Really Simple Security – Simple and Performant Security (formerly Really Simple SSL) icon

Really Simple Security – Simple and Performant Security (formerly Really Simple SSL)

by Really Simple Plugins

View on WordPress.org
99 Quality Score
Active Installs
29/30

A 97 score on popularity is anchored by 3,000,000 active installs, placing it among the most widely deployed security plugins on WordPress.

Update Freshness
25/25

The maintenance score of 100 reflects an update within the last few weeks and active development against current WordPress 7.1 and PHP 7.4 requirements.

User Rating
15/15

A 98 rating from 8,864 reviews is unusually consistent for a security plugin, where users often hit edge cases that drag scores down.

Support Health
15/15

A perfect 100 on support is based on 11 threads with 11 resolved, which is a small sample but shows the developers are responsive.

WP Compatibility
15/15

Compatibility sits at 100, confirmed by recent testing against WordPress 7.1 and a PHP 7.4 minimum that still covers the vast majority of hosts.

Scores higher than 99% of indexed plugins

About

Easily improve site security with WordPress Hardening, Two-Factor Authentication (2FA), Login Protection, Vulnerability Detection and SSL certificate.

Active Installs 3M+
Rating ★★★★½ 4.9/5
Last Updated 2026-09-15 6:18am GMT
Requires WordPress 6.6+
Tested Up To 7.1
Requires PHP 7.4+

Security History

13 known vulnerabilities, all patched
1 Critical 2 High 10 Medium

Most recent: September 16, 2026

View details ▸

Powered by Wordfence Intelligence

What It Does

Really Simple Security handles the technical side of forcing HTTPS across a WordPress site and then layers on hardening features like two-factor authentication, login protection, and vulnerability detection. It also monitors your SSL certificate so it does not silently expire. The 3,000,000 active installs suggest most people use it as a set-and-forget baseline security plugin.

Who It's For

Small to mid-sized site owners who want sensible security defaults without configuring a firewall or learning WAF rules. It is a good fit for business sites, blogs, and WooCommerce stores that need HTTPS enforcement and 2FA but do not want the overhead of a full security suite. Agencies running multiple client sites will also appreciate the centralized license options.

Who Should Skip It

If you already run Wordfence or a managed security stack with its own SSL and login protection, adding Really Simple Security is redundant and risks overlapping rules. Enterprise sites with compliance auditors who mandate specific WAF vendors should also skip this and stick with their required platform.

The Bottom Line

Really Simple Security earns its 98.71 quality score by doing the security essentials well: HTTPS enforcement, 2FA, login hardening, and vulnerability detection in one package. It is not a replacement for a dedicated WAF on high-risk sites, but for most WordPress installs it is a sensible default. The 3,000,000 installs and 98% rating make it one of the safer picks in the category.

Tags

2FA https security two factor vulnerabilities