Category: WordPress Security
Limit Login Attempts
The Limit Login Attempts function of Really Simple SSL protects your site from login attempts by unauthorized users. When you enable Limit Login Attempts, all login attempts are logged and repeated attempts to login with invalid credentials will be blocked automatically. Temporary lockouts By default, 5 invalid login attempts within 15 minutes will result in a 30 minute lockout of the offending ip address and/or username. All automatic lockouts are temporary and will be cleared after the configured lock-out duration.
Password Security
If the login credentials of accounts on your WordPress sites are compromised, this could result in your site getting hacked. The Password Security features in Really Simple SSL aim to strengthen the protection of WordPress accounts on your website. We will explain each of these features below, and how they can help you improve the security of user accounts. Securing User Accounts and Passwords Activating the “Enforce strong passwords” setting enhances WordPress’ default password strength check (for all new user registrations);
About Email verification
Some features in Really Simple SSL rely on the ability to send emails to a website administrator or to your users. To make sure these e-mail messages reach the intended recipient an e-mail verification function is included under “Settings -> General”. During activation of the plugin a verification email is sent to the supplied email address (the main WordPress administrator user by default). If you want to change the email address Really Simple SSL uses for notifications or resend the
How valuable is your website?
Thousands of websites get hacked every day. It may not have happened to you, but there is no reason for cybercriminals not to try. People often think it won’t happen to their website, because there is nothing to gain for an attacker, right? You may not be running a webshop, you’re not storing any confidential or valuable data on your website, and you are not even bothered about losing your website; for instance when you’re hardly getting any visitors at
W3 Total Cache and Security Headers
Disk: Enhanced mode blocks security headers If you are using W3 Total Cache in “Disk: Enhanced” mode, setting Security Headers via Really Simple Security will not work correctly. Really Simple Security sets security headers using PHP, and the “Disk: Enhanced” mode in W3 Total Cache completely bypasses PHP to serve static HTML only. This means W3 Total Cache “Disk: Enhanced” mode is inherently incompatible with the Security Headers functionality in Really Simple SSL. To use Really Simple Security’s security headers