{"id":364462,"date":"2026-09-11T06:56:18","date_gmt":"2026-09-11T06:56:18","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/hopelessly-sensible-simple-security-hardening\/"},"modified":"2026-09-14T08:47:21","modified_gmt":"2026-09-14T08:47:21","slug":"hopelessly-sensible","status":"publish","type":"plugin","link":"https:\/\/ko.wordpress.org\/plugins\/hopelessly-sensible\/","author":23551246,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"1.1.1","stable_tag":"1.1.1","tested":"7.1.1","requires":"6.5","requires_php":"7.4","requires_plugins":null,"header_name":"Hopelessly Sensible: Simple Security Hardening","header_author":"Hebble & Stone","header_description":"Security hardening for people who have better things to do.","assets_banners_color":"f8f8eb","last_updated":"2026-09-14 08:47:21","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"https:\/\/github.com\/Hebble-Stone-CIC\/hopelessly-sensible","header_author_uri":"https:\/\/hebblestone.org","rating":5,"author_block_rating":0,"active_installs":10,"downloads":109,"num_ratings":1,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","faq","changelog"],"tags":{"1.1.1":{"tag":"1.1.1","author":"hebblestone","date":"2026-09-14 08:47:21","revision":3694812}},"upgrade_notice":[],"ratings":{"1":0,"2":0,"3":0,"4":0,"5":1},"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3690973,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3690973,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3690973,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3690973,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["1.1.1"],"block_files":[],"assets_screenshots":{"screenshot-1.png":{"filename":"screenshot-1.png","revision":3690973,"resolution":"1","location":"assets","locale":"","width":1920,"height":1776},"screenshot-2.png":{"filename":"screenshot-2.png","revision":3690973,"resolution":"2","location":"assets","locale":"","width":1920,"height":1636}},"screenshots":{"1":"The settings screen. Every option carries a plain explanation and a note on what it might break.","2":"An option this site cannot use, still on the screen, saying what is stopping it."}},"plugin_section":[],"plugin_tags":[107,31093,396,600,14731],"plugin_category":[44,54],"plugin_contributors":[280190,280189],"plugin_business_model":[],"class_list":["post-364462","plugin","type-plugin","status-publish","hentry","plugin_tags-comments","plugin_tags-hardening","plugin_tags-privacy","plugin_tags-security","plugin_tags-xmlrpc","plugin_category-discussion-and-community","plugin_category-security-and-spam-protection","plugin_contributors-hebblestone","plugin_contributors-mattbedford","plugin_committers-hebblestone"],"banners":{"banner":"https:\/\/ps.w.org\/hopelessly-sensible\/assets\/banner-772x250.png?rev=3690973","banner_2x":"https:\/\/ps.w.org\/hopelessly-sensible\/assets\/banner-1544x500.png?rev=3690973","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/hopelessly-sensible\/assets\/icon-128x128.png?rev=3690973","icon_2x":"https:\/\/ps.w.org\/hopelessly-sensible\/assets\/icon-256x256.png?rev=3690973","generated":false},"screenshots":[{"src":"https:\/\/ps.w.org\/hopelessly-sensible\/assets\/screenshot-1.png?rev=3690973","caption":"The settings screen. Every option carries a plain explanation and a note on what it might break."},{"src":"https:\/\/ps.w.org\/hopelessly-sensible\/assets\/screenshot-2.png?rev=3690973","caption":"An option this site cannot use, still on the screen, saying what is stopping it."}],"raw_content":"<!--section=description-->\n<p>Most WordPress security plugins are heavy and slow. This one is simple, light and reliable.<\/p>\n\n<p>It does seven things. Each one has a switch, a plain-English explanation of what it does and an honest note about what it might break. No notification badges, no upgrade banners and nothing in your dashboard trying to sell you something.<\/p>\n\n<p><strong>It sets up what is safe and leaves you in charge<\/strong><\/p>\n\n<p>When you activate it, Hopelessly Sensible looks at your site and switches on everything that is safe here. Protections that take a feature away from you are left off, so that call stays yours.<\/p>\n\n<p><strong>If something changes, it stands down and tells you<\/strong><\/p>\n\n<p>If a setting stops being safe to leave on, this plugin switches it off by itself and gives you one clear, dismissible notice saying what changed and why. It is the only thing this plugin ever shows you outside its own settings screen. A switch that is off is never turned on behind your back.<\/p>\n\n<p><strong>What it does<\/strong><\/p>\n\n<ul>\n<li>Keeps your list of users and their usernames away from anonymous visitors<\/li>\n<li>Gives the same short message whether a login failed due to the username or the password<\/li>\n<li>Hides author pages and keeps writers out of your sitemap and link previews<\/li>\n<li>Blocks XML-RPC, an old remote publishing interface popular with password-guessing tools<\/li>\n<li>Optionally: closes comments everywhere<\/li>\n<li>Optionally: closes WooCommerce product reviews<\/li>\n<li>Optionally: locks the theme and plugin file editors in the dashboard<\/li>\n<li>Warns you if you have a user called \"admin\", and explains how to fix it<\/li>\n<\/ul>\n\n<p><strong>What it does not do<\/strong><\/p>\n\n<ul>\n<li>It does not write to your .htaccess file, your wp-config.php or anything outside its own single settings row. Deactivate it and your site is exactly as it was, immediately.<\/li>\n<li>It adds no JavaScript to your dashboard.<\/li>\n<li>It does not scan, does not phone home, does not collect any data and has no paid version.<\/li>\n<li>It does not give you homework. There is no checklist, no score and no red badge waiting for you.<\/li>\n<li>It does not hide options from you. Anything this plugin cannot do on your site is still on the screen, switched off, saying what is stopping it.<\/li>\n<\/ul>\n\n<p>Free and open source, GPL, written by Hebble &amp; Stone, a community interest company that builds websites for charities, organisations and small businesses.