Category: SSL & HTTPS
Can I deactivate Really Simple Security after activating SSL?
The below article refers to modern versions of Really Simple Security (version 4.0 and upwards). Versions prior to 4.0 will revert the site to http when deactivating the plugin on the plugins overview page (Plugins -> Installed Plugins), and allows the site remain on https when using the option on the Settings page instead. Really Simple Security is built to be very lightweight: the majority of the files are not even loaded when a visitor requests the frontpage. If you
Really Simple Security – Multisite set-up and tips
In this article, we will explain how to activate the plugin on Multisite WordPress environments. Really Simple Security (Free) is fully compatible with Multisite WordPress. Note that using the Pro plugin on Multisite WordPress requires the dedicated Really Simple Security (Pro Multisite) plugin, included with all Agency plans. Setting up Really Simple Security in a multisite environment Really Simple Security can be installed by uploading and activating the .zip file in your WordPress installation, or in the case of the
Hyperlinks to external urls getting replaced to https
There are rare cases where a normal hyperlink to an external URL might get replaced to https. For instance, this could occur if the site’s own domain is part of the external domain. For example: if the external URL is http://domain.com.au, while the website URL is http://domain.com. Really Simple Security replaces all instances of the own website domain in the HTML to https. In this edge case, the external URL gets replaced as well: replace http://domain.com in http://domain.com.au to https,
Redirect to https not working
After enabling Really Simple Security and clicking the “Activate SSL” button, the PHP-based WordPress 301 redirect to https:// will be activated by default. If you notice that your site can still be reached over http://, it is possible that the redirect does not work because the site is still cached. If you’re using Apache or LiteSpeed, the recommended redirect method is the 301 .htaccess redirect. But as not every server uses Apache/LiteSpeed, and not all servers support the detected .htaccess
Certificate expiration check in Really Simple Security pro
There’s something strange with uptime robots: they usually don’t detect expired SSL certificates. So, even though you don’t get any messages that your site is down, it could still be that your SSL certificate has expired… and browsers will block access your site, or at least present “insecure” warnings to users. This happens because technically, your site is not entirely down. It’s just that there’s no browser that will display your site without resulting in such warnings. Iif you’ve generated