename and randomize your database prefix
Change the debug.log file location to a non-public folder
Disable application passwords
Control admin creation
Disable HTTP methods, reducing HTTP requests
Login Protection
Secure your website’s login process and user accounts with powerful security measures.
Two-Step verification (Email login)
Enforce strong passwords and frequent password change
Limit Login Attempts
With Limit Login Attempts you can configure a threshold to temporarily or permanently block IP addresses or (non-existing) usernames. You can also throw a CAPTCHA after a failed login (hCaptcha or Google reCaptcha)
Access Control
Restrict access to your site for specific regions.
Add specific IP addresses or IP ranges to the Blocklist or Allowlist.
Useful Links
Documentation
Security Definitions
Translate Really Simple SSL
Issues & pull requests
Feature requests
Love Really Simple SSL?
If you want to support the continuing development of this plugin, please consider buying Really Simple SSL Pro, which includes some excellent security features and premium support.
About Really Simple Plugins
Our mission is to make complex WordPress requirements really easy. Really Simple SSL is developed by Really Simple Plugins.
For generating SSL certificates, Really Simple SSL uses the le acme2 PHP Let’s Encrypt client library, thanks to ‘fbett’ for providing it. Vulnerability Detection uses WP Vulnerability, an open-source initiative by Javier Casares. Want to join as a collaborator? We’re on GitHub as well!
All texts and images on this product page are protected by copyright and are the property of the author Really Simple Plugins. You will be redirected to the retailer to download the plugin. We act solely as a search engine for plugins and are not affiliated with the retailer or Really Simple Plugins.
Get your first Badge
Earn your first badge by sharing your collections. Every master was once a beginner. Welcome to your coding journey.
Click the symbol on the desired plugin to create a collection. The symbol appears when you hover over the plugin.