<\/p>\n\n<!--section=faq-->\n<dl>\n<dt id=\"will%20this%20break%20my%20site%3F\"><h3>Will this break my site?<\/h3><\/dt>\n<dd><p>Very unlikely, but each setting changes how something works and carries a warning saying what. If something surprises you, switch it back off and your site is as it was.<\/p><\/dd>\n<dt id=\"what%20happens%20if%20i%20deactivate%20it%3F\"><h3>What happens if I deactivate it?<\/h3><\/dt>\n<dd><p>Everything goes back to how it was, straight away. The plugin makes no permanent changes to your site, so there is nothing to undo. Uninstalling removes its single row from your options table.<\/p><\/dd>\n<dt id=\"does%20it%20work%20with%20woocommerce%3F\"><h3>Does it work with WooCommerce?<\/h3><\/dt>\n<dd><p>Yes, and carefully. WooCommerce reviews are stored as comments, so closing comments would ordinarily take your product reviews and star ratings with them. This plugin never does that. Reviews have their own option, off by default, and it stays on the screen with an explanation even when WooCommerce is not installed. Order notes, which are also stored as comments, are never touched by anything here.<\/p>\n\n<p>One thing to know if your shop is running an old WooCommerce. Closing comments takes the Comments screen out of your dashboard, and WooCommerce moved review moderation to its own screen under Products in version 6.7. On WooCommerce 6.7 or later this is fine, and you carry on approving reviews as normal. On anything older, reviews are still moderated on the Comments screen, so this plugin leaves that screen reachable on those shops rather than taking review moderation away from you.<\/p><\/dd>\n<dt id=\"does%20it%20work%20on%20multisite%3F\"><h3>Does it work on multisite?<\/h3><\/dt>\n<dd><p>Yes, but activate it on each site rather than across the whole network. Activating for the network means it cannot look at your sites one by one, so every option is off by default and it says so on the settings screen. Activated site by site, it looks at each one properly. Either way the settings are per site, so what you choose on one site does not affect another.<\/p><\/dd>\n<dt id=\"will%20it%20stop%20someone%20hacking%20my%20site%3F\"><h3>Will it stop someone hacking my site?<\/h3><\/dt>\n<dd><p>No plugin can promise that and you should be wary of any that implies it. This one closes off a set of well-known ways that automated tools and bots gather information and guess passwords. That is worth doing, though it is not the same thing as being safe. Strong passwords, two-factor authentication and keeping WordPress and its plugins updated matter more than anything.<\/p><\/dd>\n<dt id=\"why%20is%20there%20no%20scanning%2C%20firewall%20or%20login%20limiting%3F\"><h3>Why is there no scanning, firewall or login limiting?<\/h3><\/dt>\n<dd><p>Because those need attention and this plugin is set and forget. Features that generate alerts generate work, work gets ignored and ignored alerts are worse than no alerts.<\/p><\/dd>\n<dt id=\"i%20have%20a%20user%20called%20%22admin%22%20and%20it%20is%20warning%20me.%20what%20do%20i%20do%3F\"><h3>I have a user called \"admin\" and it is warning me. What do I do?<\/h3><\/dt>\n<dd><p>WordPress does not let you rename a user. The usual route is to create a second administrator account with a different username, log in as that one, delete the \"admin\" account and hand its posts over to the new account when WordPress asks.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>1.1.1<\/h4>\n\n<ul>\n<li>Changed: three messages borrowed from WordPress itself (the vague login error, the remote publishing refusal and the user list refusal) are now translatable as part of this plugin, as the plugin directory requires, rather than inheriting the translations WordPress ships with.<\/li>\n<\/ul>\n\n<h4>1.1.0<\/h4>\n\n<ul>\n<li>Fixed: on WordPress 7.1, \"Block remote publishing\" could not be switched on at all, and switched itself off on sites that had it on. WordPress 7.1 began using the same hook this plugin watches to work out whether anything on your site needs remote publishing, and the plugin read that as your site needing it.<\/li>\n<li>Added: \"Lock the file editor\" is now blocked, with an explanation, on sites where a published GeneratePress element runs PHP. GeneratePress stops running that code while the editor is locked, and prints the code into the page instead.<\/li>\n<li>Changed: the warning under \"Lock the file editor\" now mentions code snippets plugins, some of which stop running their code when the editor is locked.<\/li>\n<li>Tested against WordPress 7.1.<\/li>\n<\/ul>\n\n<h4>1.0.0<\/h4>\n\n<ul>\n<li>First release.<\/li>\n<\/ul>","raw_excerpt":"Security hardening for people who have better things to do. Seven options, plain English and clear information about what changes.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ko.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/364462","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ko.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/ko.wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/ko.wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=364462"}],"author":[{"embeddable":true,"href":"https:\/\/ko.wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/hebblestone"}],"wp:attachment":[{"href":"https:\/\/ko.wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=364462"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/ko.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=364462"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/ko.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=364462"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/ko.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=364462"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/ko.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=364462"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/ko.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=364462"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}