Category: WordPress Security
About Email verification
Some features in Really Simple SSL rely on the ability to send emails to a website administrator or to your users. To make sure these e-mail messages reach the intended recipient an e-mail verification function is included under “Settings -> General”. During activation of the plugin a verification email is sent to the supplied email address (the main WordPress administrator user by default). If you want to change the email address Really Simple SSL uses for notifications or resend the
How valuable is your website?
Thousands of websites get hacked every day. It may not have happened to you, but there is no reason for cybercriminals not to try. People often think it won’t happen to their website because there is nothing to gain for an attacker. You may not be running a webshop, you’re not storing any confidential or valuable data on your website, and you are not even bothered about losing your website because you’re hardly getting any visitors. No one would care
W3 Total Cache and Security Headers
Disk: Enhanced mode blocks security headers If you are using W3 Total Cache in “Disk: Enhanced” mode, setting security headers in Really Simple SSL will not work correctly. Really Simple SSL sets security headers using PHP and the “Disk: Enhanced” mode in W3 Total Cache completely bypasses PHP and serves static HTML only. This means W3 Total Cache “Disk: Enhanced” mode is incompatible with the security headers functionality in Really Simple SSL. To use Really Simple SSL’s security headers functionality
Rogue admin protection for WordPress
To protect your website against the creation of rogue admins, simply enable the “Restrict creation of administrators” setting under advanced hardening in Really Simple SSL Pro.
Disabling admin account creation protection when you are locked-out
Really Simple Security Pro has an advanced hardening setting to “Restrict creation of administrator roles” Enabling this setting will check for Users that were assigned the Administrator role in a different way than through the regular user profile interface. If a such a user account is found, the role of the user will be changed to Subscriber immediately and an e-mail notification will be sent to the site administrator. If for some reason you are locked out of your site