Easily improve site security with WordPress Hardening, Two-Factor Authentication (2FA), Login Protection, Vuln...
Basic hardening: secure headers, login honeypot, user enumeration blocking, generic login errors, rate limiting, and more.
Security Hardener is a WordPress plugin designed to enhance the security of your website by applying best practices and hardening measures. It focuses on various aspects of security, including file security, XML-RPC protection, user enumeration protection, and login security, without modifying core files. The plugin is suitable for users looking to improve their site's security without extensive technical knowledge.
The plugin features options to disable file editing, protect against pingbacks, and secure login processes. It also implements security headers and provides a system status monitor to help you maintain a secure environment. Security Hardener is aimed at individuals and businesses that prioritise website security and wish to follow recommended practices.
Best for: This plugin suits website owners who want to enhance their WordPress security.
What it does well
Where it falls short
Security Hardener provides a range of security features for WordPress users. It is a practical choice for those looking to implement security best practices on their sites.
Marc Armengou's own description of Security Hardener, lightly tidied.
Security Hardener applies WordPress security best practices based on the WordPress Advanced Administration / Security / Hardening documentation and widely accepted hardening measures. It uses WordPress core functions and follows best practices without modifying core files.
File Security:
* Disable file editor in WordPress admin
* Optionally disable all file modifications
XML-RPC Protection:
* Disable XML-RPC completely
* Remove pingback methods when XML-RPC is enabled
Pingback Protection:
* Disable self-pingbacks
* Remove X-Pingback header
* Block incoming pingbacks
User Enumeration Protection:
* Block /?author=N queries (returns 404)
* Secure REST API user endpoints (require authentication)
* Remove users from XML sitemaps
* Prevent canonical redirects that expose usernames
* Optionally block author feed pages (/author/username/feed/)
* Optionally anonymize the author name in oEmbed responses
Login Security:
* Generic error messages (no username/password hints)
* Login honeypot
* Block unsafe usernames
* Application Passwords disabled by default
* IP-based rate limiting with configurable thresholds
* Security event logging
Security Headers:
* X-Frame-Options: SAMEORIGIN (clickjacking protection)
* X-Content-Type-Options: nosniff (MIME sniffing protection)
* Referrer-Policy: strict-origin-when-cross-origin
* Permissions-Policy (restricts geolocation, microphone, camera)
* Optional HSTS (HTTP Strict Transport Security) for HTTPS sites — max-age set to 1 year
Additional Hardening:
* Hide WordPress version (meta generator tag and asset query strings)
* Remove obsolete wp_head items (RSD, WLW manifest, shortlink, emoji scripts)
* System Status — monitors file permissions, WP_DEBUG, user registration, PHP version, administrator accounts, and database version
⚠️ Important: Always test security settings in a staging environment first. Some features may affect third-party integrations or plugins.
Privacy: This plugin does not send data to external services and does not create custom database tables. It stores plugin settings and a security event log in the WordPress options table, and uses transients for temporary login attempt tracking. All data is preserved on uninstall by default and only deleted if the “Delete all data on uninstall” option is explicitly enabled.
Other plugins for securing a site.
Easily improve site security with WordPress Hardening, Two-Factor Authentication (2FA), Login Protection, Vuln...
Firewall, Malware Scanner, Two Factor Auth, and Comprehensive Security Features, powered by our 24-hour team....
The best anti-spam protection to block spam comments and spam in a contact form. The most trusted antispam sol...
Loginizer is a WordPress security plugin which helps you fight against bruteforce attacks.
Enable SVG uploads and sanitize them to stop XML/SVG vulnerabilities in your WordPress website.
Protect your website investment with All-In-One Security (AIOS) – a comprehensive and easy to use security plu...