[WordPress] 外掛分享: Really Simple Security – Simple and Performant Security (formerly Really Simple SSL)

WordPress 外掛 Really Simple Security – Simple and Performant Security (formerly Really Simple SSL) 的封面圖片。

前言介紹

  • 這款 WordPress 外掛「Really Simple Security – Simple and Performant Security (formerly Really Simple SSL)」是 2015-03-14 上架。
  • 目前有 4000000 個安裝啟用數。
  • 上一次更新是 2025-04-29,距離現在已有 4 天。
  • 外掛最低要求 WordPress 5.9 以上版本才可以安裝。
  • 外掛要求網站主機運作至少需要 PHP 版本 7.4 以上。
  • 有 8705 人給過評分。
  • 論壇上目前有 12 個提問,問題解答率 100% ,不低,算是個很有心解決問題的開發者團隊了!

外掛協作開發者

wimbraam | vicocotea | markwolters | hesseldejong | marcelsanting | janwoostendorp | rogierlankhorst |

外掛標籤

2FA | ssl | security | two factor | vulnerabilities |

內容簡介

le Plugins include Complianz GDPR, Disable Updates Manager, and Really Simple CAPTCHA.

Really Simple SSL是一個外掛,自動配置你的網站最大程度上使用SSL。使用額外的硬化功能來保護你的網站,並使用我們的伺服器健康檢查來保持最新狀態。

特點

易於SSL遷移:僅需一個點擊,即可將你的網站轉換為HTTPS。
伺服器健康檢查(新):對於網站安全性而言,你的伺服器配置非常重要。
WordPress硬化(新):調整你的配置,解決WordPress的弱點,並使其更加牢固和安全。

透過Really Simple SSL Pro加強安全性

混合內容掃描和修復。檢測使用HTTP請求的文件並進行修復,包括前端和後端。

安全標頭

這些功能可以減少點擊劫持、跨站點偽造攻擊、竊取登錄憑證和惡意軟件等風險。

獨立於你的伺服器配置,適用於Apache、LiteSpeed、NGINX等。
使用X-XSS保護、X-Content-Type-Options、X-Frame-Options和Referrer策略來保護你的網站訪問者。
啟用HTTP嚴格傳輸安全性並配置你的網站以出現在HSTS預載列表中。

高級安全性

隔離你的網站與第三方之間不必要的文件加載和交換。完全控制你的網站並最小化操縱風險。

專門為WordPress設計。
使用內容安全策略(包括學習模式)來控制第三方。
使用權限策略來控制瀏覽器功能,例如地理位置,攝像頭和麥克風。
隔離其他網站之間的信息交換。完全控制數據進出。

Really Simple SSL的HTTPS遷移是如何工作的?

該外掛會檢查現有的SSL證書。如果你沒有證書,你可以在外掛中生成證書。根據你的主機提供商,外掛也可以為你安裝證書或提供指示。
如果需要,它將處理WordPress與SSL存在的已知問題。例如,你的網站使用負載均衡器,代理或未傳遞標題以檢測證書等問題。
所有傳入的請求都會使用默認的301 WordPress重定向重定向到HTTPS。你也可以選擇一個.htaccess重定向。
站點URL和首頁URL將更改為HTTPS。
除外部超鏈接之外,你的不安全內容都會被替換為HTTPS,而動態替換。
通過使用HTTPOnly標誌來安全設置PHP Cookie。

有用的鏈接

文件
SSL定義
翻譯Really Simple SSL
問題和拉取請求
功能請求

喜歡Really Simple SSL?

希望這個外掛可以為你節省一些時間。如果你想支持該外掛的持續開發,請考慮購買包括優秀安全功能和高級支持的Really Simple SSL Pro。

關於Really Simple Plugins

Really Simple Plugins開發的其他外掛包括Complianz GDPR、Disable Updates Manager和Really Simple CAPTCHA。

原文外掛簡介

Easily improve site security with WordPress Hardening, Two-Factor Authentication (2FA), Login Protection, Vulnerability Detection and SSL certificate.
Really simple, Effective and Performant WordPress Security
Really Simple Security is the most lightweight and easy-to-use security plugin for WordPress. It secures your WordPress website with SSL certificate generation, properly enforcing en redirecting to https, scanning for possible vulnerabilities, Login Protection and implementing essential WordPress hardening features.
We believe that security should have the absolute minimum effect on website performance, user experience and maintainability. Therefore, Really Simple Security is:

Lightweight: Every security feature is developed with a modular approach and with performance in mind. Disabled features won’t load any redundant code.
Easy-to-use: 1-minute configuration with short onboarding setup.

