[WordPress] 外掛分享: Really Simple Security – Simple and Performant Security (formerly Really Simple SSL)

首頁外掛目錄 › Really Simple Security – Simple and Performant Security (formerly Really Simple SSL)
WordPress 外掛 Really Simple Security – Simple and Performant Security (formerly Really Simple SSL) 的封面圖片
3,000,000+
安裝啟用
★★★★
4.9/5 分(8803 則評價)
19 天前
最後更新
100%
問題解決
WordPress 6.6+ PHP 7.4+ v9.5.8 上架:2015-03-14

內容簡介

le Plugins include Complianz GDPR, Disable Updates Manager, and Really Simple CAPTCHA.

Really Simple SSL是一個外掛,自動配置你的網站最大程度上使用SSL。使用額外的硬化功能來保護你的網站,並使用我們的伺服器健康檢查來保持最新狀態。

特點

易於SSL遷移:僅需一個點擊,即可將你的網站轉換為HTTPS。
伺服器健康檢查(新):對於網站安全性而言,你的伺服器配置非常重要。
WordPress硬化(新):調整你的配置,解決WordPress的弱點,並使其更加牢固和安全。

透過Really Simple SSL Pro加強安全性

混合內容掃描和修復。檢測使用HTTP請求的文件並進行修復,包括前端和後端。

安全標頭

這些功能可以減少點擊劫持、跨站點偽造攻擊、竊取登錄憑證和惡意軟件等風險。

獨立於你的伺服器配置,適用於Apache、LiteSpeed、NGINX等。
使用X-XSS保護、X-Content-Type-Options、X-Frame-Options和Referrer策略來保護你的網站訪問者。
啟用HTTP嚴格傳輸安全性並配置你的網站以出現在HSTS預載列表中。

高級安全性

隔離你的網站與第三方之間不必要的文件加載和交換。完全控制你的網站並最小化操縱風險。

專門為WordPress設計。
使用內容安全策略(包括學習模式)來控制第三方。
使用權限策略來控制瀏覽器功能,例如地理位置,攝像頭和麥克風。
隔離其他網站之間的信息交換。完全控制數據進出。

Really Simple SSL的HTTPS遷移是如何工作的?

該外掛會檢查現有的SSL證書。如果你沒有證書,你可以在外掛中生成證書。根據你的主機提供商,外掛也可以為你安裝證書或提供指示。
如果需要,它將處理WordPress與SSL存在的已知問題。例如,你的網站使用負載均衡器,代理或未傳遞標題以檢測證書等問題。
所有傳入的請求都會使用默認的301 WordPress重定向重定向到HTTPS。你也可以選擇一個.htaccess重定向。
站點URL和首頁URL將更改為HTTPS。
除外部超鏈接之外,你的不安全內容都會被替換為HTTPS,而動態替換。
通過使用HTTPOnly標誌來安全設置PHP Cookie。

有用的鏈接

文件
SSL定義
翻譯Really Simple SSL
問題和拉取請求
功能請求

喜歡Really Simple SSL?

希望這個外掛可以為你節省一些時間。如果你想支持該外掛的持續開發,請考慮購買包括優秀安全功能和高級支持的Really Simple SSL Pro。

關於Really Simple Plugins

Really Simple Plugins開發的其他外掛包括Complianz GDPR、Disable Updates Manager和Really Simple CAPTCHA。

外掛標籤

開發者團隊

⬇ 下載最新版 (v9.5.8) 或搜尋安裝

① 下載 ZIP → 後台「外掛 › 安裝外掛 › 上傳外掛」
② 後台搜尋「Really Simple Security – Simple and Performant Security (formerly Really Simple SSL)」→ 直接安裝(推薦)
📦 歷史版本下載

原文外掛簡介

Easily improve site security with WordPress Hardening, Two-Factor Authentication (2FA), Login Protection, Vulnerability Detection and SSL certificate.
Really simple, Effective and Performant WordPress Security
Really Simple Security is the most lightweight and easy-to-use security plugin for WordPress. It secures your WordPress website with SSL certificate generation, including proper 301 https redirection and SSL enforcement, scanning for possible vulnerabilities, Login Protection and implementing essential WordPress hardening features.
We believe that security should have the absolute minimum effect on website performance, user experience and maintainability. Therefore, Really Simple Security is:

Lightweight: Every security feature is developed with a modular approach and with performance in mind. Disabled features won’t load any redundant code.
Easy-to-use: 1-minute configuration with short onboarding setup.

