R
Security Free WordPress.org

Really Simple Security – Simple and Performant Security (formerly Really Simple SSL)

4.9 (8,848 reviews)
· 3.0M+ active installs · By Really Simple Plugins
Active Installs
3.0M+
Rating
4.9 / 5
Version
v9.6.0
Last Updated
May 2026
Share

Plugin Review

AI-Researched

What is Really Simple Security?

Really Simple Security is a modular WordPress plugin that handles SSL migration, two-factor authentication (2FA), vulnerability scanning, and login protection. Originally known as Really Simple SSL, it has been developed by Really Simple Plugins for 11 years. The plugin currently has over 3 million active installs and holds a 4.9 out of 5 star rating from 8,848 reviews. Of those ratings, 97% are 7% are one-star. The latest version, 9.5.11, was last updated on May 5, 2026.

The plugin is designed to be lightweight. Disabled features do not load any redundant code, keeping site performance high. Its onboarding process is short, aiming for a 1-minute configuration. The developers state that security should have minimal effect on user experience and maintainability.

Key Features of Really Simple Security

  • One-Click SSL Migration – Moves your site to HTTPS with 301 redirects via PHP or .htaccess and enforces secure cookies.
  • Let's Encrypt Integration – Installs a free SSL certificate directly if your hosting provider supports manual installation.
  • WordPress Hardening – Prevents code execution in uploads, disables XML-RPC, blocks user enumeration, and restricts the "admin" username.
  • Vulnerability Detection – Scans plugins, themes, and WordPress core for known security flaws and sends notifications.
  • Two-Factor Authentication (2FA) – Allows or enforces 2FA via email codes for specific user roles.
  • Login Protection – Adds an extra layer of security to the login process, helping block brute-force attacks.
  • Server Health Check – Evaluates your server configuration for potential security weaknesses.
  • Pro Firewall (Upgrade) – Blocks bad actors with IP and username rules, 404 blocking, and region-based access control.

Who Should Use Really Simple Security?

This plugin suits site owners who want a straightforward security setup without complex configuration. Beginners can complete the onboarding in under a minute. The 3 million active installs indicate it works across many site types, from personal blogs to small business sites. The 97% five-star rating suggests that even non-technical users find it reliable.

Site owners who manage multiple sites may also benefit from its modular design. You can enable only the features you need, such as 2FA or vulnerability scanning, without loading extra code. The plugin requires WordPress 6.6 or higher and PHP 7.4 or later, making it accessible to most modern installations. Those needing a firewall or advanced SSL enforcement can upgrade to the Pro version.

Installation & Setup

Installation follows the standard WordPress process: download the plugin, upload it to /wp-content/plugins/, and activate it. After activation, the onboarding wizard appears to guide you through the initial configuration. The developers recommend making a backup before installing. The setup is beginner-friendly, with clear prompts for enabling SSL and security features.

Support & Community

Support data from the last two months shows 23 open threads and 22 resolved, giving a 100% resolution rate. This indicates responsive support from the developers. The plugin is GPL licensed, and the team accepts feedback via GitHub for code contributions or support tickets for suggestions. With 8,846 total ratings and only 1% one-star reviews, user satisfaction is consistently high. The knowledge base on the plugin site provides detailed explanations for all features, reducing the need for direct support in many cases.

Pros & Cons

What's Good
  • With 3 million+ active installs and a 4.9/5 rating from 8,848 reviews, it is one of the most trusted security plugins on the WordPress repository.
  • 97% of its 8,848 ratings are 5-star, reflecting high user satisfaction with its lightweight, modular design that loads no code for disabled features.
  • It offers a one-click SSL migration and 301 redirect via PHP or .htaccess, simplifying HTTPS enforcement for non-technical users.
  • The plugin includes built-in Two-Factor Authentication (2FA) via email for specific user roles, adding a practical layer of login protection.
  • Vulnerability detection scans plugins, themes, and core files, with 96% of support threads resolved (22 of 23), indicating responsive maintenance.
Drawbacks
  • The free version only supports email-based 2FA, lacking app-based authenticators like Google Authenticator or SMS, which reduces security flexibility.
  • Login protection features are limited to 2FA and username restrictions, without built-in CAPTCHA or brute-force rate limiting seen in competitors.
  • The Let’s Encrypt SSL certificate generation requires manual hosting provider support, which may not work on all shared hosting environments.

Technical Details

Requires WordPress
6.6+
Requires PHP
7.4+
Tested up to WP
7.0
First Released
2015 (11+ years)
Support (last 2 months)
15 threads  —  100% resolved

Feature Tags

2fa https security two-factor vulnerabilities

Frequently Asked Questions

Compare Really Simple Security With...

1 comparisons