Security Features
Easy SSL Migration
Migrates your website to HTTPS and enforces SSL in just one click.

301 redirect via PHP or .htaccess
Secure cookies
Let’s Encrypt: Install an SSL Certificate if your hosting provider supports manual installation.
Server Health Check: Your server configuration is every bit as important for your website security.

WordPress Hardening
Tweak your configuration and keep WordPress fortified and safe by tackling potential weaknesses.

Prevent code execution in the uploads folder
Prevent login feedback and disable user enumeration
Disable XML-RPC
Disable directory browsing
Username restrictions (block ‘admin’ and public names)
and much more..

Vulnerability Detection
Get notified when plugins, themes or WP core contain vulnerabilities and need appropriate action.
Login Protection
Allow or enforce Two-Factor Authentication (2FA) for specific user roles. Users receive a two-factor code via Email.
Improve Security with Really Simple Security Pro
Protect your site with all essential security features by upgrading to Really Simple Security Pro.
Advanced SSL enforcement

Mixed Content Scan & Fixer. Detect files that are requested over HTTP and fix it, both Front- and Back-end.
Enable HTTP Strict Transport Security and configure your site for the HSTS Preload list.

Firewall
Really Simple Security Pro includes a performant and efficient WordPress firewall, to stop bots, crawlers and bad actors with IP and username blocks.

404 blocking – Blocks crawlers as they trigger unusual numbers of 404 errors.
Region blocking – Only allow/block access to your site from specific regions.
Automated and customisable Firewall rules.
IP blocklist and allowlist.

Security Headers
Security headers protect your site visitors against the risk of clickjacking, cross-site-forgery attacks, stealing login credentials and malware.

Independent of your Server Configuration, works on Apache, LiteSpeed, NGINX, etc.
Protect your website visitors with X-XSS Protection, X-Content-Type-Options, X-Frame-Options, a Referrer Policy and CORS headers.
Automatically generate your WordPress-tailored Content Security Policy.

Vulnerability Measures
When a vulnerability is detected in a plugin, theme or WordPress core you will get notified accordingly. With Vulnerability Measures, you can configure simple but effective measures to make sure that a critical vulnerability won’t remain unattended.

Force update: An update process will be tried multiple times until it can be assumed development of a theme or plugin is abandoned. You will be notified during these steps.
Quarantine: When a plugin or theme can’t be updated to solve a vulnerability, Really Simple Security can quarantine the plugin.

Advanced Site Hardening

Choose a custom login URL
Automated File Permissions check and fixer
Rename and randomize your database prefix
Change the debug.log file location to a non-public folder
Disable application passwords
Control admin creation
Disable HTTP methods, reducing HTTP requests

Login Protection
Secure your website’s login process and user accounts with powerful security measures.

Two-Step verification (Email login)
Enforce strong passwords and frequent password change
Limit Login Attempts

With Limit Login Attempts you can configure a threshold to temporarily or permanently block IP addresses or (non-existing) usernames. You can also throw a CAPTCHA after a failed login (hCaptcha or Google reCaptcha)
Access Control

Restrict access to your site for specific regions.
Add specific IP addresses or IP ranges to the Blocklist or Allowlist.

Useful Links

Documentation
Security Definitions
Translate Really Simple Security
Issues & pull requests
Feature requests

Love Really Simple Security?
If you want to support the continuing development of this plugin, please consider buying Really Simple Security Pro, which includes some excellent security features and premium support.
About Really Simple Plugins
Our mission is to make complex WordPress requirements really easy. Really Simple Security is developed by Really Simple Plugins.
For generating SSL certificates, Really Simple Security uses the le acme2 PHP Let’s Encrypt client library, thanks to ‘fbett’ for providing it. Vulnerability Detection uses WP Vulnerability, an open-source initiative by Javier Casares. Want to join as a collaborator? We’re on GitHub as well!

