Re

Really Simple Security

by Really Simple Plugins

Handles SSL redirection, security headers, hardening and two-factor login from one clearly written settings screen.

4.98,863 WordPress.org reviewsSecurityFreemium

This link may earn us a commission. It never changes our rating.

What Really Simple Security does

Handles SSL redirection, security headers, hardening and two-factor login from one clearly written settings screen.

It sits in the security part of a WordPress stack and is sold by Really Simple Plugins on a freemium basis. We recommend it in our security guides because it does that one job well without asking you to rebuild the rest of the site around it.

Every plugin adds work to a page request, so treat this as a decision with a cost. Record a speed test before you install it and run the same test afterwards, on the same page, so you know exactly what it charged you.

Real user ratings

Score

4.9/5

Reviews

8,863

Active installs

3,000,000+

Downloads

219.0M

Latest version

9.8.1

Last updated

2026-09-01

These figures come straight from the public WordPress.org plugin directory API for version 9.8.1, not from us. Check them yourself on the WordPress.org listing. Our own editorial score is 4.9/5.

Where Really Simple Security ranks elsewhere

PublisherListPosition
KinstaBest WordPress Security Plugins#14 of 22

Positions are read from the published articles themselves, so they reflect that publisher's order rather than ours. Lists get re-ordered over time, so follow the link if you want the current version.

What changed in the latest version

v9.8.1Latest release2026-09-01
  • Security: Prevented unexpected deletion of the login nonce.
  • Security: Prevented a bug that incorrectly changed the 2FA status from active to open.
  • Security: Prevent XML-RPC logins without 2FA for users with 2FA configured.
v9.8.02026-08-25
  • Fixed: Other plugin installation now retrieves the download link correctly.
  • Fixed: PHP 8.5 compatibility issues.
  • Fixed: The 2FA grace period was not always handled correctly.
  • Changed: REST API checks are faster and run only when needed.
  • Changed: Tested up to WordPress 7.1.
v9.7.02026-07-29
  • Fixed: Alignment of the e-mail validation status icon.
  • Fixed: Vulnerability data is included in uninstall cleanup.
  • Changed: Removed an unused passkey log message.
  • Changed: Updated the Other Plugins section in onboarding and settings.

Release notes are the developer's own words, published on WordPress.org. Read the full changelog

Pros and cons

  • Sensible hardening defaults you can apply in minutes
  • A free tier you can trial before paying
  • Actively maintained and used on production sites we test
  • The firewall and 2FA depth sit in the paid tier
  • The features most sites need sit in the paid tier

How to use it

  1. 1Take a full backup before enabling any blocking feature.
  2. 2Turn on login protection and two-factor for administrator accounts first.
  3. 3Schedule scans outside peak hours to protect response times.
  4. 4Set alerts to a monitored inbox, not the default admin address.
  5. 5Re-run the speed test so you know what the protection costs you.

How it compares

Other security plugins we recommend, with their rating and pricing model.

PluginOur ratingWordPress.orgPricingBest for
Really Simple Security4.94.9 (8,863)FreemiumSensible hardening defaults you can apply in minutes
Akismet4.74.7 (1,186)FreemiumCatches almost all comment spam with no tuning
Antispam Bee4.84.8 (226)FreePrivacy friendly spam filtering with no account
Duo4.24 (1)FreemiumCentral policy control for teams
Jetpack Protect4.34.6 (123)FreemiumFree vulnerability alerts
Limit Login Attempts Reloaded4.84.8 (1,483)FreemiumBig protection for almost no overhead