Security Features
Easy SSL Migration
Migrates your website to HTTPS and enforces SSL in just one click.

301 redirect via PHP or .htaccess
Secure cookies
Let’s Encrypt: Install an SSL Certificate if your hosting provider supports manual installation.
Server Health Check: Your server configuration is every bit as important for your website security.

WordPress Hardening
Tweak your configuration and keep WordPress fortified and safe by tackling potential weaknesses.

Prevent code execution in the uploads folder
Prevent login feedback and disable user enumeration
Disable XML-RPC
Disable directory browsing
Username restrictions (block ‘admin’ and public names)
and much more..

Vulnerability Detection
Get notified when plugins, themes or WP core contain vulnerabilities and need appropriate action.
Login Protection
Allow or enforce Two-Factor Authentication (2FA) for specific user roles. Users receive a two-factor code via Email.
Improve Security with Really Simple Security Pro
Protect your site with all essential security features by upgrading to Really Simple Security Pro.
Advanced SSL enforcement

Mixed Content Scan & Fixer. Detect files that are requested over HTTP and fix them to HTTPS, both Front- and Back-end.
Enable HTTP Strict Transport Security and configure your site for the HSTS Preload list.

Firewall
Really Simple Security Pro includes a performant and efficient WordPress firewall, to stop bots, crawlers and bad actors with IP and username blocks.

404 blocking – Blocks crawlers as they trigger unusual numbers of 404 errors.
Region blocking – Only allow/block access to your site from specific regions.
Automated and customisable Firewall rules.
IP blocklist and allowlist.

Security Headers
Security headers protect your site visitors against the risk of clickjacking, cross-site-forgery attacks, stealing login credentials and malware.

Independent of your Server Configuration, works on Apache, LiteSpeed, NGINX, etc.
Protect your website visitors with X-XSS Protection, X-Content-Type-Options, X-Frame-Options, a Referrer Policy and CORS headers.
Automatically generate your WordPress-tailored Content Security Policy.

Vulnerability Measures
When a vulnerability is detected in a plugin, theme or WordPress core you will get notified accordingly. With Vulnerability Measures, you can configure simple but effective measures to make sure that a critical vulnerability won’t remain unattended.

Force update: An update process will be tried multiple times until it can be assumed development of a theme or plugin is abandoned. You will be notified during these steps.
Quarantine: When a plugin or theme can’t be updated to solve a vulnerability, Really Simple Security can quarantine the plugin.

Advanced Site Hardening

Choose a custom login URL
Automated File Permissions check and fixer
Rename and randomize your database prefix
Change the debug.log file location to a non-public folder
Disable application passwords
Control admin creation
Disable HTTP methods, reducing HTTP requests

Login Protection
Secure your website’s login process and user accounts with powerful security measures.

Two-Step verification (Email login)
2FA (two factor authentication) with TOTP
Passwordless login with passkey login
Enforce strong passwords and frequent password change
Limit Login Attempts

With Limit Login Attempts you can configure a threshold to temporarily or permanently block IP addresses or (non-existing) usernames. You can also throw a CAPTCHA after a failed login (hCaptcha or Google reCaptcha)
Access Control

Restrict access to your site for specific regions.
Add specific IP addresses or IP ranges to the Blocklist or Allowlist.

Useful Links

Documentation
Security Definitions
Translate Really Simple Security
Issues & pull requests
Feature requests

Love Really Simple Security?
If you want to support the continuing development of this plugin, please consider buying Really Simple Security Pro, which includes some excellent security features and premium support.
About Really Simple Plugins
Our mission is to make complex WordPress requirements really easy. Really Simple Security is developed by Really Simple Plugins.
For generating SSL certificates, Really Simple Security uses the le acme2 PHP Let’s Encrypt client library, thanks to ‘fbett’ for providing it. Vulnerability Detection uses WP Vulnerability, an open-source initiative by Javier Casares. Want to join as a collaborator? We’re on GitHub as well!

延伸相關外掛

文章
Filter
Apply Filters
Mastodon