各版本下載點

  • 方法一:點下方版本號的連結下載 ZIP 檔案後,登入網站後台左側選單「外掛」的「安裝外掛」,然後選擇上方的「上傳外掛」,把下載回去的 ZIP 外掛打包檔案上傳上去安裝與啟用。
  • 方法二:透過「安裝外掛」的畫面右方搜尋功能,搜尋外掛名稱「Really Simple Security – Simple and Performant Security (formerly Really Simple SSL)」來進行安裝。

(建議使用方法二,確保安裝的版本符合當前運作的 WordPress 環境。


9.1.1 | 9.1.2 | 9.1.3 | 9.1.4 | 9.2.0 | 9.3.1 | 9.3.2 | 9.3.3 | 9.3.4 | 9.3.5 | trunk | 9.1.1.1 | 9.3.2.1 |

延伸相關外掛(你可能也想知道)

  • Wordfence Security – Firewall, Malware Scan, and Login Security 》fective way to manage multiple WordPress sites with Wordfence installed from a single location., Monitor security status across all your sites from...。
  • Jetpack – WP Security, Backup, Speed, & Growth 》search engines, and grow your traffic with Jetpack. It’s the ultimate toolkit for WordPress professionals and beginners alike., , Customize and des...。
  • Hostinger Tools 》- Hostinger Onboarding WordPress Plugin 简化和加快了WordPress网站的设置过程。, - 提供了简便和快速的方式来建立WordPress网站。。
  • Limit Login Attempts Reloaded – Login Security, Brute Force Protection, Firewall 》Limit Login Attempts Reloaded 是一款WordPress外掛,可阻止暴力破解攻擊並透過限制常規登錄、XMLRPC、Woocommerce和自訂登錄頁面的登錄嘗試次數來優化您的...。
  • ManageWP Worker 》, Want to clone or migrate your WordPress website to a new host or domain? No problem! With ManageWP, you can easily clone or migrate your website ...。
  • Security Optimizer – The All-In-One Protection Plugin 》透過精心挑選且易於配置的功能,SiteGround Security 外掛提供了您所需的一切來保護您的網站並預防多種威脅,例如暴力破解攻擊、登錄錯誤、資料外洩等等。, ...。
  • Safe SVG 》Safe SVG 可以讓你安心地在 WordPress 中上傳 SVG 檔案!, 它能夠讓你允許上傳 SVG 檔案的同時,確保它們已經經過消毒以防止 SVG/XML 弱點影響你的網站。此外...。
  • Loginizer 》Loginizer 是一個 WordPress 外掛,可幫助您對抗暴力攻擊,當 IP 地址達到最大重試次數時,該外掛會阻止其登錄。您可以使用 Loginizer 將 IP 地址列入黑名單...。
  • All-In-One Security (AIOS) – Security and Firewall 》vated to your website, All-in-One Security's WAF will detect and block hacking attempts, adding an extra layer of security to your WordPress site. ...。
  • Solid Security – Password, Two Factor Authentication, and Brute Force Protection 》ing iThemes Security Plugin can benefit you:, 保護您的 WordPress 網站的最佳外掛程式, 平均每天有 30,000 個網站遭受駭客攻擊,在網路上每 39 秒就會有一...。
  • User Role Editor 》「User Role Editor」WordPress 外掛讓您輕鬆更改使用者角色和權限。, 只需打開您希望新增到所選角色的能力核取方塊,然後按「更新」按鈕以保存您的更改。完...。
  • Sucuri Security – Auditing, Malware Scanner and Security Hardening 》Sucuri Inc. 是全球公認的網站安全權威,專門為 WordPress 安全提供專業知識。, Sucuri Security WordPress 擴充套件對所有 WordPress 使用者免費提供。它是...。
  • MainWP Child – Securely Connects to the MainWP Dashboard to Manage Multiple Sites 》這是一個針對「MainWP Dashboard」的子外掛程式,可將您的 WordPress 網站連接至 MainWP Dashboard。, MainWP是一個完整的 WordPress 管理解決方案,是自助...。
  • SiteGuard WP Plugin 》版本: 1.6.7, , 您可以在日文網頁和英文網頁上找到文件、常見問題和更詳細的資訊。 , 安裝SiteGuard WP Plugin後,WordPress安全性會得到提高。, 本外掛是一...。
  • Limit Login Attempts 》此外掛可限制正常登入及使用驗證 cookies 登入的次數。, WordPress 預設允許使用者無限次數嘗試登入,無論是透過登入頁面或是傳送特殊 cookies 皆可。這讓密...。

文章
Filter
Apply Filters
Mastodon