A WordPress plugin that adds security headers, CSP, login protection, SMTP, spam protection and more. Functionality is continuously being expanded to cover more ground.
Features
- Adds security headers, including configurable HSTS, X-Frame-Options, COOP and CORP
- Supports Content Security Policy (CSP), editable from the admin UI and validated against unrecognized directives
- Protects login with rate-limiting
- Blocks weak passwords, with an exemption list for individual users
- Blocks common/guessable usernames
- Validates protected brand names against required domains — self-registration blocks a brand-impersonating email outright
- Locks file editing, with a temporary admin-bar toggle that automatically relocks after a period of inactivity
- Honeypot spam protection (CF7, Elementor, WPForms, Forminator, lost password)
- Custom SMTP sending, with a test-email button
- Central security log with automatic retention, including new user account creation
- Removes certain default WordPress traces from
<head>
- Blocks usernames from leaking through author URLs, the REST API and embedded author data
- English, with community translations available via translate.wordpress.org
What does it protect against?
- Basic login attacks
- Some forms of user enumeration
- Unwanted WordPress metadata
- Missing security headers
Important: it does not protect against vulnerabilities in other plugins or themes, poor server configuration, or missing updates.
Compatibility
Some security headers can affect elements such as iframes, embeds and third-party scripts. Some of the CSP directives may be too strict and might need loosening depending on your needs — this is done from the admin UI's CSP field (administrator role).