Security Hardener
by Marc Armengou 0 (0 reviews)

Security Hardener

Basic hardening: secure headers, login honeypot, user enumeration blocking, generic login errors, rate limiting, and more.

Security Hardener ranks #12,123 among WordPress.org plugins with 200+ active installations, is #695 of 4,529 in the Security category, and was last updated Aug 19, 2026. Data from WordPress.org, refreshed twice daily — see methodology.

Compatible with WP 7.1.1
v2.4.5 Current Version v2.4.5
Updated 4 weeks ago Last Update on 19 Aug, 2026
Refreshed 9 hours ago Last Refreshed on
#695 of 4,529 in Security Top 25% by installs Actively maintained
View on WordPress.org
Rank
#12,123
+58 this week
Active Installs
200+
-14.9%
KW Avg Position
92.5
0.5 worse
Downloads
2.2K
+3 today
Support Resolved
0%
No change
Rating
0%
Review 0 out of 5
0 (0 reviews)

Next Milestone 300

Total Progress 49%
200+ 300+
1,073
Ranks to Climb
-
Growth Needed
8,000,000
Active Installs
Pro

Unlock Exact Install Count

See the precise estimated active installs for this plugin, calculated from real-time ranking data.

  • Exact install estimates within tiers
  • Track install growth over time
  • Milestone progress predictions
Upgrade to Pro
Need 51 more installs to reach 300+

Rank Changes

12,096 12,154 12,213 12,271 12,329 11-09-2026 12-09-2026 13-09-2026 14-09-2026 15-09-2026 16-09-2026 17-09-2026 18-09-2026
12,038 12,222 12,406 12,589 12,773 03-09-2026 04-09-2026 05-09-2026 06-09-2026 07-09-2026 08-09-2026 09-09-2026 10-09-2026 11-09-2026 12-09-2026 13-09-2026 14-09-2026 15-09-2026 16-09-2026 17-09-2026 18-09-2026
Current #12,123
Change
Best #

Upgrade to Pro

Unlock 30-day and 90-day rank history charts with a Pro subscription.

Upgrade Now

Active Installs Growth

Active Installs 0,000,000+
Growth +0.0%
Peak 0,000,000

Downloads Growth

0 10 20 11-09-2026 12-09-2026 13-09-2026 14-09-2026 15-09-2026 16-09-2026 17-09-2026 18-09-2026
0 10 20 03-09-2026 04-09-2026 05-09-2026 06-09-2026 07-09-2026 08-09-2026 09-09-2026 10-09-2026 11-09-2026 12-09-2026 13-09-2026 14-09-2026 15-09-2026 16-09-2026 17-09-2026 18-09-2026
Downloads
Growth
Peak

Upgrade to Pro

Unlock 30-day, 90-day, and yearly download history charts with a Pro subscription.

Upgrade Now

Reviews & Ratings

0.0
0 reviews
Overall 0%
5
0 (0%)
4
0 (0%)
3
0 (0%)
2
0 (0%)
1
0 (0%)

Security History

Source: WPVulnerability

No known vulnerabilities on record for Security Hardener. Checked 1 month ago.

TL;DR

AI summary of the plugin's readme

This plugin is for WordPress site owners and administrators who want to reduce their site's attack surface without editing core files. It addresses common attack vectors like login brute-forcing, user enumeration, XML-RPC abuse, and missing security headers.

  • Login honeypot
  • IP-based rate limiting
  • Blocks author enumeration queries
  • Disables XML-RPC
  • Secures REST API user endpoints
  • Security headers (X-Frame-Options, HSTS)
  • Hides WordPress version
  • Security event logging

Frequently Asked Questions

Common questions about Security Hardener

By default, the plugin enables: * File editor disabled * XML-RPC disabled * User enumeration blocking * Generic login errors * Login honeypot * Block unsafe usernames * Login rate limiting (5 attempts per 15 minutes) * Security headers * WordPress version hiding (meta generator tag and asset query strings) * Clean wp_head output * Security event logging * Application Passwords disabled HSTS and author feed blocking are disabled by default. Application Passwords are disabled by default — disable this option only if you use the WordPress mobile app, Jetpack, or other REST API integrations that require them.
No. The plugin uses lightweight WordPress hooks and native functions. Security headers add negligible overhead, and rate limiting only checks transients during login attempts.
By default, rate limiting uses REMOTE_ADDR. If behind a trusted proxy, add this to wp-config.php: define('WPSH_TRUSTED_PROXIES', array( '173.245.48.0', // Example: Cloudflare IP range // Add your proxy IPs here )); The plugin will then check HTTP_CF_CONNECTING_IP (Cloudflare) or HTTP_X_FORWARDED_FOR headers.
* X-Frame-Options: SAMEORIGIN * X-Content-Type-Options: nosniff * Referrer-Policy: strict-origin-when-cross-origin * Permissions-Policy: geolocation=(), microphone=(), camera=()
* Strict-Transport-Security: max-age=31536000 (optionally with includeSubDomains if enabled)
Yes. Security headers are sent at the PHP level before caching. However, if you use aggressive server-level caching, you may need to configure your cache to allow these headers through.
Yes, but be careful of conflicts. If another plugin also: * Sends security headers, you may get duplicates (usually harmless) * Blocks user enumeration, one should be disabled * Has login rate limiting, choose one to avoid confusion This plugin is designed to be lightweight and focused on core WordPress hardening.
When you uninstall (not just deactivate) the plugin, data is preserved by default. If you have enabled the "Delete all data on uninstall" option under Settings > Security Hardener > Other Settings, then on uninstall: * All plugin settings are deleted * All security logs are deleted * All login rate limiting transients are cleared * Your WordPress installation is returned to its default state Note: Deactivating the plugin always preserves all settings.
No. The plugin only secures user-related endpoints by requiring authentication. All other REST API functionality works normally. Public endpoints like oEmbed continue to work.
Failed login blocks expire automatically based on your configured window (default: 15 minutes). Wait for the block period to expire, or: Access your database (phpMyAdmin, etc.) Search for options with _transient_wpsh_login_ in the name Delete those transient options Try logging in again

Sign In / Register

You need to sign in or register to use this feature.