Hopelessly Sensible: Simple Security Hardening Wordpress Plugin - Rating, Reviews, Demo & Download
Plugin Description
Most security plugins are built for people who enjoy security. This one is built for everyone else: the person who looks after a small charity’s website on a Tuesday evening and would like to stop worrying about it.
It does seven things. Each one has a switch, a plain-English explanation of what it does, and an honest note about what it might break. No notification badges, no upgrade prompts, no counting of attacks repelled, and nothing anywhere in your dashboard trying to sell you something.
It describes your site as it is today.
Everything on the settings screen is about your site now, not about what it looked like the day you installed this. If four people publish posts here, it says four. If three comments are approved and hidden from your visitors, it says so, and tells you how to get rid of them for good if that is what you want.
It sets up what is safe, and leaves the rest to you.
When you activate it, the plugin looks at your site and switches on what is safe here. If you have one writer, it hides author pages. If nobody has approved a comment in a year, it closes comments. Three of the seven are never switched on for you, because they take something away from you rather than from a visitor, and that decision is yours to make.
If something changes, it stands down and tells you.
If a setting stops being safe to leave on, this plugin switches it off by itself. Install something that needs remote publishing and blocking remote publishing goes off, rather than sitting there reading as on while quietly breaking your new plugin. When that happens you get one notice, once, saying what changed and why, and you can dismiss it for good. It is the only thing this plugin will ever show you outside its own settings screen, and it only ever appears because something has already happened.
A switch that is off is never turned on behind your back. That direction is always yours.
What it does
- Keeps your list of users and their usernames away from anonymous visitors
- Gives the same short message whether a login failed on the username or the password
- Hides author pages, and keeps writers out of your sitemap and link previews
- Blocks XML-RPC, an old remote publishing interface popular with password-guessing tools
- Closes comments everywhere, and leaves WooCommerce reviews alone unless you say otherwise
- Closes WooCommerce product reviews, if you want that
- Locks the theme and plugin file editors in the dashboard
- Warns you if you have a user called “admin”, and does nothing else about it
What it does not do
- It does not write to your .htaccess file, your wp-config.php, or anything outside its own single settings row. Deactivate it and your site is exactly as it was, immediately.
- It adds no JavaScript to your dashboard.
- It does not scan, does not phone home, does not collect anything, and has no paid version.
- It does not give you homework. There is no checklist, no score, and no red badge waiting for you.
- It does not hide options from you. Anything this plugin cannot do on your site is still on the screen, switched off, saying what is stopping it.
Free and open source, GPL, written by Hebble & Stone, a community interest company that builds websites for charities.
Screenshots
No screenshots provided

