WPThumbs
Themes Plugins By purpose By industry Best-of lists Fix it guides
Free Plugin by Marc Armengou v2.4.5

Security Hardener

Basic hardening: secure headers, login honeypot, user enumeration blocking, generic login errors, rate limiting, and more.

Security Hardener

The facts

Active installs
200+
Price
Free
Last updated
19 Aug 2026
Added
Nov 2025
Requires WP
6.9
Tested up to
WP 7.1
Requires PHP
8.2
Downloads
2,108

Our analysis

AI-assisted

Security Hardener is a WordPress plugin designed to enhance the security of your website by applying best practices and hardening measures. It focuses on various aspects of security, including file security, XML-RPC protection, user enumeration protection, and login security, without modifying core files. The plugin is suitable for users looking to improve their site's security without extensive technical knowledge.

The plugin features options to disable file editing, protect against pingbacks, and secure login processes. It also implements security headers and provides a system status monitor to help you maintain a secure environment. Security Hardener is aimed at individuals and businesses that prioritise website security and wish to follow recommended practices.

Best for: This plugin suits website owners who want to enhance their WordPress security.

What it does well

  • Applies WordPress security best practices
  • Does not modify core files
  • Offers comprehensive protection features
  • Privacy-focused with no data sent externally
  • Includes system status monitoring

Where it falls short

  • Some features may affect third-party integrations
  • Data is preserved on uninstall unless explicitly deleted

Verdict

Security Hardener provides a range of security features for WordPress users. It is a practical choice for those looking to implement security best practices on their sites.

From the developer

Marc Armengou's own description of Security Hardener, lightly tidied.

Security Hardener applies WordPress security best practices based on the WordPress Advanced Administration / Security / Hardening documentation and widely accepted hardening measures. It uses WordPress core functions and follows best practices without modifying core files.

Key Features

File Security:
* Disable file editor in WordPress admin
* Optionally disable all file modifications

XML-RPC Protection:
* Disable XML-RPC completely
* Remove pingback methods when XML-RPC is enabled

Pingback Protection:
* Disable self-pingbacks
* Remove X-Pingback header
* Block incoming pingbacks

User Enumeration Protection:
* Block /?author=N queries (returns 404)
* Secure REST API user endpoints (require authentication)
* Remove users from XML sitemaps
* Prevent canonical redirects that expose usernames
* Optionally block author feed pages (/author/username/feed/)
* Optionally anonymize the author name in oEmbed responses

Login Security:
* Generic error messages (no username/password hints)
* Login honeypot
* Block unsafe usernames
* Application Passwords disabled by default
* IP-based rate limiting with configurable thresholds
* Security event logging

Security Headers:
* X-Frame-Options: SAMEORIGIN (clickjacking protection)
* X-Content-Type-Options: nosniff (MIME sniffing protection)
* Referrer-Policy: strict-origin-when-cross-origin
* Permissions-Policy (restricts geolocation, microphone, camera)
* Optional HSTS (HTTP Strict Transport Security) for HTTPS sites — max-age set to 1 year

Additional Hardening:
* Hide WordPress version (meta generator tag and asset query strings)
* Remove obsolete wp_head items (RSD, WLW manifest, shortlink, emoji scripts)
* System Status — monitors file permissions, WP_DEBUG, user registration, PHP version, administrator accounts, and database version

⚠️ Important: Always test security settings in a staging environment first. Some features may affect third-party integrations or plugins.

Privacy: This plugin does not send data to external services and does not create custom database tables. It stores plugin settings and a security event log in the WordPress options table, and uses transients for temporary login attempt tracking. All data is preserved on uninstall by default and only deleted if the “Delete all data on uninstall” option is explicitly enabled.

Read the full description on the official page →

Tagged as

Alternatives

Other plugins for securing a site.

Really Simple Security

Easily improve site security with WordPress Hardening, Two-Factor Authentication (2FA), Login Protection, Vuln...

Free 3M+ installs 4.9★ (8,862)
Wordfence Security

Firewall, Malware Scanner, Two Factor Auth, and Comprehensive Security Features, powered by our 24-hour team....

Free 5M+ installs 4.7★ (4,983)
Akismet Anti-spam: Spam Protection

The best anti-spam protection to block spam comments and spam in a contact form. The most trusted antispam sol...

Free 5M+ installs 4.7★ (1,186)
Loginizer

Loginizer is a WordPress security plugin which helps you fight against bruteforce attacks.

Free 1M+ installs 4.8★ (1,030)
Safe SVG

Enable SVG uploads and sanitize them to stop XML/SVG vulnerabilities in your WordPress website.

Free 1M+ installs 4.9★ (79)
All-In-One Security

Protect your website investment with All-In-One Security (AIOS) – a comprehensive and easy to use security plu...

Free 1M+ installs 4.7★ (1,715)